In short
Remote Desktop Gateway (RD Gateway) is a Windows Server Remote Desktop Services role that gives authorized remote users a secure, encrypted path to internal Windows desktops and RemoteApp resources over the internet. Instead of publishing every target server's RDP endpoint directly, clients connect to the gateway and the gateway brokers access to approved internal resources.
People often search for RDS Gateway, but Microsoft's role name is Remote Desktop Gateway (RD Gateway), part of the Remote Desktop Services platform.
For a single administrator with a predictable source IP, tightly restricted direct RDP can be a reasonable management path. For multiple users, changing locations, RemoteApp, RD Session Host, or a business that wants one controlled remote-access entry point, RD Gateway is the cleaner architecture.
On a Raff Windows environment, the internet-facing RD Gateway path normally uses TCP 443, with UDP 3391 available when the supported UDP transport is enabled. Target hosts do not need to publish TCP 3389 directly to internet clients, but the gateway still needs the required internal RDP connectivity to those targets.
This page covers what RD Gateway is and when to use it instead of direct RDP. If you only want direct-RDP hardening steps, use the Windows Server hardening checklist. If you are deciding between the two administrative sessions and a true multi-user RDS deployment, use Multi-User RDP vs RDS Session Host.
What is Remote Desktop Gateway (RDS Gateway)?
Remote Desktop Gateway is a Windows Server role that sits between internet-connected Remote Desktop clients and internal RDS resources. Microsoft describes the role as enabling secure, encrypted connections to Remote Desktop Services resources over the internet without requiring users to establish a traditional VPN first.
The basic path is:
Remote user | | HTTPS / RD Gateway transport v Remote Desktop Gateway | | internal RDP path v Authorized Windows desktop or RD Session Host
The security benefit is architectural: you can publish the gateway as the remote-access entry point instead of publishing TCP 3389 from every target Windows server to the public internet.
RD Gateway is not the desktop host itself. The gateway authenticates and authorizes the connection, then brokers it to the allowed internal Windows resource.
RD Gateway vs direct RDP: quick comparison
| Area | Direct RDP | Remote Desktop Gateway |
|---|---|---|
| Internet-facing path | Client connects directly to the Windows host | Client connects to the gateway first |
| Typical external port | RDP is commonly exposed on TCP 3389 unless restricted or translated | HTTPS uses TCP 443; supported RD Gateway designs can also use UDP 3391 |
| Public exposure | Each directly reachable RDP host needs its own controlled path | Gateway becomes the main published RDP access layer |
| Best fit | Small admin-only access with strict allowlisting | Multiple users, RDS resources, changing locations, centralized policy |
| Authorization | Windows account and host/firewall controls | RD CAP and RD RAP plus target-host controls |
| Certificates | RDP certificate/security still matters | Public gateway should use a trusted certificate matching its FQDN |
| MFA | Added through the chosen identity/access design | Can integrate with NPS and Microsoft Entra MFA designs |
| Complexity | Lower | Higher: gateway role, certificate, policies, DNS, monitoring |
| Scaling | Each direct endpoint must be managed | Gateway servers can be deployed as a farm/load-balanced design |
The important comparison is not "which one makes RDP faster?" It is where you place the trust boundary and how many public RDP entry points you want to manage.
How RD Gateway works
A typical connection has four stages:
- The Remote Desktop client is configured with the RD Gateway hostname.
- The client establishes the gateway connection over the published RD Gateway transport.
- RD Gateway evaluates whether the user is allowed to connect and which internal resources that user may reach.
- The gateway brokers the RDP session to the authorized target server over the internal network path.
Microsoft's current RDS role guidance identifies HTTPS on TCP 443 as the primary external RD Gateway path and also documents UDP 3391 for the UDP transport. The target Windows server still needs to be reachable from the gateway over the required internal RDP path. The difference is that the target server's RDP port does not need to be published directly to every internet client.
What are RD CAP and RD RAP?
RD Gateway uses authorization policies to separate who may use the gateway from what they may reach.
Remote Desktop Connection Authorization Policy (RD CAP)
An RD CAP determines which users or groups are allowed to connect through the gateway and can include conditions such as authentication method or group membership.
Think of it as:
Who is allowed through this gateway?
Remote Desktop Resource Authorization Policy (RD RAP)
An RD RAP determines which internal computers or resource groups an authorized user may access through the gateway.
Think of it as:
Which Windows resources may this approved user reach?
Keeping those questions separate is one of RD Gateway's main advantages over a loose collection of direct public RDP rules.
RD Gateway vs direct RDP architecture

Direct RDP
A direct design looks like this:
Internet | v Windows Server RDP endpoint
For one administrator, this can be simple. But if the server accepts RDP from the entire internet, its authentication endpoint is continuously exposed to scanning and credential attacks.
A safer direct-RDP design narrows the exposure with controls such as source-IP allowlisting, Network Level Authentication, named administrator accounts, strong unique credentials, account lockout and monitoring, current Windows security updates, and firewall rules that expose only the required path.
For the detailed direct-RDP hardening workflow, see the Windows Server hardening checklist.
RD Gateway
A gateway design looks more like this:
Internet | v RD Gateway | +--> Windows Server A +--> RD Session Host B +--> Approved RDS resource C
Only the gateway needs to be the controlled public RDS entry point. Target hosts can remain behind internal firewall rules that allow RDP from the gateway or other approved management paths.
That centralization becomes more valuable as the number of users, servers, offices, and support staff grows.
What ports does Remote Desktop Gateway use?
Plan the RD Gateway network path in two parts: internet-facing gateway transport and gateway-to-target RDP connectivity.
| Traffic | Typical port | Purpose |
|---|---|---|
| HTTPS | TCP 443 | Primary encrypted RD Gateway transport |
| RD Gateway UDP transport | UDP 3391 | Optional supported UDP path |
| Internal RDP | TCP/UDP 3389 as required by the target design | Gateway-to-target RDP connectivity inside the protected network |
Do not interpret RD Gateway as "RDP no longer uses 3389 anywhere." The goal is to avoid publishing every target host's RDP endpoint directly to the public internet. Internal connectivity between the gateway and target resources still has to be allowed by your network design.
Firewall requirements can vary with Windows Server version, RDS topology, NAT, and whether UDP transport is enabled. Validate the actual Microsoft requirements for the deployment rather than copying a generic port rule into production.