What Is RDP (Remote Desktop Protocol)?

Also called: Remote Desktop

Related problems: Servers reachable from the internet through Remote Desktop; Staff and contractors need remote access to office computers; Ransomware attackers getting in through remote access; Insurer asking whether RDP is exposed

Remote Desktop Protocol (RDP) is Microsoft’s protocol for connecting to a Windows computer or server over a network and controlling it as if you were sitting in front of it. The remote machine sends its screen to the user, and the user’s keyboard and mouse input are sent back. RDP is built into Windows and is widely used by IT teams to manage servers, by staff to reach office computers, and by many virtual desktop products to deliver desktops.

At a glance

  • RDP is built into Windows; clients exist for most operating systems.
  • It is used for server administration, remote work and many hosted desktop services.
  • Directly exposing RDP to the internet is widely reported as a common entry point for ransomware.
  • Safer deployments put RDP behind a gateway, VPN or zero trust access, with MFA and restricted users.
  • Insurers and auditors often ask specifically whether RDP is exposed.

What problem it solves

IT teams need to manage servers they can’t physically reach, and staff sometimes need to use a specific office computer or application from home. RDP gives them a full graphical session on the remote machine without copying data to the local device: the files and applications stay on the remote system, and mainly screen images and input travel over the network, unless features such as drive or clipboard redirection are turned on.

The same convenience creates risk. An RDP service reachable from the internet invites automated password-guessing, use of stolen credentials and exploitation of unpatched flaws. Once in, an attacker has an interactive session on a Windows machine inside the network, a strong starting point for lateral movement and ransomware. Security agencies and incident responders have repeatedly identified exposed RDP as a frequent initial access route, which is why its security matters as much as its usefulness.

How it works

Client and host. A user runs an RDP client and connects to a Windows host that has Remote Desktop enabled, by default on TCP port 3389. The host asks for credentials, and Network Level Authentication, when enabled, requires the user to authenticate before a full session starts.

Session. The host renders the desktop and sends compressed screen updates; the client sends keystrokes and mouse movements. RDP can also redirect printers, clipboards, drives and audio, which IT can restrict by policy.

Encryption. RDP sessions are encrypted, commonly using TLS. Encryption protects the session in transit but doesn’t stop someone with valid or guessed credentials from logging in.

Gateways and brokers. In larger setups, users connect through a gateway that sits at the edge and forwards sessions inside, and a broker assigns users to hosts. This is how many virtual desktop infrastructure (VDI) and desktop as a service (DaaS) environments deliver desktops.

Securing it. Common controls include removing direct internet exposure, requiring MFA, limiting which users and groups can connect, patching promptly, account lockout, logging and monitoring, and using privileged access management (PAM) for admin sessions.

When it matters for buyers

  • When cyber insurance renews. Expect questions on whether RDP is exposed and whether MFA protects remote access.
  • When supporting remote staff. Decide whether staff need full remote desktops, specific apps or just files; the answer shapes whether RDP, VDI, DaaS or other tools fit.
  • When contractors or vendors need access. Third-party RDP access is a common weak point; brokered, time-limited access with recording is safer.
  • When choosing a hosted desktop service. Our desktop as a service and privileged access management overviews cover the two most common ways to control remote sessions.

Questions to ask vendors

  • Is any RDP host in our environment reachable directly from the internet, and how will you find out?
  • How do users reach RDP through your service: gateway, VPN or zero trust access?
  • Do you enforce MFA on every remote session, including admin and vendor accounts?
  • Can sessions be recorded, time-limited and approved for privileged or third-party users?
  • How quickly are RDP-related security patches applied on hosts you manage?
  • Which redirection features (clipboard, drives, printers) are allowed by default?

How it differs from a VPN

A virtual private network (VPN) connects a device to a network, giving it network-level access to whatever it is allowed to reach. RDP gives a user a remote screen on one specific machine. They’re often combined: a user connects to the VPN, then opens an RDP session to an office computer. Zero trust network access (ZTNA) is a newer alternative that can grant access to a single RDP host without putting the device on the whole network.

Frequently Asked Questions

Is RDP secure?
RDP encrypts its sessions, but how safe it is depends on how it's deployed. Exposing it directly to the internet with password-only logins is widely reported as a common way attackers get in. Placing it behind a gateway, VPN or zero trust access with MFA, and keeping it patched, reduces that risk substantially.
Should RDP be open to the internet?
Security guidance generally says no. Put it behind a remote access gateway, VPN or zero trust access service, require MFA, and restrict who can connect. Many cyber insurers ask about exposed RDP directly.
What is the difference between RDP and VDI?
RDP is a protocol for displaying and controlling a remote Windows session. VDI is an approach that runs user desktops as virtual machines in a data center or cloud. Many VDI and desktop-as-a-service products use RDP or a similar display protocol to deliver those desktops.
What port does RDP use?
By default TCP port 3389, and newer versions can also use UDP. Changing the port alone is not a meaningful protection, because attackers scan for RDP on other ports too.
Do we need RDP if we use remote support tools?
Not necessarily. Many IT teams use remote monitoring and management or remote support tools instead. Those tools carry similar risks if poorly controlled, so the same rules apply: MFA, limited access and logging.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.