Reduce exposure
Remove unnecessary Internet-facing RDP and similar services. Where remote administration is required, place it behind a controlled access service and require strong authentication.
Restrict internal access
Users generally do not need RDP access to every server. Restrict source networks and administrative groups. Use management networks or jump hosts where appropriate.
Identity and patching
- Require MFA for remote access where supported.
- Separate administrator accounts from ordinary accounts.
- Patch operating systems and remote-access components.
- Disable obsolete protocols and authentication methods.
Monitor
Log authentication, source, target and privileged sessions where available. Investigate unusual remote administration from user networks or unexpected locations.
Containment
Maintain a tested method to restrict remote administration during an incident while preserving an authorised recovery path.
Combine this guide with the Ransomware Network Security Guide and Remote Access VPN Design.