# Windows Firewall Group Policy: 5 Steps to Deploy Secure Rules

Source: https://srvscripts.com/guides/windows-firewall-group-policy/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

A Windows Firewall Group Policy object lets you set the firewall state, default actions and inbound rules for every domain-joined computer from one place, instead of clicking through `wf.msc` on each machine. You need it when you open management ports such as RDP or WinRM to an admin subnet only, when you want local administrators to stop adding their own exceptions, or when auditors ask for firewall logs. This guide covers the GPO console, PowerShell against a GPO, Intune, verification with the ActiveStore, troubleshooting and rollback.

**Short answer:** Create a GPO linked to the computer OU and open `Computer Configuration » Policies » Windows Settings » Security Settings » Windows Defender Firewall with Advanced Security`. In **Properties** set each profile to **On**, inbound **Block**, outbound **Allow**. Add inbound rules for the ports you need, scoped to your management subnet, then check the result with `Get-NetFirewallRule -PolicyStore ActiveStore`.

In short: Create a GPO linked to the computer OU and open Computer Configuration » Policies » Windows Settings » Security Settings » Windows Defender Firewall with Advanced Security.

## Which method to use

| Method | Best for | Pros | Cons |
| --- | --- | --- | --- |
| GPO console (Windows Defender Firewall with Advanced Security node) | Most domains | Same wizard as wf.msc; predefined rule groups | Slow for dozens of rules |
| PowerShell with -PolicyStore or Open-NetGPO | Repeatable builds, many rules | Scriptable, reviewable, fast | Needs the NetSecurity and GroupPolicy modules |
| Administrative Templates » Network » Network Connections » Windows Defender Firewall | Legacy only | Simple on/off settings | Older model; do not mix with the node above |
| Intune Endpoint security » Firewall | Entra joined or co-managed devices | Cloud-managed; up to 150 rules per profile | Separate model; avoid managing the same device from both |

For a domain we recommend the Windows Defender Firewall with Advanced Security node for profile settings and PowerShell for building the rules, so the rule list can live in source control.

## Prerequisites

Before you build a Windows Firewall Group Policy object, collect the following:

- Windows 11 Pro, Enterprise or Education, or Windows Server 2016 to 2025, joined to the domain.

- Rights to create and link GPOs, and the Group Policy Management Console. PowerShell steps need the **GroupPolicy** and **NetSecurity** modules (installed with RSAT).

- The subnets of your management hosts, jump servers and monitoring servers. Rules scoped to these are much safer than rules open to Any.

- A test OU with one workstation and one server, and a second machine to test connections from.

## Step 1: Create the GPO and set the profiles

- In **Group Policy Management**, right-click the workstation OU and choose **Create a GPO in this domain, and Link it here**. Name it, for example, SEC – Firewall Workstations. Use a separate GPO for servers.

- Edit the GPO and go to `Computer Configuration » Policies » Windows Settings » Security Settings » Windows Defender Firewall with Advanced Security`.

- Right-click **Windows Defender Firewall with Advanced Security – LDAP://…** and choose **Properties**.

- On the **Domain Profile**, **Private Profile** and **Public Profile** tabs set **Firewall state** to On (recommended), **Inbound connections** to Block (default) and **Outbound connections** to Allow (default).

Every value in a new Windows Firewall Group Policy object starts as Not configured, which means “use the local setting”. Setting the state explicitly stops a local administrator from turning a profile off.

### Understand the three profiles

- **Domain** applies when Windows can authenticate to a domain controller on that network (`Get-NetConnectionProfile` shows DomainAuthenticated).

- **Private** applies to networks a user or policy marked as private.

- **Public** applies to everything else, such as hotel and café Wi-Fi.

Create management rules for the Domain profile only. A laptop on public Wi-Fi then keeps RDP and WinRM closed even though the same GPO applies.

## Step 2: Control rule merging, notifications and logging

### Turn off local rule merging

- On each profile tab, under **Settings**, click **Customize…**.

- Under **Rule merging**, set **Apply local firewall rules** to No. Set **Apply local connection security rules** to No as well if you manage IPsec centrally.

- Set **Display a notification** to No so users are not prompted when a program is blocked.

With merging off, only rules from Group Policy (and MDM) are active; rules that installers or local admins create are ignored. Microsoft notes that apps which create their own rules at install time then need those rules deployed centrally, so build your inventory first. Start by leaving merging on for the Domain profile and turning it off for Public, then tighten the Domain profile once your GPO contains every rule you need.

### Configure logging

- On each profile tab, under **Logging**, click **Customize…**.

- Set **Name** to a per-profile file, for example `%SystemRoot%\System32\LogFiles\Firewall\pfirewall_Domain.log`.

- Set **Size limit (KB)** to at least `20480`; the maximum is `32767`.

- Set **Log dropped packets** to Yes. Set **Log successful connections** to Yes only while you are investigating, because it grows the log quickly.

