Guides · RDP-FIDO-GATE

How to protect Windows RDP with a FIDO2 security key

Windows can sign you in to Remote Desktop with a security key only when the machine is joined to Microsoft Entra ID. On a standalone PC, a workgroup server or a classic Active Directory domain there is no built-in way. This guide shows a setup that works anywhere: the RDP port stays closed until a registered key is touched.

Updated

Why a key in front of RDP, not inside it

Most RDP break-ins do not defeat the login screen — they reach it. Port 3389 is scanned around the clock, and once it answers, attackers try stolen passwords and unpatched pre-authentication bugs.

A gate in front of RDP changes the order of events. The port is blocked by the Windows Firewall by default. You prove possession of a hardware key first; only then does the firewall open 3389 — for your IP address alone and for about 90 seconds. To everyone else the port never answers.

What you need

Step 1. Install the gate on the host

  1. Download RdpFido-Setup.exe on the machine you want to reach, run it and choose Host. Windows asks for administrator confirmation.
  2. The installer enables Remote Desktop with NLA, binds a TLS certificate to the gate port 7440 and starts the gate service.
  3. The last page shows a one-time key enrollment code, valid for 15 minutes, together with the machine's addresses. Note the address and the code.
  4. If the code expires, run RdpFidoGate.exe code as administrator to get a new one.

For a management system the gate installs silently: msiexec /i RdpFidoGate-Setup.msi /qn.

Step 2. Forward the ports (internet access only)

On the same LAN you can skip this step. From the internet, forward two ports on the router to the host's LAN address:

External portProtocolPurpose
7440TCPThe gate: control channel and key confirmation
3389TCPRDP — passes only while the gate holds it open for your IP

Reserve the host's LAN address in the router's DHCP settings, and use a DDNS name if your public IP changes. Forwarding 3389 does not expose RDP: the host firewall keeps it blocked until the key is confirmed.

Step 3. Install the client and enroll the key

  1. On your own PC run the same RdpFido-Setup.exe and choose Client. It installs per user and needs no administrator rights.
  2. Activate the client with your e-mail address: a code arrives by mail.
  3. Add a session: the host address, gate port 7440 and the one-time enrollment code from step 1.
  4. Touch the key when asked. The key is now registered for this host.

Step 4. Connect

Click the session tile and touch the key. The gate verifies the WebAuthn signature, opens 3389 for your current IP for about 90 seconds and the client starts mstsc. Windows then asks for its own password as usual — so the session is protected by two independent factors.

The gate re-asserts the firewall block every 30 seconds, so an opening cannot be left behind.

Check that it works

RDP-FIDO-GATE

RDP-FIDO-GATE keeps port 3389 closed and opens it for one IP, for about 90 seconds, only after a FIDO2 key touch or an authenticator code. The Free edition covers 10 saved sessions.

Frequently asked questions

Does this need Microsoft Entra ID, a domain or an RD Gateway?

No. The gate uses only what is in Windows itself: the Windows Firewall, the Windows WebAuthn API and DPAPI. It works on a workgroup PC, a domain member and a cloud VM alike.

What if I lose the key?

Enroll a second key in advance, or issue a new enrollment code on the host with RdpFidoGate.exe code — that requires administrator access to the host itself, for example from the local console.

Is the Windows password still required?

Yes. The key opens the port; Windows then authenticates the user with its own credentials. A stolen password alone cannot reach the login screen, and a stolen key alone cannot pass it.

Can several people use one host?

Yes. Each person enrolls their own key with an enrollment code issued on the host; every key opens the port only for the address it connects from.

Related guides