A Windows Firewall Group Policy object lets you set the firewall state, default actions and inbound rules for every domain-joined computer from one place, instead of clicking through wf.msc on each machine. You need it when you open management ports such as RDP or WinRM to an admin subnet only, when you want local administrators to stop adding their own exceptions, or when auditors ask for firewall logs. This guide covers the GPO console, PowerShell against a GPO, Intune, verification with the ActiveStore, troubleshooting and rollback.
Applies to Windows 11 Pro, Enterprise and Education; Windows Server 2016 to 2025
Short answer: Create a GPO linked to the computer OU and open Computer Configuration » Policies » Windows Settings » Security Settings » Windows Defender Firewall with Advanced Security. In Properties set each profile to On, inbound Block, outbound Allow. Add inbound rules for the ports you need, scoped to your management subnet, then check the result with Get-NetFirewallRule -PolicyStore ActiveStore.
Table of Contents
Which method to use
| Method | Best for | Pros | Cons |
|---|---|---|---|
| GPO console (Windows Defender Firewall with Advanced Security node) | Most domains | Same wizard as wf.msc; predefined rule groups | Slow for dozens of rules |
PowerShell with -PolicyStore or Open-NetGPO | Repeatable builds, many rules | Scriptable, reviewable, fast | Needs the NetSecurity and GroupPolicy modules |
| Administrative Templates » Network » Network Connections » Windows Defender Firewall | Legacy only | Simple on/off settings | Older model; do not mix with the node above |
| Intune Endpoint security » Firewall | Entra joined or co-managed devices | Cloud-managed; up to 150 rules per profile | Separate model; avoid managing the same device from both |
For a domain we recommend the Windows Defender Firewall with Advanced Security node for profile settings and PowerShell for building the rules, so the rule list can live in source control.
Prerequisites
Before you build a Windows Firewall Group Policy object, collect the following:
- Windows 11 Pro, Enterprise or Education, or Windows Server 2016 to 2025, joined to the domain.
- Rights to create and link GPOs, and the Group Policy Management Console. PowerShell steps need the GroupPolicy and NetSecurity modules (installed with RSAT).
- The subnets of your management hosts, jump servers and monitoring servers. Rules scoped to these are much safer than rules open to Any.
- A test OU with one workstation and one server, and a second machine to test connections from.
Step 1: Create the GPO and set the profiles
- In Group Policy Management, right-click the workstation OU and choose Create a GPO in this domain, and Link it here. Name it, for example, SEC – Firewall Workstations. Use a separate GPO for servers.
- Edit the GPO and go to
Computer Configuration » Policies » Windows Settings » Security Settings » Windows Defender Firewall with Advanced Security. - Right-click Windows Defender Firewall with Advanced Security – LDAP://… and choose Properties.
- On the Domain Profile, Private Profile and Public Profile tabs set Firewall state to On (recommended), Inbound connections to Block (default) and Outbound connections to Allow (default).
Every value in a new Windows Firewall Group Policy object starts as Not configured, which means “use the local setting”. Setting the state explicitly stops a local administrator from turning a profile off.
Understand the three profiles
- Domain applies when Windows can authenticate to a domain controller on that network (
Get-NetConnectionProfileshows DomainAuthenticated). - Private applies to networks a user or policy marked as private.
- Public applies to everything else, such as hotel and café Wi-Fi.
Create management rules for the Domain profile only. A laptop on public Wi-Fi then keeps RDP and WinRM closed even though the same GPO applies.
Step 2: Control rule merging, notifications and logging
Turn off local rule merging
- On each profile tab, under Settings, click Customize….
- Under Rule merging, set Apply local firewall rules to No. Set Apply local connection security rules to No as well if you manage IPsec centrally.
- Set Display a notification to No so users are not prompted when a program is blocked.
With merging off, only rules from Group Policy (and MDM) are active; rules that installers or local admins create are ignored. Microsoft notes that apps which create their own rules at install time then need those rules deployed centrally, so build your inventory first. Start by leaving merging on for the Domain profile and turning it off for Public, then tighten the Domain profile once your GPO contains every rule you need.