The Windows Defender Firewall service writes the log as `NT SERVICE\mpssvc`. If you choose a new folder, give that account Full Control or no log file appears.

## Step 3: Add inbound rules for remote management

Most Windows Firewall Group Policy work is inbound rules for management traffic. Right-click **Inbound Rules** and choose **New Rule…**. The wizard offers Program, Port, Predefined and Custom. Predefined groups add the same rules Windows ships with; Custom gives every page, including **Scope**. After creating a predefined rule, open it and set **Scope » Remote IP address** to your management subnet and **Advanced » Profiles** to Domain.

| Need | Predefined group or rule | Protocol and port |
| --- | --- | --- |
| Remote Desktop | “Remote Desktop” (User Mode TCP-In and UDP-In) | TCP 3389, UDP 3389 |
| PowerShell remoting | “Windows Remote Management” (HTTP-In) | TCP 5985 (HTTPS listener: TCP 5986, custom rule) |
| Ping | Custom rule, ICMPv4 type 8 and ICMPv6 type 128 | ICMP echo request |
| File shares and admin shares | “File and Printer Sharing” (SMB-In) | TCP 445 |
| Event Viewer, Services, Task Scheduler, Disk Management remotely | “Remote Event Log Management”, “Remote Service Management”, “Remote Scheduled Tasks Management”, “Remote Volume Management” | RPC endpoint mapper and dynamic RPC |
| WMI and many monitoring agents | “Windows Management Instrumentation (WMI)” | RPC / DCOM |

### Create an ICMP echo rule

- Choose **Custom**, then **All programs**.

- Set **Protocol type** to **ICMPv4**, click **Customize…**, choose **Specific ICMP types** and tick **Echo Request**.

- Scope: remote IP addresses of your monitoring servers. Action: **Allow the connection**. Profile: Domain. Name it MGMT – ICMPv4 Echo Request.

- Repeat for ICMPv6 with Echo Request if you use IPv6.

Enabling RDP needs more than a port. The “Allow users to connect remotely by using Remote Desktop Services” policy turns the listener on; the firewall rule only lets traffic reach it.

## Step 4: Build the same Windows Firewall Group Policy with PowerShell

The NetSecurity cmdlets accept a GPO as the policy store in the form `domain\GPO display name`. Each call opens and saves the GPO, so for more than a few rules use `Open-NetGPO`, make all changes in one session and write them once with `Save-NetGPO`.

```
$name = 'SEC - Firewall Workstations'
New-GPO -Name $name | New-GPLink -Target 'OU=Workstations,DC=contoso,DC=com'
$store = "contoso.com\$name"
$mgmt  = '10.10.50.0/24'
$s = Open-NetGPO -PolicyStore $store
Set-NetFirewallProfile -GPOSession $s -Profile Domain,Private,Public -Enabled True `
    -DefaultInboundAction Block -DefaultOutboundAction Allow -NotifyOnListen False
Set-NetFirewallProfile -GPOSession $s -Profile Public -AllowLocalFirewallRules False
Set-NetFirewallProfile -GPOSession $s -Profile Domain -LogBlocked True `
    -LogMaxSizeKilobytes 20480 `
    -LogFileName '%SystemRoot%\System32\LogFiles\Firewall\pfirewall_Domain.log'
New-NetFirewallRule -GPOSession $s -DisplayName 'MGMT - RDP (TCP-In)' -Direction Inbound `
    -Protocol TCP -LocalPort 3389 -RemoteAddress $mgmt -Profile Domain -Action Allow
New-NetFirewallRule -GPOSession $s -DisplayName 'MGMT - RDP (UDP-In)' -Direction Inbound `
    -Protocol UDP -LocalPort 3389 -RemoteAddress $mgmt -Profile Domain -Action Allow
New-NetFirewallRule -GPOSession $s -DisplayName 'MGMT - WinRM HTTP (TCP-In)' -Direction Inbound `
    -Protocol TCP -LocalPort 5985 -RemoteAddress $mgmt -Profile Domain -Action Allow
New-NetFirewallRule -GPOSession $s -DisplayName 'MGMT - ICMPv4 Echo Request' -Direction Inbound `
    -Protocol ICMPv4 -IcmpType 8 -RemoteAddress $mgmt -Profile Domain -Action Allow
New-NetFirewallRule -GPOSession $s -DisplayName 'MGMT - SMB (TCP-In)' -Direction Inbound `
    -Protocol TCP -LocalPort 445 -RemoteAddress $mgmt -Profile Domain -Action Allow
Save-NetGPO -GPOSession $s
```

Read the rules back from the GPO without touching any client:

```
Get-NetFirewallRule -PolicyStore 'contoso.com\SEC - Firewall Workstations' |
    Format-Table DisplayName, Enabled, Direction, Action, Profile
```

Keep this script in source control. Changing a rule later is a matter of editing the script and running `Set-NetFirewallRule` or `Remove-NetFirewallRule` with the same `-PolicyStore`.

