The questions you will meet
- Is multi-factor authentication required for all remote access to the network?
- Is Remote Desktop Protocol (RDP) accessible from the internet? If yes, how is it protected?
- Is MFA required for administrator and privileged accounts?
- Which MFA methods are in use — SMS, app, hardware token?
The wording differs between insurers, but the intent is the same: exposed RDP with password-only logins is one of the most common ways ransomware gets in, and underwriters want to see it closed.
What “phishing-resistant MFA” means
Not all second factors are equal. SMS codes can be intercepted or redirected, app codes can be read out to a caller, and push prompts can be approved by a tired user. CISA's guidance on implementing phishing-resistant MFA and NIST SP 800-63B both single out authenticators where the secret never leaves the device and the response is cryptographically bound to the service — in practice, FIDO2 / WebAuthn security keys and platform authenticators.
An application may not use the phrase, but a hardware-key answer is the one that never needs a follow-up question.
Meeting the RDP questions with a port gate
RDP-FIDO-GATE addresses both RDP questions with one control on the host:
- “Is RDP accessible from the internet?” — Port 3389 is blocked by the Windows Firewall by default and does not answer scans. It opens for a single IP for about 90 seconds after authentication.
- “Is MFA required for remote access?” — The port opens only after a FIDO2 key touch; Windows then requires the account password. That is two independent factors, the first of them phishing-resistant.
- “Which methods?” — FIDO2 / WebAuthn hardware keys. Where keys are not available a gate can run with authenticator-app codes instead; report that as app-based OTP.
A rollout plan for a small office
- List every machine reachable by RDP from outside — including the forgotten port forward on the router.
- Buy two FIDO2 keys per person who needs remote access: one to use, one as a spare kept in a safe place.
- Install the gate on each host and enroll both keys. The setup guide covers it.
- Confirm from outside that 3389 does not answer:
Test-NetConnection <host> -Port 3389must fail before a key touch. - Keep evidence for the application: a dated external scan showing 3389 closed and a short written procedure for enrolling and revoking keys.
What this does not cover
A questionnaire asks about more than RDP: e-mail MFA, backups, endpoint protection, patching. The gate is a technical control for remote desktop access only. It is not legal or insurance advice — read your insurer's definitions and answer each question as it is written.