Guides · RDP-FIDO-GATE

MFA for Remote Desktop: the four approaches compared

“Add MFA to RDP” can mean four quite different architectures. They differ in where the second factor is checked — before the network connection, at a gateway, or at the Windows logon — and in how much infrastructure they need. This comparison is meant to help you pick one, not to sell one.

Updated

The four approaches

Side by side

VPN + MFARD Gateway + NPS extensionLogon-MFA agentPort gating (RDP-FIDO-GATE)
Where the factor is checkedAt the VPN, before any RDP trafficAt the gateway, before the session is brokeredAt the Windows logon, after the RDP connection is madeAt the gate, before port 3389 opens
Is 3389 reachable before MFA?NoNo (443 on the gateway is)Yes, unless you add a VPN or allow-listNo
Extra infrastructureA VPN server or serviceRD Gateway and NPS servers, Entra ID tenantThe vendor's cloud serviceNone — a service on the host
Cloud identity requiredDepends on the VPNYes, Microsoft Entra IDYes, the vendor'sNo
Typical factorApp push or codeApp push, phone call or codeApp push or codeFIDO2 hardware key; or an authenticator code
Works on a standalone PCYesNo — designed for domainsYesYes
Licensing modelPer user or per applianceRDS CALs plus Microsoft Entra licencesPer-user subscriptionFree up to 10 sessions; one-time Pro

When each one fits

VPN with MFA is the right default when people need more than RDP — file shares, intranet sites, printers. Its cost is a VPN to maintain and patch: VPN appliances are themselves a frequent point of entry.

RD Gateway with the NPS extension suits organisations that already run a Windows domain with Entra ID and want to stay inside Microsoft's stack. It needs several server roles and is more than a small office usually wants to operate.

A logon-MFA agent is the quickest to roll out across many machines and covers local console logons as well. Check where it leaves the port: the second factor is asked after the RDP connection has been accepted, so 3389 must still be shielded by something else.

Port gating fits when the task is exactly “reach these few Windows machines safely from anywhere”: a small office, a home lab, an MSP technician's own toolkit, a cloud VM. There is no server to run and no directory to join, and the factor is a phishing-resistant hardware key.

What RDP-FIDO-GATE does not do

Try the port-gating approach

Install the gate on one host and the client on your PC: the Free edition covers 10 saved sessions with no time limit after activation. The step-by-step guide takes about ten minutes.

RDP-FIDO-GATE

RDP-FIDO-GATE keeps port 3389 closed and opens it for one IP, for about 90 seconds, only after a FIDO2 key touch or an authenticator code. The Free edition covers 10 saved sessions.

Frequently asked questions

Can I combine approaches?

Yes, and it is common: a VPN for general access plus a hardware-key gate in front of RDP on the most sensitive hosts, or a logon agent for console logons plus a gate that keeps 3389 closed.

Which approach is phishing-resistant?

Phishing resistance depends on the factor, not the architecture. Push notifications and one-time codes can be relayed by an attacker; FIDO2 / WebAuthn keys cannot, because the signature is bound to the service it was created for.

Does RD Gateway support FIDO2 keys?

Not through the NPS extension, which offers app notifications, phone calls and one-time codes. Security-key sign-in to RDP in Microsoft's stack requires Entra-joined or hybrid-joined devices and web-based authentication.

Related guides