Remote Desktop Protocol (RDP) is Microsoft’s protocol for connecting to a Windows computer or server over a network and controlling it as if you were sitting in front of it. The remote machine sends its screen to the user, and the user’s keyboard and mouse input are sent back. RDP is built into Windows and is widely used by IT teams to manage servers, by staff to reach office computers, and by many virtual desktop products to deliver desktops.
At a glance
- RDP is built into Windows; clients exist for most operating systems.
- It is used for server administration, remote work and many hosted desktop services.
- Directly exposing RDP to the internet is widely reported as a common entry point for ransomware.
- Safer deployments put RDP behind a gateway, VPN or zero trust access, with MFA and restricted users.
- Insurers and auditors often ask specifically whether RDP is exposed.
What problem it solves
IT teams need to manage servers they can’t physically reach, and staff sometimes need to use a specific office computer or application from home. RDP gives them a full graphical session on the remote machine without copying data to the local device: the files and applications stay on the remote system, and mainly screen images and input travel over the network, unless features such as drive or clipboard redirection are turned on.
The same convenience creates risk. An RDP service reachable from the internet invites automated password-guessing, use of stolen credentials and exploitation of unpatched flaws. Once in, an attacker has an interactive session on a Windows machine inside the network, a strong starting point for lateral movement and ransomware. Security agencies and incident responders have repeatedly identified exposed RDP as a frequent initial access route, which is why its security matters as much as its usefulness.
How it works
Client and host. A user runs an RDP client and connects to a Windows host that has Remote Desktop enabled, by default on TCP port 3389. The host asks for credentials, and Network Level Authentication, when enabled, requires the user to authenticate before a full session starts.
Session. The host renders the desktop and sends compressed screen updates; the client sends keystrokes and mouse movements. RDP can also redirect printers, clipboards, drives and audio, which IT can restrict by policy.
Encryption. RDP sessions are encrypted, commonly using TLS. Encryption protects the session in transit but doesn’t stop someone with valid or guessed credentials from logging in.
Gateways and brokers. In larger setups, users connect through a gateway that sits at the edge and forwards sessions inside, and a broker assigns users to hosts. This is how many virtual desktop infrastructure (VDI) and desktop as a service (DaaS) environments deliver desktops.
Securing it. Common controls include removing direct internet exposure, requiring MFA, limiting which users and groups can connect, patching promptly, account lockout, logging and monitoring, and using privileged access management (PAM) for admin sessions.
When it matters for buyers
- When cyber insurance renews. Expect questions on whether RDP is exposed and whether MFA protects remote access.
- When supporting remote staff. Decide whether staff need full remote desktops, specific apps or just files; the answer shapes whether RDP, VDI, DaaS or other tools fit.
- When contractors or vendors need access. Third-party RDP access is a common weak point; brokered, time-limited access with recording is safer.
- When choosing a hosted desktop service. Our desktop as a service and privileged access management overviews cover the two most common ways to control remote sessions.
Questions to ask vendors
- Is any RDP host in our environment reachable directly from the internet, and how will you find out?
- How do users reach RDP through your service: gateway, VPN or zero trust access?
- Do you enforce MFA on every remote session, including admin and vendor accounts?
- Can sessions be recorded, time-limited and approved for privileged or third-party users?
- How quickly are RDP-related security patches applied on hosts you manage?
- Which redirection features (clipboard, drives, printers) are allowed by default?
How it differs from a VPN
A virtual private network (VPN) connects a device to a network, giving it network-level access to whatever it is allowed to reach. RDP gives a user a remote screen on one specific machine. They’re often combined: a user connects to the VPN, then opens an RDP session to an office computer. Zero trust network access (ZTNA) is a newer alternative that can grant access to a single RDP host without putting the device on the whole network.
