Blocking RDP Port 3389 in an Active Directory Domain

Today, most medium and large companies use Active Directory to centrally manage their users and computers. Alongside this, we also build in a number of security measures, especially on user computers.

One of the most important of these security measures is Remote Desktop Protocol (RDP), which we can also simply refer to as port 3389. What matters here is not just blocking port 3389 itself, which has effectively become the standard TCP port for this, but also keeping in mind that RDP connections can be blocked through other methods as well.

In this post and video, we’ll walk through a short demonstration covering the scenario where we prevent a domain-joined device from making connections on port 3389.

First, we log in as Administrator on a machine that has the Active Directory management console.

Opening the Group Policy Management Console

Creating the Firewall Rule

Editing the GPO

Choosing the Rule Type

Restricting the Connection

Defining the Exceptions

Naming the Rule

Active Directory schema

Applying the GPO to the Target Computers

I log in to a sample device on the domain and type the following command into the cmd prompt. This pulls all the updates down onto my test device.

gpupdate /force
Active Directory schema

As a result, we’ve blocked outbound connections from our domain-joined computers on port 3389. You can think of this as just one of the simplest links in the chain of security measures I mentioned at the start of this post.