1. Open event viewer
  2. Navigate to either of the following paths depending on if its a remote or local conneciton

Event ViewerApplications and Services LogsMicrosoftWindowsTerminalServices-LocalSessionManager

Event ViewerApplications and Services LogsMicrosoftWindowsTerminalServices-RemoteConnectionManager

3. look for a event type similar as below and copy the IP address from it.

Event ViewerWindows LogsSecurity  (Event ID: 4624, Logon Type: 10)

Once you have found the IP address use the block ip post below to block it in windows firewall