Configure logging
- On each profile tab, under Logging, click Customize….
- Set Name to a per-profile file, for example
%SystemRoot%\System32\LogFiles\Firewall\pfirewall_Domain.log. - Set Size limit (KB) to at least
20480; the maximum is32767. - Set Log dropped packets to Yes. Set Log successful connections to Yes only while you are investigating, because it grows the log quickly.
The Windows Defender Firewall service writes the log as NT SERVICE\mpssvc. If you choose a new folder, give that account Full Control or no log file appears.
Step 3: Add inbound rules for remote management
Most Windows Firewall Group Policy work is inbound rules for management traffic. Right-click Inbound Rules and choose New Rule…. The wizard offers Program, Port, Predefined and Custom. Predefined groups add the same rules Windows ships with; Custom gives every page, including Scope. After creating a predefined rule, open it and set Scope » Remote IP address to your management subnet and Advanced » Profiles to Domain.
| Need | Predefined group or rule | Protocol and port |
|---|---|---|
| Remote Desktop | “Remote Desktop” (User Mode TCP-In and UDP-In) | TCP 3389, UDP 3389 |
| PowerShell remoting | “Windows Remote Management” (HTTP-In) | TCP 5985 (HTTPS listener: TCP 5986, custom rule) |
| Ping | Custom rule, ICMPv4 type 8 and ICMPv6 type 128 | ICMP echo request |
| File shares and admin shares | “File and Printer Sharing” (SMB-In) | TCP 445 |
| Event Viewer, Services, Task Scheduler, Disk Management remotely | “Remote Event Log Management”, “Remote Service Management”, “Remote Scheduled Tasks Management”, “Remote Volume Management” | RPC endpoint mapper and dynamic RPC |
| WMI and many monitoring agents | “Windows Management Instrumentation (WMI)” | RPC / DCOM |
Create an ICMP echo rule
- Choose Custom, then All programs.
- Set Protocol type to ICMPv4, click Customize…, choose Specific ICMP types and tick Echo Request.
- Scope: remote IP addresses of your monitoring servers. Action: Allow the connection. Profile: Domain. Name it MGMT – ICMPv4 Echo Request.
- Repeat for ICMPv6 with Echo Request if you use IPv6.
Enabling RDP needs more than a port. The “Allow users to connect remotely by using Remote Desktop Services” policy turns the listener on; the firewall rule only lets traffic reach it.
Step 4: Build the same Windows Firewall Group Policy with PowerShell
The NetSecurity cmdlets accept a GPO as the policy store in the form domain\GPO display name. Each call opens and saves the GPO, so for more than a few rules use Open-NetGPO, make all changes in one session and write them once with Save-NetGPO.
$name = 'SEC - Firewall Workstations'
New-GPO -Name $name | New-GPLink -Target 'OU=Workstations,DC=contoso,DC=com'
$store = "contoso.com\$name"
$mgmt = '10.10.50.0/24'
$s = Open-NetGPO -PolicyStore $store
Set-NetFirewallProfile -GPOSession $s -Profile Domain,Private,Public -Enabled True `
-DefaultInboundAction Block -DefaultOutboundAction Allow -NotifyOnListen False
Set-NetFirewallProfile -GPOSession $s -Profile Public -AllowLocalFirewallRules False
Set-NetFirewallProfile -GPOSession $s -Profile Domain -LogBlocked True `
-LogMaxSizeKilobytes 20480 `
-LogFileName '%SystemRoot%\System32\LogFiles\Firewall\pfirewall_Domain.log'
New-NetFirewallRule -GPOSession $s -DisplayName 'MGMT - RDP (TCP-In)' -Direction Inbound `
-Protocol TCP -LocalPort 3389 -RemoteAddress $mgmt -Profile Domain -Action Allow
New-NetFirewallRule -GPOSession $s -DisplayName 'MGMT - RDP (UDP-In)' -Direction Inbound `
-Protocol UDP -LocalPort 3389 -RemoteAddress $mgmt -Profile Domain -Action Allow
New-NetFirewallRule -GPOSession $s -DisplayName 'MGMT - WinRM HTTP (TCP-In)' -Direction Inbound `
-Protocol TCP -LocalPort 5985 -RemoteAddress $mgmt -Profile Domain -Action Allow
New-NetFirewallRule -GPOSession $s -DisplayName 'MGMT - ICMPv4 Echo Request' -Direction Inbound `
-Protocol ICMPv4 -IcmpType 8 -RemoteAddress $mgmt -Profile Domain -Action Allow
New-NetFirewallRule -GPOSession $s -DisplayName 'MGMT - SMB (TCP-In)' -Direction Inbound `
-Protocol TCP -LocalPort 445 -RemoteAddress $mgmt -Profile Domain -Action Allow
Save-NetGPO -GPOSession $s
Read the rules back from the GPO without touching any client:
Get-NetFirewallRule -PolicyStore 'contoso.com\SEC - Firewall Workstations' |
Format-Table DisplayName, Enabled, Direction, Action, Profile
Keep this script in source control. Changing a rule later is a matter of editing the script and running Set-NetFirewallRule or Remove-NetFirewallRule with the same -PolicyStore.
