Have you created a security group and set the appropriate inbound and outbound rules? You’ll have to apply that security group to that instance as well after creating it…
You could just open all the ports just to initially make a connection and fine tune it from there, but maybe keep your static public IP obscure from the world while you do so. I’m not sure of the implications of leaving them all totally open, but the RDP is pretty secure so I feel like your EC2 instance backend will be fine. Just don’t take my word on that part 100%.