Emergency server help: get in touch

Enable Remote Desktop with Group Policy: NLA, Firewall Rules and User Access

Turn on RDP for Windows 11 and Windows Server 2025 computers with one GPO: allow connections, require Network Level Authentication, open the Remote Desktop firewall rules, manage Remote Desktop Users, optionally change the port, and do the same with Intune.

Published Updated 12 min read

To enable Remote Desktop with Group Policy, you need three pieces in one GPO: a policy that allows connections, a firewall rule that lets TCP and UDP 3389 in, and a group that says who may sign in. Network Level Authentication (NLA) should be the fourth piece, so nobody reaches the sign-in screen without valid credentials first. This guide walks through each setting with its registry value, adds the Intune equivalents, and shows how to test and roll back.

Applies to Windows 11 Pro, Enterprise and Education; Windows Server 2016 to 2025

Short answer: Link a GPO to the computer OU and enable Computer Configuration » Policies » Administrative Templates » Windows Components » Remote Desktop Services » Remote Desktop Session Host » Connections » "Allow users to connect remotely by using Remote Desktop Services". In the same GPO, add the predefined Remote Desktop inbound firewall rules, enable NLA under Security, and add your support group to Remote Desktop Users with a Local Users and Groups preference. Then test with Test-NetConnection pc01 -Port 3389.

Which method to use

MethodScopeProsCons
Group PolicyDomain-joined PCs and serversOne GPO covers listener, NLA, firewall and group membershipDomain only
PowerShell and registryOne machine or Server CoreFast, scriptable, no GUINot enforced; can drift
Settings or sconfigOne machineSimple for a single PC or serverManual
IntuneEntra-joined and co-managed devicesSettings catalog, firewall rules and local group membershipEntra groups do not grant RDP rights through local group policy

How the pieces fit together

When you enable Remote Desktop with Group Policy, each setting controls a different gate. A connection only works when all four are open:

GateSettingWhat happens if it is missing
Listener“Allow users to connect remotely by using Remote Desktop Services”Port 3389 does not answer at all
FirewallRemote Desktop inbound rulesThe port times out from other machines, but works locally
AuthenticationNLA and TLS security layerConnections work but the sign-in screen is exposed before authentication
AuthorisationRemote Desktop Users membership and the logon rightUsers authenticate, then see a message that they lack the right to sign in

Keep all four in one GPO so they are linked, filtered and removed together. Splitting them across GPOs is the most common reason a pilot works on one OU and fails on the next.

Prerequisites

  • Windows 11 Pro, Enterprise or Education, or Windows Server 2016 to 2025. Windows 11 Home cannot accept Remote Desktop connections.
  • Rights to create and link GPOs, and GPMC.
  • A security group for the people who need access, for example SG-RDP-Workstations.
  • A decision on where connections may come from: an admin subnet, a VPN range or an RD Gateway. Do not expose 3389 to the internet.

Step 1: Allow Remote Desktop connections

This is the setting most people mean when they say they want to enable Remote Desktop with Group Policy. It turns on the RDP listener on every computer in scope.

  1. In GPMC, right-click the OU that holds the target computers and choose Create a GPO in this domain, and Link it here. Name it, for example, CFG – Remote Desktop.
  2. Go to Computer Configuration » Policies » Administrative Templates » Windows Components » Remote Desktop Services » Remote Desktop Session Host » Connections.
  3. Open “Allow users to connect remotely by using Remote Desktop Services”, set it to Enabled and click OK.

This writes fDenyTSConnections = 0 (REG_DWORD) under HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services, which overrides the local switch in Settings. Disabled blocks new connections but keeps sessions that are already open. Not Configured falls back to the local setting, which is off by default.

Step 2: Require Network Level Authentication

NLA makes the client authenticate before a full session is created, which cuts resource use and reduces exposure to attacks on the sign-in screen.

  1. In the same GPO, go to Remote Desktop Session Host » Security.
  2. Enable “Require user authentication for remote connections by using Network Level Authentication”. It writes UserAuthentication = 1 in the same policy key.
  3. Enable “Require use of specific security layer for remote connections” and choose SSL (value SecurityLayer = 2), so the server always uses TLS.
  4. Optionally enable “Set client connection encryption level” with High Level.

Every supported Windows client supports NLA. Old thin clients or third-party RDP apps that do not will get an error that the remote computer requires NLA; update them rather than turning NLA off.

