How to secure a new Windows Server in the first hour
First-hour checklist for Windows Server 2022 and 2025: updates, named admins, NLA, Remote Desktop limited by IP, account lockout, Defender and audit logs.
- Intermediate
- 25 min read
- Updated
Tested on: Windows Server 2022, Windows Server 2025
This guide is not available in your language yet, so it is shown in English.
On this page
- Before you start
- Step 1: Install all updates
- Step 2: Use named administrator accounts
- Step 3: Keep Network Level Authentication on
- Step 4: Limit Remote Desktop to your IP addresses
- Step 5: Set an account lockout policy
- Step 6: Check Microsoft Defender Antivirus
- Step 7: Remove what you do not need
- Step 8: Watch sign-ins
- Step 9: Back up
- Troubleshooting
- Next steps
A new Windows server is scanned for Remote Desktop within minutes of going online. This checklist for Windows Server 2022 and 2025 closes the common gaps. Run the PowerShell commands in a window opened with Run as administrator.
Before you start
- You can sign in with Remote Desktop; see first steps on a Windows server.
- Know your own public IP address (or addresses) for the Remote Desktop allow list.
- Take a snapshot first where your plan offers one (Windows VPS plans include free snapshots).
Step 1: Install all updates
Open Settings › Windows Update and install everything, or use SConfig option 6. Set automatic updates with SConfig option 5. See automatic updates.
Verify: after the restart, Windows Update reports the server is up to date.
Step 2: Use named administrator accounts
Create a personal administrator account, so actions in the logs carry a name and you have a second way in:
$password = Read-Host -AsSecureString
New-LocalUser -Name "alex" -Password $password -FullName "Alex"
Add-LocalGroupMember -Group "Administrators" -Member "alex"Give the built-in Administrator a long, unique password (net user Administrator *) and keep it as an emergency account, or disable it once you have confirmed the new account works.
Verify: sign in as alex and run whoami /groups; BUILTIN\Administrators is listed.
Step 3: Keep Network Level Authentication on
NLA requires authentication before a full Remote Desktop session starts, which blocks many attacks. Check it:
(Get-CimInstance -Namespace root\cimv2\TerminalServices -ClassName Win32_TSGeneralSetting -Filter "TerminalName='RDP-tcp'").UserAuthenticationRequired1 means NLA is required. SConfig option 7 can set it if needed.
Step 4: Limit Remote Desktop to your IP addresses
Restrict the built-in Remote Desktop firewall rules to your own addresses. Replace the example addresses with yours:
Set-NetFirewallRule -DisplayGroup "Remote Desktop" -RemoteAddress 198.51.100.7, 203.0.113.0/24Keep your current session open and connect a second session to confirm you still get in. For teams with changing addresses, put Remote Desktop behind a VPN instead. More: Windows Defender Firewall rules.
Step 5: Set an account lockout policy
Lockout slows down password guessing. Show the current policy, then set a threshold and duration:
net accounts
net accounts /lockoutthreshold:10 /lockoutduration:15 /lockoutwindow:15This locks an account for 15 minutes after 10 failed sign-ins within 15 minutes. Balance it: too strict a threshold lets attackers lock you out on purpose.
Verify: net accounts shows the new values.
Step 6: Check Microsoft Defender Antivirus
Get-MpComputerStatus | Select-Object AMServiceEnabled, AntivirusEnabled, RealTimeProtectionEnabled, AntivirusSignatureLastUpdated
Update-MpSignatureAll three Enabled values should be True, and the signature date recent.
Step 7: Remove what you do not need
List installed roles and features and remove those you do not use:
Get-WindowsFeature | Where-Object InstalledCheck what listens on the network, and close or restrict anything unexpected:
Get-NetTCPConnection -State Listen | Sort-Object LocalPort | Select-Object LocalAddress, LocalPort, OwningProcessStep 8: Watch sign-ins
Failed sign-ins are event 4625, successful ones 4624, in the Security log:
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625} -MaxEvents 20 | Select-Object TimeCreated, MessageA steady stream of failures from many addresses means Remote Desktop is exposed; restrict it (Step 4). A successful sign-in you do not recognise means you should change passwords at once and follow what to do if your server is hacked.
Step 9: Back up
Keep backups of important data away from the server and test restores. See backup strategy for Windows Server Backup and off-site copies.
Troubleshooting
Remote Desktop stopped working after Step 4. Your public IP address is not in the list, or it changed. Use the web console and run Set-NetFirewallRule -DisplayGroup "Remote Desktop" -RemoteAddress Any, then add the right address. See locked out after a firewall change.
Your account is locked. Wait for the lockout duration, or unlock it from another administrator account: net user alex /active:yes re-enables a disabled account; the lockout clears after the set duration.
The firewall group name is not found. On a server installed in another language the display group differs. Find it with Get-NetFirewallRule -DisplayGroup "*Remote*".
Next steps
- Fine-grained rules: Windows Defender Firewall rules.
- Connection problems: Remote Desktop connection problems.
Frequently asked questions
Is it enough to change the Remote Desktop port?
No. A different port reduces automated attempts, but scanners find it. Restricting Remote Desktop to your IP addresses, or putting it behind a VPN, and strong passwords with an account lockout policy protect the server.
Should I rename or disable the Administrator account?
Create a named administrator for daily work first. You can then disable the built-in Administrator or keep it with a long, unique password as an emergency account. Never remove your only way in.
Do I need extra antivirus software?
Microsoft Defender Antivirus is built into Windows Server and is enough for most servers when it is on and up to date. Check its status with Get-MpComputerStatus.
How can I see failed sign-in attempts?
In the Security log, event ID 4625 records failed sign-ins and 4624 successful ones. Get-WinEvent can filter them, as shown in this guide.
What if a security setting locks me out?
Use the web console if your service page shows one, or open a support ticket. Test every change with a second Remote Desktop session before you close the first.
Sources
- learn.microsoft.com/en-us/windows-server/administration/windows-com…
- learn.microsoft.com/en-us/powershell/module/defender/get-mpcomputer…
- learn.microsoft.com/en-us/powershell/module/defender/update-mpsigna…
- learn.microsoft.com/en-us/powershell/module/microsoft.powershell.di…
- learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-…
- learn.microsoft.com/en-us/powershell/module/netsecurity/set-netfire…
- learn.microsoft.com/en-us/windows-server/administration/server-core…