The four approaches
- VPN with MFA. Users join a VPN that requires a second factor; RDP is reachable only inside the tunnel.
- RD Gateway with an MFA extension. Microsoft's Remote Desktop Gateway publishes RDP over HTTPS; the NPS extension for Microsoft Entra multifactor authentication adds the second factor.
- A logon-MFA agent on the host. A credential provider installed on each machine asks for a second factor during Windows logon. Duo Authentication for Windows Logon is the best-known example.
- Port gating. The RDP port is closed by default and opens for one IP after a factor is confirmed out of band. RDP-FIDO-GATE works this way.
Side by side
| VPN + MFA | RD Gateway + NPS extension | Logon-MFA agent | Port gating (RDP-FIDO-GATE) | |
|---|---|---|---|---|
| Where the factor is checked | At the VPN, before any RDP traffic | At the gateway, before the session is brokered | At the Windows logon, after the RDP connection is made | At the gate, before port 3389 opens |
| Is 3389 reachable before MFA? | No | No (443 on the gateway is) | Yes, unless you add a VPN or allow-list | No |
| Extra infrastructure | A VPN server or service | RD Gateway and NPS servers, Entra ID tenant | The vendor's cloud service | None — a service on the host |
| Cloud identity required | Depends on the VPN | Yes, Microsoft Entra ID | Yes, the vendor's | No |
| Typical factor | App push or code | App push, phone call or code | App push or code | FIDO2 hardware key; or an authenticator code |
| Works on a standalone PC | Yes | No — designed for domains | Yes | Yes |
| Licensing model | Per user or per appliance | RDS CALs plus Microsoft Entra licences | Per-user subscription | Free up to 10 sessions; one-time Pro |
When each one fits
VPN with MFA is the right default when people need more than RDP — file shares, intranet sites, printers. Its cost is a VPN to maintain and patch: VPN appliances are themselves a frequent point of entry.
RD Gateway with the NPS extension suits organisations that already run a Windows domain with Entra ID and want to stay inside Microsoft's stack. It needs several server roles and is more than a small office usually wants to operate.
A logon-MFA agent is the quickest to roll out across many machines and covers local console logons as well. Check where it leaves the port: the second factor is asked after the RDP connection has been accepted, so 3389 must still be shielded by something else.
Port gating fits when the task is exactly “reach these few Windows machines safely from anywhere”: a small office, a home lab, an MSP technician's own toolkit, a cloud VM. There is no server to run and no directory to join, and the factor is a phishing-resistant hardware key.
What RDP-FIDO-GATE does not do
- It protects Remote Desktop (and its own FIDO Stream mode), not other protocols. For file shares and internal sites use a VPN.
- Keys are enrolled per host; there is no central directory to manage.
- It does not replace the Windows logon. Users still enter their Windows credentials after the port opens — which is the second factor of the pair.
Try the port-gating approach
Install the gate on one host and the client on your PC: the Free edition covers 10 saved sessions with no time limit after activation. The step-by-step guide takes about ten minutes.