Step 3: Open the firewall with Group Policy

Enabling the listener does not open the Windows Firewall. To enable Remote Desktop with Group Policy end to end, add the predefined rules to the same GPO:

  1. Go to Computer Configuration » Policies » Windows Settings » Security Settings » Windows Defender Firewall with Advanced Security » Windows Defender Firewall with Advanced Security » Inbound Rules.
  2. Right-click Inbound Rules, choose New Rule, select Predefined and pick Remote Desktop from the list.
  3. Keep Remote Desktop – User Mode (TCP-In) and Remote Desktop – User Mode (UDP-In) ticked. Untick Remote Desktop – Shadow (TCP-In) unless you use session shadowing.
  4. Choose Allow the connection and click Finish.
  5. Open each new rule, go to the Scope tab and under Remote IP address add only your admin subnet or VPN range, for example 10.10.50.0/24.

The rules apply to all profiles by default. On the Advanced tab you can limit them to the Domain profile, but laptops at home will then refuse RDP over VPN if the VPN adapter is not in the Domain profile, so test first.

On a single machine, the same rule group is enabled with:

Enable-NetFirewallRule -DisplayGroup "Remote Desktop"

Step 4: Control who can connect

By default, members of the local Administrators and Remote Desktop Users groups may sign in through Remote Desktop. The cleanest way to add your support staff is a Local Users and Groups preference, which adds members without removing existing ones.

  1. Go to Computer Configuration » Preferences » Control Panel Settings » Local Users and Groups, right-click and choose New » Local Group.
  2. Set Action to Update and pick Remote Desktop Users (built-in) from the Group name list.
  3. Click Add, browse to CONTOSO\SG-RDP-Workstations, leave the action as Add to this group and click OK twice.

Restricted Groups (Computer Configuration » Policies » Windows Settings » Security Settings » Restricted Groups) also works. Use This group is a member of to add a domain group to Remote Desktop Users; the Members of this group list replaces the whole membership and removes anyone not listed.

User rights

The right “Allow log on through Remote Desktop Services” under Computer Configuration » Policies » Windows Settings » Security Settings » Local Policies » User Rights Assignment already includes Administrators and Remote Desktop Users on member computers. Only define it if you want to narrow it, and always list both groups, because defining it replaces the local list. Consider adding Local account to “Deny log on through Remote Desktop Services” so local accounts cannot be used for RDP.

Step 5 (optional): Change the listening port

A different port hides RDP from casual scans but is not a security control. If you still want it, deploy the value with a Group Policy Preferences registry item:

  • Hive HKEY_LOCAL_MACHINE, key SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp, value PortNumber, type REG_DWORD, decimal data such as 3390.
  • Create custom inbound firewall rules for TCP and UDP on the new port, because the predefined rules only cover 3389.
  • Restart the computer (or the Remote Desktop Services service) and connect with pc01.contoso.com:3390.
Get-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name PortNumber

One machine: PowerShell and registry

For a Server Core box or a machine outside the domain, run from an elevated PowerShell:

Set-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections -Value 0
Set-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication -Value 1
Enable-NetFirewallRule -DisplayGroup "Remote Desktop"
Add-LocalGroupMember -Group "Remote Desktop Users" -Member "CONTOSO\SG-RDP-Workstations"

These are the local values, not the policy values, so a GPO that sets the policy later wins over them. On Server Core, sconfig option Remote desktop does the same interactively.

Intune equivalents

  1. Listener and NLA: create a Settings catalog profile for Windows 10 and later, browse to Administrative templates » Windows Components » Remote Desktop Services » Remote Desktop Session Host and enable Allow users to connect remotely by using Remote Desktop Services (Connections) and Require user authentication for remote connections by using Network Level Authentication (Security).
  2. Firewall: in Endpoint security » Firewall » Create policy, choose Windows and Windows Firewall Rules, and add an inbound Allow rule for TCP and UDP 3389 with your remote address range.
  3. Who can connect: in Endpoint security » Account protection, create a Local user group membership profile for Remote Desktop Users with action Add (Update). Microsoft notes that Entra groups added this way do not apply to Remote Desktop connections on Entra-joined devices, so add individual users by SID or UPN.

Access from outside the office

If you enable Remote Desktop with Group Policy on laptops or servers that staff reach from home, do not publish 3389 on the internet router. Use one of these instead:

  • A VPN, with the firewall rule scope set to the VPN address pool.
  • An RD Gateway, which wraps RDP in HTTPS on port 443 and can require multifactor authentication through Network Policy Server.
  • For Azure-hosted machines, Azure Bastion or Azure Virtual Desktop instead of a public IP.

Also enable account lockout in the domain password policy, so password guessing against RDP stops quickly.

Targeting and exceptions

  • Link the GPO only to OUs that need RDP, such as servers and IT workstations, not the whole domain.
  • Use separate GPOs for servers and workstations, because the allowed groups and firewall scopes differ.
  • To exclude a few machines in the OU, add their computer accounts to a group and deny Apply group policy on the GPO’s Delegation tab.
  • On domain controllers, only administrators may use Remote Desktop by default. Keep it that way and do not link a workstation GPO to the Domain Controllers OU.

