Changing the Remote Desktop port takes more than editing a number in Windows. The host’s listening port, firewall rules, and connection address all need to line up. Start with Registry Editor, then allow the new port and reconnect using the steps below.
Before you change the port
Make these changes on the host PC, the computer you want to access remotely. You need administrator access and an RDP-capable edition of Windows, such as Windows 11 Pro, Enterprise, or Education. Windows Home can connect to another PC but cannot host built-in Remote Desktop.
Back up the registry before editing it. If you’re changing a computer remotely, arrange another way to regain access. Remote Desktop must already be enabled under Settings > System > Remote Desktop.
The examples use port 3390, which must be available on your host. Use your chosen number consistently in the registry, firewall rules, and connection address. No download is required.
Change the listening port in Registry Editor
Open Registry Editor with administrator privileges on the host PC, then navigate to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp. Select PortNumber and choose Edit > Modify.
Select Decimal so you can enter the port as an ordinary decimal number. Enter 3390, or your chosen port, in Value data, then select OK.
Close Registry Editor. The firewall changes below come next, before you restart the PC.
If you cannot make the change in Registry Editor, try the administrator PowerShell method later on this page. It updates the same setting and still requires the firewall changes and a restart.
Allow the new port through Windows Firewall
These rules let incoming Remote Desktop traffic reach your new listening port. Open Windows Firewall with Advanced Security and select Inbound Rules.
Choose Action > New rule, then select Custom and click Next. Choose All programs, then click Next.
On Protocol and Ports, select TCP as the protocol. Set the local port to 3390, or your chosen number, then continue to Scope. Restrict the addresses allowed to connect as appropriate for your network.
On Action, choose Allow the connection. On Profile, select the network profiles on which you intend to allow the connection. On Name, enter a recognizable rule name, such as RDP-3390-TCP, then select Finish to create the rule. Repeat the rule-creation process with UDP and the same local port, using a name such as RDP-3390-UDP.
Restart and connect with the new address
Restart the host PC after the registry change and both firewall rules are in place. Open Remote Desktop Connection on the computer you’re connecting from.
In Computer, enter the host name followed by a colon and the port, such as pc1:3390, using your host’s name in place of pc1. Select Connect. Tip: You can also launch the connection with mstsc /v:pc1:3390 from Run or a terminal, or use that command as a shortcut target.
Use PowerShell as an alternative
Prefer a command? PowerShell changes the same registry value as Registry Editor, so you only need one of these methods.
Open PowerShell as administrator on the host PC. To set port 3390, run Set-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name 'PortNumber' -Value 3390.
You can also create both firewall rules here. These examples allow connections on the Private profile for a trusted network. Substitute your chosen port and the actual intended firewall profile.
Create the TCP rule with New-NetFirewallRule -DisplayName 'RDP-3390-TCP' -Direction Inbound -Action Allow -Protocol TCP -LocalPort 3390 -Profile Private. Create the UDP rule with New-NetFirewallRule -DisplayName 'RDP-3390-UDP' -Direction Inbound -Action Allow -Protocol UDP -LocalPort 3390 -Profile Private.
Restart the host PC to apply the listening-port change. Connect using the host name and new port, such as pc1:3390.
If the registry command fails, reopen PowerShell using Run as administrator and retry, or use Registry Editor. If a firewall command fails, create the matching rule through Windows Firewall with Advanced Security using the steps above.
If Remote Desktop no longer connects
Check that PortNumber, both firewall rules, and the port entered in Computer all match. Confirm that the host was restarted. In Windows Firewall with Advanced Security, check that the rules apply to the intended network profile.
For a connection that already uses router port forwarding, the router’s internal destination port must match the Windows listening port. The external port can be different, and your connection address must use that external port. Microsoft recommends a VPN over exposing RDP through internet port forwarding; changing the port does not replace authentication or secure network access.
On a work or managed PC, contact your administrator if the change or connection is blocked. Managed firewall policy can restrict local rules.
Frequently Asked Questions
Can I change the listening port in Windows Settings?
No. Settings > System > Remote Desktop is where you enable Remote Desktop access, but Microsoft documents changing the listening port only through the PortNumber registry value. Change it using Registry Editor or administrator PowerShell.
Does this also work on Windows 10?
Microsoft documents the listening-port change for Windows 10, but ordinary Windows 10 support ended on October 14, 2025. ESU and LTSC servicing depend on your installation.
Which Windows Server versions support this method?
Microsoft documents the listening-port change for Windows Server 2025, 2022, 2019, and 2016.
Was the built-in Remote Desktop Connection client retired?
No. The Microsoft Store Remote Desktop app reached end of support on May 27, 2025, and is no longer available to download. That retirement does not apply to the built-in Remote Desktop Connection client, mstsc.exe. Windows App is the current alternative to the retired Store app, but its remote PC connections on Windows are in preview. For a generally available client on Windows, keep using Remote Desktop Connection (mstsc.exe).