Step 5: Intune firewall policies
For Microsoft Entra joined devices, go to Endpoint security » Firewall » Create policy and choose platform Windows:
- The Windows Firewall profile sets the state, default actions, logging and local policy merge for each network type. Local policy merge maps to the Firewall CSP value
AllowLocalPolicyMerge. - The Windows Firewall rules profile holds the rules. Each profile supports up to 150 rules; rules from several non-conflicting profiles merge on the device.
Two Windows Firewall profiles that set the same setting to different values conflict, and Intune does not send that setting. On co-managed devices, decide whether Group Policy or Intune owns the firewall and keep the other one empty.
Targeting and exceptions
One Windows Firewall Group Policy object rarely fits every machine. Plan the scope before you add rules:
- Separate GPOs by role. Workstations, member servers and domain controllers need different inbound rules. Do not add workstation rules to the Default Domain Policy.
- Scope, not exceptions. Restrict each allow rule with Remote IP address rather than creating block rules. Microsoft’s precedence is: explicit block rules win over allow rules, and more specific rules win over less specific ones, so a stray block rule can override your whole design.
- Security filtering or WMI filters. Use a computer group with Apply group policy denied to exclude a machine, or a WMI filter to apply a server rule set only to a given OS.
- Connection security rules (optional). Under Connection Security Rules you can require IPsec authentication between domain members. An inbound rule with Allow the connection if it is secure then accepts traffic only from authenticated computers. Pilot this carefully; a mistake can cut off management traffic.
Verify it works
Check each Windows Firewall Group Policy change on a test machine before you widen the link.
- Refresh policy and confirm the GPO applies:
gpupdate /force
gpresult /scope computer /r - Check the network category. Domain rules only work if the adapter is on the Domain profile:
Get-NetConnectionProfile | Format-Table InterfaceAlias, NetworkCategory - List the effective rules that came from Group Policy. The ActiveStore is the sum of all stores:
Get-NetFirewallRule -PolicyStore ActiveStore |
Where-Object PolicyStoreSourceType -eq 'GroupPolicy' |
Format-Table DisplayName, Enabled, Profile, Action
Get-NetFirewallRule -PolicyStore RSOP | Measure-Object
Get-NetFirewallProfile -PolicyStore ActiveStore |
Format-Table Name, Enabled, DefaultInboundAction, AllowLocalFirewallRules, LogBlocked - Inspect a rule’s port and address filters:
Get-NetFirewallRule -PolicyStore ActiveStore -DisplayName 'MGMT - RDP (TCP-In)' | Get-NetFirewallPortFilterand… | Get-NetFirewallAddressFilter. - Test from a management host with
Test-NetConnection -ComputerName PC-0142 -Port 3389, and from a host outside the scope, which should fail. - Policy rules are stored under
HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\FirewallRules;netsh advfirewall show allprofilesshows state and logging for each profile.
