# Enable Remote Desktop with Group Policy: NLA, Firewall Rules and User Access

Source: https://srvscripts.com/guides/enable-remote-desktop-group-policy/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

To enable Remote Desktop with Group Policy, you need three pieces in one GPO: a policy that allows connections, a firewall rule that lets TCP and UDP 3389 in, and a group that says who may sign in. Network Level Authentication (NLA) should be the fourth piece, so nobody reaches the sign-in screen without valid credentials first. This guide walks through each setting with its registry value, adds the Intune equivalents, and shows how to test and roll back.

**Short answer:** Link a GPO to the computer OU and enable `Computer Configuration » Policies » Administrative Templates » Windows Components » Remote Desktop Services » Remote Desktop Session Host » Connections » "Allow users to connect remotely by using Remote Desktop Services"`. In the same GPO, add the predefined **Remote Desktop** inbound firewall rules, enable NLA under **Security**, and add your support group to **Remote Desktop Users** with a Local Users and Groups preference. Then test with `Test-NetConnection pc01 -Port 3389`.

In short: Link a GPO to the computer OU and enable Computer Configuration » Policies » Administrative Templates » Windows Components » Remote Desktop Services » Remote Desktop Session Host » Connections » “Allow users to connect remotely by using…

## Which method to use

| Method | Scope | Pros | Cons |
| --- | --- | --- | --- |
| Group Policy | Domain-joined PCs and servers | One GPO covers listener, NLA, firewall and group membership | Domain only |
| PowerShell and registry | One machine or Server Core | Fast, scriptable, no GUI | Not enforced; can drift |
| Settings or sconfig | One machine | Simple for a single PC or server | Manual |
| Intune | Entra-joined and co-managed devices | Settings catalog, firewall rules and local group membership | Entra groups do not grant RDP rights through local group policy |

## How the pieces fit together

When you enable Remote Desktop with Group Policy, each setting controls a different gate. A connection only works when all four are open:

| Gate | Setting | What happens if it is missing |
| --- | --- | --- |
| Listener | “Allow users to connect remotely by using Remote Desktop Services” | Port 3389 does not answer at all |
| Firewall | Remote Desktop inbound rules | The port times out from other machines, but works locally |
| Authentication | NLA and TLS security layer | Connections work but the sign-in screen is exposed before authentication |
| Authorisation | Remote Desktop Users membership and the logon right | Users authenticate, then see a message that they lack the right to sign in |

Keep all four in one GPO so they are linked, filtered and removed together. Splitting them across GPOs is the most common reason a pilot works on one OU and fails on the next.

## Prerequisites

- Windows 11 Pro, Enterprise or Education, or Windows Server 2016 to 2025. Windows 11 Home cannot accept Remote Desktop connections.

- Rights to create and link GPOs, and GPMC.

- A security group for the people who need access, for example SG-RDP-Workstations.

- A decision on where connections may come from: an admin subnet, a VPN range or an RD Gateway. Do not expose 3389 to the internet.

## Step 1: Allow Remote Desktop connections

This is the setting most people mean when they say they want to enable Remote Desktop with Group Policy. It turns on the RDP listener on every computer in scope.

- In GPMC, right-click the OU that holds the target computers and choose **Create a GPO in this domain, and Link it here**. Name it, for example, CFG – Remote Desktop.

- Go to `Computer Configuration » Policies » Administrative Templates » Windows Components » Remote Desktop Services » Remote Desktop Session Host » Connections`.

- Open **“Allow users to connect remotely by using Remote Desktop Services”**, set it to **Enabled** and click **OK**.

This writes `fDenyTSConnections = 0` (REG_DWORD) under `HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services`, which overrides the local switch in Settings. **Disabled** blocks new connections but keeps sessions that are already open. **Not Configured** falls back to the local setting, which is off by default.

## Step 2: Require Network Level Authentication

NLA makes the client authenticate before a full session is created, which cuts resource use and reduces exposure to attacks on the sign-in screen.

- In the same GPO, go to `Remote Desktop Session Host » Security`.

- Enable **“Require user authentication for remote connections by using Network Level Authentication”**. It writes `UserAuthentication = 1` in the same policy key.

- Enable **“Require use of specific security layer for remote connections”** and choose SSL (value `SecurityLayer = 2`), so the server always uses TLS.

- Optionally enable **“Set client connection encryption level”** with High Level.

Every supported Windows client supports NLA. Old thin clients or third-party RDP apps that do not will get an error that the remote computer requires NLA; update them rather than turning NLA off.

## Step 3: Open the firewall with Group Policy

Enabling the listener does not open the Windows Firewall. To enable Remote Desktop with Group Policy end to end, add the predefined rules to the same GPO:

- Go to `Computer Configuration » Policies » Windows Settings » Security Settings » Windows Defender Firewall with Advanced Security » Windows Defender Firewall with Advanced Security » Inbound Rules`.

