Guides · RDP-FIDO-GATE

RDP two-factor with an authenticator app, no domain required

Not every team has hardware keys. If your people already use Google Authenticator, Microsoft Authenticator or Aegis, the same 6-digit codes can guard Remote Desktop — on a standalone Windows machine, with nothing in the cloud.

Updated

How it works

RDP-FIDO-GATE 1.23 and newer can run a gate in code mode. Port 3389 stays blocked by the Windows Firewall. The client asks for the current code from your authenticator app; when the gate accepts it, the port opens for your IP for about 90 seconds and the RDP client connects. Windows still asks for its own password afterwards.

A gate signs people in one way — with keys or with codes. The mode is chosen at installation and can be switched later.

Step 1. Install the gate in code mode

Step 2. Enroll an authenticator

  1. On the host run RdpFidoGate.exe code to get a one-time enrollment code.
  2. In the client add a session with the host address, port 7440 and that code.
  3. The client shows a QR code and the secret. Scan it with the authenticator app.
  4. Type the first 6-digit code from the app to confirm. The account is enrolled.

An administrator can also create an account on the gate itself: RdpFidoGate.exe totp add NAME prints the QR code in the console, and totp test NAME CODE checks a code.

Step 3. Connect

Click the session, type the current code, and the RDP session opens. Each code is accepted once only, so a code seen over someone's shoulder cannot be replayed.

Limits worth knowing

Codes or keys?

Authenticator codeFIDO2 key
Hardware to buyNone — a phone appA security key per person (or Windows Hello)
Phishing-resistantNoYes
Opens RDPYesYes
Opens FIDO StreamNoYes
Works offline on the user sideYesYes

RDP-FIDO-GATE

RDP-FIDO-GATE keeps port 3389 closed and opens it for one IP, for about 90 seconds, only after a FIDO2 key touch or an authenticator code. The Free edition covers 10 saved sessions.

Frequently asked questions

Which authenticator apps work?

Any app that implements standard time-based one-time passwords (TOTP): Google Authenticator, Microsoft Authenticator, Aegis, FreeOTP, password managers with a TOTP field and others.

Does the host need internet access to check a code?

No. The code is verified on the gate itself from the shared secret and the clock. Keep the host's time synchronised.

Can one gate accept both keys and codes?

No. A gate works in one mode, chosen at setup and switched with the auth command. Run key mode where you need phishing resistance and FIDO Stream.

Does it work on a Linux host?

Yes. The gate is also packaged for Linux, where the command is rdpfido-gate auth totp and the enrollment code comes from sudo rdpfido-gate code.

Related guides