Skip to content

SecurityServer hardening

How to secure a new Windows Server in the first hour

First-hour checklist for Windows Server 2022 and 2025: updates, named admins, NLA, Remote Desktop limited by IP, account lockout, Defender and audit logs.

  • Intermediate
  • 25 min read
  • Updated

Tested on: Windows Server 2022, Windows Server 2025

This guide is not available in your language yet, so it is shown in English.

On this page
  1. Before you start
  2. Step 1: Install all updates
  3. Step 2: Use named administrator accounts
  4. Step 3: Keep Network Level Authentication on
  5. Step 4: Limit Remote Desktop to your IP addresses
  6. Step 5: Set an account lockout policy
  7. Step 6: Check Microsoft Defender Antivirus
  8. Step 7: Remove what you do not need
  9. Step 8: Watch sign-ins
  10. Step 9: Back up
  11. Troubleshooting
  12. Next steps

A new Windows server is scanned for Remote Desktop within minutes of going online. This checklist for Windows Server 2022 and 2025 closes the common gaps. Run the PowerShell commands in a window opened with Run as administrator.

Before you start

  • You can sign in with Remote Desktop; see first steps on a Windows server.
  • Know your own public IP address (or addresses) for the Remote Desktop allow list.
  • Take a snapshot first where your plan offers one (Windows VPS plans include free snapshots).

Step 1: Install all updates

Open Settings › Windows Update and install everything, or use SConfig option 6. Set automatic updates with SConfig option 5. See automatic updates.

Verify: after the restart, Windows Update reports the server is up to date.

Step 2: Use named administrator accounts

Create a personal administrator account, so actions in the logs carry a name and you have a second way in:

PowerShell
$password = Read-Host -AsSecureString
New-LocalUser -Name "alex" -Password $password -FullName "Alex"
Add-LocalGroupMember -Group "Administrators" -Member "alex"

Give the built-in Administrator a long, unique password (net user Administrator *) and keep it as an emergency account, or disable it once you have confirmed the new account works.

Verify: sign in as alex and run whoami /groups; BUILTIN\Administrators is listed.

Step 3: Keep Network Level Authentication on

NLA requires authentication before a full Remote Desktop session starts, which blocks many attacks. Check it:

PowerShell
(Get-CimInstance -Namespace root\cimv2\TerminalServices -ClassName Win32_TSGeneralSetting -Filter "TerminalName='RDP-tcp'").UserAuthenticationRequired

1 means NLA is required. SConfig option 7 can set it if needed.

Step 4: Limit Remote Desktop to your IP addresses

Restrict the built-in Remote Desktop firewall rules to your own addresses. Replace the example addresses with yours:

PowerShell
Set-NetFirewallRule -DisplayGroup "Remote Desktop" -RemoteAddress 198.51.100.7, 203.0.113.0/24

Keep your current session open and connect a second session to confirm you still get in. For teams with changing addresses, put Remote Desktop behind a VPN instead. More: Windows Defender Firewall rules.

Step 5: Set an account lockout policy

Lockout slows down password guessing. Show the current policy, then set a threshold and duration:

PowerShell
net accounts
net accounts /lockoutthreshold:10 /lockoutduration:15 /lockoutwindow:15

This locks an account for 15 minutes after 10 failed sign-ins within 15 minutes. Balance it: too strict a threshold lets attackers lock you out on purpose.

Verify: net accounts shows the new values.

Step 6: Check Microsoft Defender Antivirus

PowerShell
Get-MpComputerStatus | Select-Object AMServiceEnabled, AntivirusEnabled, RealTimeProtectionEnabled, AntivirusSignatureLastUpdated
Update-MpSignature

All three Enabled values should be True, and the signature date recent.

Step 7: Remove what you do not need

List installed roles and features and remove those you do not use:

PowerShell
Get-WindowsFeature | Where-Object Installed

Check what listens on the network, and close or restrict anything unexpected:

PowerShell
Get-NetTCPConnection -State Listen | Sort-Object LocalPort | Select-Object LocalAddress, LocalPort, OwningProcess

Step 8: Watch sign-ins

Failed sign-ins are event 4625, successful ones 4624, in the Security log:

PowerShell
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625} -MaxEvents 20 | Select-Object TimeCreated, Message

A steady stream of failures from many addresses means Remote Desktop is exposed; restrict it (Step 4). A successful sign-in you do not recognise means you should change passwords at once and follow what to do if your server is hacked.

Step 9: Back up

Keep backups of important data away from the server and test restores. See backup strategy for Windows Server Backup and off-site copies.

Troubleshooting

Remote Desktop stopped working after Step 4. Your public IP address is not in the list, or it changed. Use the web console and run Set-NetFirewallRule -DisplayGroup "Remote Desktop" -RemoteAddress Any, then add the right address. See locked out after a firewall change.

Your account is locked. Wait for the lockout duration, or unlock it from another administrator account: net user alex /active:yes re-enables a disabled account; the lockout clears after the set duration.

The firewall group name is not found. On a server installed in another language the display group differs. Find it with Get-NetFirewallRule -DisplayGroup "*Remote*".

Next steps

Frequently asked questions

Is it enough to change the Remote Desktop port?

No. A different port reduces automated attempts, but scanners find it. Restricting Remote Desktop to your IP addresses, or putting it behind a VPN, and strong passwords with an account lockout policy protect the server.

Should I rename or disable the Administrator account?

Create a named administrator for daily work first. You can then disable the built-in Administrator or keep it with a long, unique password as an emergency account. Never remove your only way in.

Do I need extra antivirus software?

Microsoft Defender Antivirus is built into Windows Server and is enough for most servers when it is on and up to date. Check its status with Get-MpComputerStatus.

How can I see failed sign-in attempts?

In the Security log, event ID 4625 records failed sign-ins and 4624 successful ones. Get-WinEvent can filter them, as shown in this guide.

What if a security setting locks me out?

Use the web console if your service page shows one, or open a support ticket. Test every change with a second Remote Desktop session before you close the first.

Sources

Генерирај лозинка

Please confirm