- Right-click **Inbound Rules**, choose **New Rule**, select **Predefined** and pick **Remote Desktop** from the list.

- Keep **Remote Desktop – User Mode (TCP-In)** and **Remote Desktop – User Mode (UDP-In)** ticked. Untick **Remote Desktop – Shadow (TCP-In)** unless you use session shadowing.

- Choose **Allow the connection** and click **Finish**.

- Open each new rule, go to the **Scope** tab and under **Remote IP address** add only your admin subnet or VPN range, for example `10.10.50.0/24`.

The rules apply to all profiles by default. On the **Advanced** tab you can limit them to the Domain profile, but laptops at home will then refuse RDP over VPN if the VPN adapter is not in the Domain profile, so test first.

On a single machine, the same rule group is enabled with:

```
Enable-NetFirewallRule -DisplayGroup "Remote Desktop"
```

## Step 4: Control who can connect

By default, members of the local **Administrators** and **Remote Desktop Users** groups may sign in through Remote Desktop. The cleanest way to add your support staff is a Local Users and Groups preference, which adds members without removing existing ones.

- Go to `Computer Configuration » Preferences » Control Panel Settings » Local Users and Groups`, right-click and choose **New » Local Group**.

- Set **Action** to Update and pick **Remote Desktop Users (built-in)** from the **Group name** list.

- Click **Add**, browse to CONTOSO\SG-RDP-Workstations, leave the action as Add to this group and click **OK** twice.

Restricted Groups (`Computer Configuration » Policies » Windows Settings » Security Settings » Restricted Groups`) also works. Use **This group is a member of** to add a domain group to Remote Desktop Users; the **Members of this group** list replaces the whole membership and removes anyone not listed.

### User rights

The right **“Allow log on through Remote Desktop Services”** under `Computer Configuration » Policies » Windows Settings » Security Settings » Local Policies » User Rights Assignment` already includes Administrators and Remote Desktop Users on member computers. Only define it if you want to narrow it, and always list both groups, because defining it replaces the local list. Consider adding **Local account** to **“Deny log on through Remote Desktop Services”** so local accounts cannot be used for RDP.

## Step 5 (optional): Change the listening port

A different port hides RDP from casual scans but is not a security control. If you still want it, deploy the value with a Group Policy Preferences registry item:

- Hive HKEY_LOCAL_MACHINE, key `SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp`, value `PortNumber`, type REG_DWORD, decimal data such as `3390`.

- Create custom inbound firewall rules for TCP and UDP on the new port, because the predefined rules only cover 3389.

- Restart the computer (or the Remote Desktop Services service) and connect with `pc01.contoso.com:3390`.

```
Get-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name PortNumber
```

## One machine: PowerShell and registry

For a Server Core box or a machine outside the domain, run from an elevated PowerShell:

```
Set-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections -Value 0
Set-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication -Value 1
Enable-NetFirewallRule -DisplayGroup "Remote Desktop"
Add-LocalGroupMember -Group "Remote Desktop Users" -Member "CONTOSO\SG-RDP-Workstations"
```

These are the local values, not the policy values, so a GPO that sets the policy later wins over them. On Server Core, `sconfig` option **Remote desktop** does the same interactively.

## Intune equivalents

- **Listener and NLA:** create a **Settings catalog** profile for Windows 10 and later, browse to **Administrative templates » Windows Components » Remote Desktop Services » Remote Desktop Session Host** and enable **Allow users to connect remotely by using Remote Desktop Services** (Connections) and **Require user authentication for remote connections by using Network Level Authentication** (Security).

- **Firewall:** in **Endpoint security » Firewall » Create policy**, choose **Windows** and **Windows Firewall Rules**, and add an inbound Allow rule for TCP and UDP 3389 with your remote address range.

- **Who can connect:** in **Endpoint security » Account protection**, create a **Local user group membership** profile for **Remote Desktop Users** with action Add (Update). Microsoft notes that Entra groups added this way do not apply to Remote Desktop connections on Entra-joined devices, so add individual users by SID or UPN.

## Access from outside the office

If you enable Remote Desktop with Group Policy on laptops or servers that staff reach from home, do not publish 3389 on the internet router. Use one of these instead:

- A VPN, with the firewall rule scope set to the VPN address pool.

- An RD Gateway, which wraps RDP in HTTPS on port 443 and can require multifactor authentication through Network Policy Server.

- For Azure-hosted machines, Azure Bastion or Azure Virtual Desktop instead of a public IP.

Also enable account lockout in the domain password policy, so password guessing against RDP stops quickly.

## Targeting and exceptions

- Link the GPO only to OUs that need RDP, such as servers and IT workstations, not the whole domain.

