# How to secure a new Windows Server in the first hour

> First-hour checklist for Windows Server 2022 and 2025: updates, named admins, NLA, Remote Desktop limited by IP, account lockout, Defender and audit logs.

Difficulty: Intermediate\
Tested on: Windows Server 2022, Windows Server 2025

A new Windows server is scanned for Remote Desktop within minutes of going online. This checklist for Windows Server 2022 and 2025 closes the common gaps. Run the PowerShell commands in a window opened with **Run as administrator**.

## Before you start

- You can sign in with Remote Desktop; see [first steps on a Windows server](/guides/windows-server-first-steps-rdp).
- Know your own public IP address (or addresses) for the Remote Desktop allow list.
- Take a snapshot first where your plan offers one (Windows VPS plans include free snapshots).

## Step 1: Install all updates

Open **Settings › Windows Update** and install everything, or use SConfig option `6`. Set automatic updates with SConfig option `5`. See [automatic updates](/guides/automatic-updates).

**Verify:** after the restart, Windows Update reports the server is up to date.

## Step 2: Use named administrator accounts

Create a personal administrator account, so actions in the logs carry a name and you have a second way in:

```powershell
$password = Read-Host -AsSecureString
New-LocalUser -Name "alex" -Password $password -FullName "Alex"
Add-LocalGroupMember -Group "Administrators" -Member "alex"
```

Give the built-in `Administrator` a long, unique password (`net user Administrator *`) and keep it as an emergency account, or disable it once you have confirmed the new account works.

**Verify:** sign in as `alex` and run `whoami /groups`; `BUILTIN\Administrators` is listed.

## Step 3: Keep Network Level Authentication on

NLA requires authentication before a full Remote Desktop session starts, which blocks many attacks. Check it:

```powershell
(Get-CimInstance -Namespace root\cimv2\TerminalServices -ClassName Win32_TSGeneralSetting -Filter "TerminalName='RDP-tcp'").UserAuthenticationRequired
```

`1` means NLA is required. SConfig option `7` can set it if needed.

## Step 4: Limit Remote Desktop to your IP addresses

Restrict the built-in Remote Desktop firewall rules to your own addresses. Replace the example addresses with yours:

```powershell
Set-NetFirewallRule -DisplayGroup "Remote Desktop" -RemoteAddress 198.51.100.7, 203.0.113.0/24
```

**Keep your current session open** and connect a second session to confirm you still get in. For teams with changing addresses, put Remote Desktop behind a VPN instead. More: [Windows Defender Firewall rules](/guides/windows-firewall).

## Step 5: Set an account lockout policy

Lockout slows down password guessing. Show the current policy, then set a threshold and duration:

```powershell
net accounts
net accounts /lockoutthreshold:10 /lockoutduration:15 /lockoutwindow:15
```

This locks an account for 15 minutes after 10 failed sign-ins within 15 minutes. Balance it: too strict a threshold lets attackers lock you out on purpose.

**Verify:** `net accounts` shows the new values.

## Step 6: Check Microsoft Defender Antivirus

```powershell
Get-MpComputerStatus | Select-Object AMServiceEnabled, AntivirusEnabled, RealTimeProtectionEnabled, AntivirusSignatureLastUpdated
Update-MpSignature
```

All three `Enabled` values should be `True`, and the signature date recent.

## Step 7: Remove what you do not need

List installed roles and features and remove those you do not use:

```powershell
Get-WindowsFeature | Where-Object Installed
```

Check what listens on the network, and close or restrict anything unexpected:

```powershell
Get-NetTCPConnection -State Listen | Sort-Object LocalPort | Select-Object LocalAddress, LocalPort, OwningProcess
```

## Step 8: Watch sign-ins

Failed sign-ins are event 4625, successful ones 4624, in the Security log:

```powershell
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625} -MaxEvents 20 | Select-Object TimeCreated, Message
```

A steady stream of failures from many addresses means Remote Desktop is exposed; restrict it (Step 4). A successful sign-in you do not recognise means you should change passwords at once and follow [what to do if your server is hacked](/guides/hacked-server-recovery).

## Step 9: Back up

Keep backups of important data away from the server and test restores. See [backup strategy](/guides/backup-strategy-3-2-1) for Windows Server Backup and off-site copies.

## Troubleshooting

**Remote Desktop stopped working after Step 4.** Your public IP address is not in the list, or it changed. Use the web console and run `Set-NetFirewallRule -DisplayGroup "Remote Desktop" -RemoteAddress Any`, then add the right address. See [locked out after a firewall change](/guides/locked-out-after-firewall-change).

**Your account is locked.** Wait for the lockout duration, or unlock it from another administrator account: `net user alex /active:yes` re-enables a disabled account; the lockout clears after the set duration.

**The firewall group name is not found.** On a server installed in another language the display group differs. Find it with `Get-NetFirewallRule -DisplayGroup "*Remote*"`.

## Next steps

- Fine-grained rules: [Windows Defender Firewall rules](/guides/windows-firewall).
- Connection problems: [Remote Desktop connection problems](/guides/rdp-connection-problems).

## Frequently asked questions

### Is it enough to change the Remote Desktop port?

No. A different port reduces automated attempts, but scanners find it. Restricting Remote Desktop to your IP addresses, or putting it behind a VPN, and strong passwords with an account lockout policy protect the server.

### Should I rename or disable the Administrator account?

Create a named administrator for daily work first. You can then disable the built-in Administrator or keep it with a long, unique password as an emergency account. Never remove your only way in.

### Do I need extra antivirus software?

Microsoft Defender Antivirus is built into Windows Server and is enough for most servers when it is on and up to date. Check its status with Get-MpComputerStatus.

### How can I see failed sign-in attempts?

In the Security log, event ID 4625 records failed sign-ins and 4624 successful ones. Get-WinEvent can filter them, as shown in this guide.

### What if a security setting locks me out?

Use the web console if your service page shows one, or open a support ticket. Test every change with a second Remote Desktop session before you close the first.

---

Source: <https://hyperdc.com/guides/security/secure-windows-server>\
Updated: 2026-10-09