Verify it works

Check each gate in order after you enable Remote Desktop with Group Policy on a pilot machine:

  1. On the target computer:
    gpupdate /force
    gpresult /scope computer /r
    reg query "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services"
    Get-NetFirewallRule -DisplayGroup "Remote Desktop" | Format-Table DisplayName, Enabled, Profile
    net localgroup "Remote Desktop Users"

    You should see fDenyTSConnections 0x0, UserAuthentication 0x1, enabled rules and your group.
  2. From an admin PC, test the port:
    Test-NetConnection pc01.contoso.com -Port 3389

    TcpTestSucceeded : True means the listener and firewall are open.
  3. Connect with mstsc /v:pc01.contoso.com as a member of the support group.
  4. On the target, check event 1149 in Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational (network authentication succeeded) and event 4624 with logon type 10 in the Security log.

Troubleshooting

Most failures after you enable Remote Desktop with Group Policy map to one of the four gates above. Start with the port test, then the group, then the policy result.

SymptomLikely causeFix
TcpTestSucceeded : FalseFirewall rule missing, wrong profile or wrong scopeCheck Get-NetFirewallRule and the rule’s Remote IP scope and profile
“To sign in remotely, you need the right to sign in through Remote Desktop Services”User not in Remote Desktop Users, or the user right was overwrittenCheck net localgroup and the “Allow log on through Remote Desktop Services” policy
Client says the remote computer requires NLAOld client without NLA supportUpdate the client; keep NLA on
Settings shows Remote Desktop off and greyed outPolicy set to Disabled in another GPOFind the winning GPO in gpresult /h
Works on 3389 but not the new portNo firewall rule for the custom port, or no restartAdd TCP and UDP rules for the port and restart
Entra users denied on an Entra-joined PCEntra group in Remote Desktop Users is not honoured for RDPAdd the users individually
CredSSP encryption oracle errorClient or server missing updatesPatch both sides; do not lower the CredSSP policy

Roll back or undo

  1. Set “Allow users to connect remotely by using Remote Desktop Services” to Disabled to block new connections everywhere the GPO applies. Not Configured only removes the policy value and leaves each machine’s local setting as it was.
  2. Delete the Remote Desktop inbound rules from the GPO; they disappear from clients at the next refresh.
  3. Change the Local Group preference action to remove the members, or use Delete on the item.
  4. If you changed the port, set PortNumber back to 3389 and restart.

Once the pilot works, you can enable Remote Desktop with Group Policy for other OUs by linking the same GPO, and keep the firewall scope and group membership as the real access controls.

Enable Remote Desktop with Group Policy at a glance

Enable Remote Desktop with Group Policy summary card: Link a GPO to the computer OU and enable Computer Configuration » Policies » Administrative Templates » Windows…
In short: Link a GPO to the computer OU and enable Computer Configuration » Policies » Administrative Templates » Windows Components » Remote Desktop Services » Remote Desktop Session Host » Connections » “Allow users to connect remotely by using…

Official documentation: RemoteDesktopServices Policy CSP, Change the listening port for Remote Desktop, Account protection policy in Intune.

Related guides: Manage local administrators with Group Policy (Restricted Groups vs GPP) · Windows Firewall rules with Group Policy · RDP connection logs and event IDs.

Frequently asked questions

Which Group Policy setting enables Remote Desktop?

“Allow users to connect remotely by using Remote Desktop Services” under Computer Configuration » Policies » Administrative Templates » Windows Components » Remote Desktop Services » Remote Desktop Session Host » Connections. It sets fDenyTSConnections to 0, but you still need firewall rules and group membership.

Does enabling the policy open the firewall?

No. Add the predefined Remote Desktop inbound rules to the GPO under Windows Defender Firewall with Advanced Security, and limit their remote IP scope to your admin or VPN range.

How do I let non-admin users connect with RDP?

Add their group to the local Remote Desktop Users group with a Local Users and Groups preference or Restricted Groups. That group already has the “Allow log on through Remote Desktop Services” right on member computers.

Should I change the RDP port from 3389?

Only as a minor extra. It hides RDP from basic scans but is not a security control; restrict the firewall scope, require NLA and use a VPN or RD Gateway instead.

How do I test that RDP is reachable?

Run Test-NetConnection with the computer name and -Port 3389 from an admin PC. TcpTestSucceeded True means the listener and firewall are open; then connect with mstsc.

Maintenance record

This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.

Maintained by
srvScripts editorial team
Supported versions
Windows 11 Pro, Enterprise and Education; Windows Server 2016 to 2025
Last full review
Next review

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.