forumNew topic

If I enabled Remote Desktop (RDP) on office computers, can someone connect from the internet?

GGamze K***MemberCommunity member
Joined
Oct 2022
Message
3
#1

We had trouble working from home and needed access to the office computers, so we enabled RDP. We turned on Windows built-in Remote Desktop, Port 3389. We emailed passwords to all employees (standard passwords, not complex). Maybe it was wrong to do, but now all computers are accessible from the internet.

A friend told us today: 'Opening RDP to the internet is bad'. Why? The password is strong, we have antivirus. Are people trying to attack via SSH or similar methods?

I can't disable RDP right now (employees are working remotely). But how can I secure it? Do I need to set up a VPN? Or is there another way?

ZZerrin U***MemberCommunity member
Joined
Oct 2024
Message
3
Most Helpful#2

Exposing RDP directly to the internet makes it vulnerable to brute force attacks. Thousands of bots scan port 3389 and guess passwords (even if the password is strong, it can be cracked with 100k attempts). Steps: 1) Change the RDP port (e.g., 12345 instead of 3389), 2) Enable Network Level Authentication (NLA) (in RDP properties), 3) All passwords min 16 chars, uppercase+lowercase+number+special char, 4) Fail2ban or rate limiting (block after X attempts), 5) Use a VPN (RDP accessible only via VPN), 6) IP whitelist (only company IPs). 7) Don't use RDP Wrapper v2 (deprecated), 8) Harden Windows Firewall rules, 9) Session timeout and idle disconnect, 10) Log and monitor RDP connections, 11) Install Network Intrusion Detection (IDS). BEST PRACTICE: VPN + RDP combo (connect to VPN then RDP).

ÜÜlkü S***MemberCommunity member
Joined
Oct 2024
Message
118
#3

opening rdp to the internet is weird, they just brute force it. changing the port doesn't help much. set up a vpn, then rdp. but setup is a bit hard...

Edit: asked below, I wrote the answer in the second message.

PPolat G***Member
Job title
Graphic Designer
Sector
Law
Organization type
workshop
Joined
Nov 2023
Message
29

Doki · SEO consulting · 2023

#4

RDP bruteforce attacks basic tools: Hydra, Medusa, Masscan + RDP password list. An internet-exposed 3389 gets thousands of attempts per minute. Mitigation: 1) check nla_enforce and security layer: HKCU/Software/Policies/Microsoft/Windows NT/Terminal Services/SecurityLayer value 2 (default 0), 2) IP restriction: netsh advfirewall firewall add rule name='RDP restrict' dir=in action=block protocol=tcp localport=3389 /*, 3) VPN + RDP stacked deployment, 4) log monitoring with Siem.

RRecep S***ExpertCommunity member
Joined
Mar 2024
Message
243
#5

Leaving RDP open is pretty risky. Best bet is to set up a VPN, takes an hour then force everyone to access the network via VPN... RDP should only be open through the VPN. But if setting up a VPN is hard for you: change the port, make the password strong and only allow access from your companys IP in the firewall. fail2ban is for Linux, not Windows so stick with VPN...

EEmre P***Member
Job title
Field sales representative
Sector
Cosmetics
Organization type
medium-sized business
Joined
Nov 2022
Message
55
#6

Remote access strategies: 1) VPN (OpenVPN, WireGuard): encrypted tunnel, IP masked, best for small teams, 2) Bastion Host (Jump Server): acts like a proxy, RDP only accessible from the bastion, 3) Zero Trust Access (Teleport, Gravitational): device verification, behavioral analytics, 4) RDP Gateway: Windows Server role, session logging. For SMEs, VPN is recommended — easy setup, low cost, high security.

ZZeynep K***MemberCommunity member
Joined
Feb 2024
Message
41
#7

If they gave out standard passwords via email, that's risky too. Do all employees have the same password? Or is each one different? If it's the same, once one is compromised, all computers are exposed. And did you check if NLA is enabled? On most systems it's disabled by default or weak...

GGürkan K***MemberCommunity member
Joined
Sep 2025
Message
189
#8

If I understood correctly, youre saying: Taking measures without an inventory leaves doors you havent seen open.

MMustafa G***Member
Job title
Purchasing manager
Sector
Furniture manufacturing
Organization type
medium-sized business
Joined
Dec 2022
Message
72
#9

Timely topic. An untested backup is not a backup.

Hope this helps.

UUğur Ö***Member
Job title
Sales Manager
Sector
IT services
Organization type
regional distributor
Joined
Jan 2024
Message
5

Doki · Brand identity · 2026

#10

Could you elaborate on that? Processes without records never improve because you don't know what to fix.

Any unwritten clause becomes a point of disagreement later as both sides remember it differently. Correct me if I'm wrong.

BBarış Ç***Member
Job title
Customer Relations Manager
Sector
Furniture manufacturing
Organization type
two-branch business
Joined
Oct 2023
Message
12
#11

I can't fully agree with this. Solutions that work at a small scale collapse when you grow; I learned this late.

That's all, sorry if I went on too long.

KKadriyeMember
Job title
Ceramics workshop
Joined
Jun 2024
Message
72
#12

I went through the same thing two years ago. If you don't write this down from the start it leads to arguments later.

Just leaving this note, it might be useful.

MMustafa Ç***Member
Job title
Clinic manager
Sector
Glass
Organization type
two-branch business
Joined
Oct 2022
Message
49
#13

There's a common mistake people make when doing this. Mistakes made on the remote desktop security side are usually reversible but expensive.

The answer varies greatly by industry; there is no one-size-fits-all rule. This is my opinion, I'm not claiming it's absolute truth.

KKadir S***Expert
Job title
Warehouse Manager
Sector
Livestock
Organization type
early-stage startup
Joined
Jun 2022
Message
1
#14

I've been dealing with this for a long time. The biggest time-waster for us was not knowing who had the final say.

EElif C***MemberCommunity member
Joined
Feb 2023
Message
374
#15

Same here.

İİbrahim T***MemberCommunity member
Joined
Aug 2023
Message
279
#16

I feel the same way. When we decide without measuring, we always end up in the same place.

That's all, sorry if I went on too long.

SSinemExpert
Job title
Project manager
Joined
Oct 2023
Message
176
#17

I was thinking the same thing. Everything goes well for the first three months; problems arise in the fourth.

When making decisions, write down the worst-case scenario too, not just the best. I'm also curious if anyone does it differently.

MMerve Y***Member
Job title
Data entry clerk
Sector
E-commerce
Organization type
40-person manufacturing company
Joined
Mar 2024
Message
151
#18

Following. If you scold false alarms, nobody will report again.

Good luck with that.

DDilara U***Member
Job title
Logistics planning
Sector
Plastic
Organization type
120-person company
Joined
Oct 2025
Message
219
#19

I completely agree. People defend habits, not processes. Resistance comes from there.

Hope this helps.

SSultan Ç***New memberCommunity member
Joined
Aug 2026
Message
7
#20

I felt relieved reading this answer, so it's not just me. Most incidents start with a leaked password, not a vulnerability.

Reply