- Use separate GPOs for servers and workstations, because the allowed groups and firewall scopes differ.

- To exclude a few machines in the OU, add their computer accounts to a group and deny **Apply group policy** on the GPO’s Delegation tab.

- On domain controllers, only administrators may use Remote Desktop by default. Keep it that way and do not link a workstation GPO to the Domain Controllers OU.

## Verify it works

Check each gate in order after you enable Remote Desktop with Group Policy on a pilot machine:

- On the target computer:

```
gpupdate /forcegpresult /scope computer /rreg query "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services"Get-NetFirewallRule -DisplayGroup "Remote Desktop" | Format-Table DisplayName, Enabled, Profilenet localgroup "Remote Desktop Users"
```

You should see `fDenyTSConnections` 0x0, `UserAuthentication` 0x1, enabled rules and your group.

- From an admin PC, test the port:

```
Test-NetConnection pc01.contoso.com -Port 3389
```

`TcpTestSucceeded : True` means the listener and firewall are open.

- Connect with `mstsc /v:pc01.contoso.com` as a member of the support group.

- On the target, check event **1149** in `Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational` (network authentication succeeded) and event **4624** with logon type **10** in the Security log.

## Troubleshooting

Most failures after you enable Remote Desktop with Group Policy map to one of the four gates above. Start with the port test, then the group, then the policy result.

| Symptom | Likely cause | Fix |
| --- | --- | --- |
| TcpTestSucceeded : False | Firewall rule missing, wrong profile or wrong scope | Check Get-NetFirewallRule and the rule’s Remote IP scope and profile |
| “To sign in remotely, you need the right to sign in through Remote Desktop Services” | User not in Remote Desktop Users, or the user right was overwritten | Check net localgroup and the “Allow log on through Remote Desktop Services” policy |
| Client says the remote computer requires NLA | Old client without NLA support | Update the client; keep NLA on |
| Settings shows Remote Desktop off and greyed out | Policy set to Disabled in another GPO | Find the winning GPO in gpresult /h |
| Works on 3389 but not the new port | No firewall rule for the custom port, or no restart | Add TCP and UDP rules for the port and restart |
| Entra users denied on an Entra-joined PC | Entra group in Remote Desktop Users is not honoured for RDP | Add the users individually |
| CredSSP encryption oracle error | Client or server missing updates | Patch both sides; do not lower the CredSSP policy |

## Roll back or undo

- Set “Allow users to connect remotely by using Remote Desktop Services” to **Disabled** to block new connections everywhere the GPO applies. **Not Configured** only removes the policy value and leaves each machine’s local setting as it was.

- Delete the Remote Desktop inbound rules from the GPO; they disappear from clients at the next refresh.

- Change the Local Group preference action to remove the members, or use **Delete** on the item.

- If you changed the port, set `PortNumber` back to 3389 and restart.

Once the pilot works, you can enable Remote Desktop with Group Policy for other OUs by linking the same GPO, and keep the firewall scope and group membership as the real access controls.

## Enable Remote Desktop with Group Policy at a glance

**Official documentation:** [RemoteDesktopServices Policy CSP](https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-remotedesktopservices), [Change the listening port for Remote Desktop](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/clients/change-listening-port), [Account protection policy in Intune](https://learn.microsoft.com/en-us/intune/device-configuration/endpoint-security/account-protection).

**Related guides:** [Manage local administrators with Group Policy (Restricted Groups vs GPP)](/guides/local-administrators-group-policy/) · [Windows Firewall rules with Group Policy](/guides/windows-firewall-group-policy/) · [RDP connection logs and event IDs](/guides/rdp-connection-logs-event-ids/).

## Frequently asked questions

### Which Group Policy setting enables Remote Desktop?

“Allow users to connect remotely by using Remote Desktop Services” under Computer Configuration » Policies » Administrative Templates » Windows Components » Remote Desktop Services » Remote Desktop Session Host » Connections. It sets fDenyTSConnections to 0, but you still need firewall rules and group membership.

### Does enabling the policy open the firewall?

No. Add the predefined Remote Desktop inbound rules to the GPO under Windows Defender Firewall with Advanced Security, and limit their remote IP scope to your admin or VPN range.

### How do I let non-admin users connect with RDP?

Add their group to the local Remote Desktop Users group with a Local Users and Groups preference or Restricted Groups. That group already has the “Allow log on through Remote Desktop Services” right on member computers.

### Should I change the RDP port from 3389?

Only as a minor extra. It hides RDP from basic scans but is not a security control; restrict the firewall scope, require NLA and use a VPN or RD Gateway instead.

### How do I test that RDP is reachable?

Run Test-NetConnection with the computer name and -Port 3389 from an admin PC. TcpTestSucceeded True means the listener and firewall are open; then connect with mstsc.