For per-connection evidence, enable Audit Filtering Platform Connection under Advanced Audit Policy Configuration » System Audit Policies » Object Access. Security event 5157 then records blocked connections and 5156 records allowed ones. This is noisy, so enable it for a short test only.
Troubleshooting
When a Windows Firewall Group Policy rule does not behave as expected, the cause is usually the profile, a block rule or rule merging.
| Symptom | Likely cause | Fix |
|---|---|---|
| Rule present but port still closed | Adapter on Public or Private, rule set to Domain only | Check Get-NetConnectionProfile; fix DNS or domain controller reachability |
| Allowed port is blocked | An explicit block rule from another GPO or local store | Search ActiveStore for Action -eq 'Block' rules on that port |
| App stopped working after rollout | Local rules ignored after “Apply local firewall rules = No” | Add the app’s rule to the GPO, or re-enable merging for that profile |
| No log file | Folder lacks permissions for NT SERVICE\mpssvc | Use the default folder or grant Full Control |
| RDP rule works, RDP still refused | Remote Desktop not enabled or user not in Remote Desktop Users | Enable the RDS connection policy and group membership |
| Settings flip after sync | Intune and GPO both manage the firewall | Pick one management source |
| GPO rules missing entirely | GPO not applied (filtering, link, replication) | Check gpresult and events 1058/1030 |
Roll back or undo
- A single rule: disable it first (
Disable-NetFirewallRule -PolicyStore 'contoso.com\SEC - Firewall Workstations' -DisplayName 'MGMT - SMB (TCP-In)'), confirm nothing breaks, then remove it withRemove-NetFirewallRule. - Profile settings: set the values back to Not configured in Properties; clients fall back to their local settings on the next refresh.
- The whole GPO: unlink it and run
gpupdate /force. Policy rules are removed from the clients; local rules become active again if they were suppressed by rule merging. - Intune: unassign the profile, or set the conflicting setting to its previous value, and sync the device.
Back up the GPO before each change (Backup-GPO -Name 'SEC - Firewall Workstations' -Path C:\GPOBackup) and roll every Windows Firewall Group Policy update to a pilot OU before the rest of the estate.
Windows Firewall Group Policy at a glance

Official documentation: Manage Windows Firewall with the command line, Windows Firewall rules, Firewall policy for endpoint security in Intune.
Related guides: Enable Remote Desktop Group Policy and Firewall Rules Made Easy · SMB signing and disabling SMBv1 with Group Policy · Troubleshoot Group Policy not applying: gpresult, RSoP and Events 1058/1030.
Frequently asked questions
Does a Windows Firewall Group Policy override rules created locally?
Rules from the GPO and local rules are combined by default. If you set “Apply local firewall rules” to No for a profile, only Group Policy and MDM rules apply on that profile and local rules are ignored.
Why does my GPO firewall rule work on some laptops but not others?
The rule is probably scoped to the Domain profile. Laptops on home or public networks use the Private or Public profile, so the rule does not apply there, which is usually what you want for management ports.
How do I add firewall rules to a GPO with PowerShell?
Use New-NetFirewallRule with -PolicyStore “domain\GPO name”, or open the GPO once with Open-NetGPO, pass the session with -GPOSession to each cmdlet and write the changes with Save-NetGPO.
How can I see which firewall rules are actually active on a computer?
Run Get-NetFirewallRule -PolicyStore ActiveStore. It returns the sum of local and Group Policy rules, and the PolicyStoreSourceType property shows which ones came from Group Policy.
Maintenance record
This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.
- Maintained by
- srvScripts editorial team
- Supported versions
- Windows 11 Pro, Enterprise and Education; Windows Server 2016 to 2025
- Last full review
- Next review
- Sources
- learn.microsoft.com/en-us/windows/security/operating-system-security/network-security/windows-firewall/configure-with-command-line
learn.microsoft.com/en-us/windows/security/operating-system-security/network-security/windows-firewall/rules
learn.microsoft.com/en-us/intune/intune-service/protect/endpoint-security-firewall-policy