## Step 5: Intune firewall policies

For Microsoft Entra joined devices, go to **Endpoint security » Firewall » Create policy** and choose platform **Windows**:

- The **Windows Firewall** profile sets the state, default actions, logging and local policy merge for each network type. Local policy merge maps to the Firewall CSP value `AllowLocalPolicyMerge`.

- The **Windows Firewall rules** profile holds the rules. Each profile supports up to 150 rules; rules from several non-conflicting profiles merge on the device.

Two Windows Firewall profiles that set the same setting to different values conflict, and Intune does not send that setting. On co-managed devices, decide whether Group Policy or Intune owns the firewall and keep the other one empty.

## Targeting and exceptions

One Windows Firewall Group Policy object rarely fits every machine. Plan the scope before you add rules:

- **Separate GPOs by role.** Workstations, member servers and domain controllers need different inbound rules. Do not add workstation rules to the Default Domain Policy.

- **Scope, not exceptions.** Restrict each allow rule with **Remote IP address** rather than creating block rules. Microsoft’s precedence is: explicit block rules win over allow rules, and more specific rules win over less specific ones, so a stray block rule can override your whole design.

- **Security filtering or WMI filters.** Use a computer group with **Apply group policy** denied to exclude a machine, or a WMI filter to apply a server rule set only to a given OS.

- **Connection security rules (optional).** Under **Connection Security Rules** you can require IPsec authentication between domain members. An inbound rule with **Allow the connection if it is secure** then accepts traffic only from authenticated computers. Pilot this carefully; a mistake can cut off management traffic.

## Verify it works

Check each Windows Firewall Group Policy change on a test machine before you widen the link.

- Refresh policy and confirm the GPO applies:

```
gpupdate /forcegpresult /scope computer /r
```

- Check the network category. Domain rules only work if the adapter is on the Domain profile:

```
Get-NetConnectionProfile | Format-Table InterfaceAlias, NetworkCategory
```

- List the effective rules that came from Group Policy. The ActiveStore is the sum of all stores:

```
Get-NetFirewallRule -PolicyStore ActiveStore |    Where-Object PolicyStoreSourceType -eq 'GroupPolicy' |    Format-Table DisplayName, Enabled, Profile, ActionGet-NetFirewallRule -PolicyStore RSOP | Measure-ObjectGet-NetFirewallProfile -PolicyStore ActiveStore |    Format-Table Name, Enabled, DefaultInboundAction, AllowLocalFirewallRules, LogBlocked
```

- Inspect a rule’s port and address filters: `Get-NetFirewallRule -PolicyStore ActiveStore -DisplayName 'MGMT - RDP (TCP-In)' | Get-NetFirewallPortFilter` and `… | Get-NetFirewallAddressFilter`.

- Test from a management host with `Test-NetConnection -ComputerName PC-0142 -Port 3389`, and from a host outside the scope, which should fail.

- Policy rules are stored under `HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\FirewallRules`; `netsh advfirewall show allprofiles` shows state and logging for each profile.

For per-connection evidence, enable **Audit Filtering Platform Connection** under `Advanced Audit Policy Configuration » System Audit Policies » Object Access`. Security event 5157 then records blocked connections and 5156 records allowed ones. This is noisy, so enable it for a short test only.

## Troubleshooting

When a Windows Firewall Group Policy rule does not behave as expected, the cause is usually the profile, a block rule or rule merging.

| Symptom | Likely cause | Fix |
| --- | --- | --- |
| Rule present but port still closed | Adapter on Public or Private, rule set to Domain only | Check Get-NetConnectionProfile; fix DNS or domain controller reachability |
| Allowed port is blocked | An explicit block rule from another GPO or local store | Search ActiveStore for Action -eq 'Block' rules on that port |
| App stopped working after rollout | Local rules ignored after “Apply local firewall rules = No” | Add the app’s rule to the GPO, or re-enable merging for that profile |
| No log file | Folder lacks permissions for NT SERVICE\mpssvc | Use the default folder or grant Full Control |
| RDP rule works, RDP still refused | Remote Desktop not enabled or user not in Remote Desktop Users | Enable the RDS connection policy and group membership |
| Settings flip after sync | Intune and GPO both manage the firewall | Pick one management source |
| GPO rules missing entirely | GPO not applied (filtering, link, replication) | Check gpresult and events 1058/1030 |

## Roll back or undo

- **A single rule:** disable it first (`Disable-NetFirewallRule -PolicyStore 'contoso.com\SEC - Firewall Workstations' -DisplayName 'MGMT - SMB (TCP-In)'`), confirm nothing breaks, then remove it with `Remove-NetFirewallRule`.

- **Profile settings:** set the values back to Not configured in **Properties**; clients fall back to their local settings on the next refresh.

- **The whole GPO:** unlink it and run `gpupdate /force`. Policy rules are removed from the clients; local rules become active again if they were suppressed by rule merging.

- **Intune:** unassign the profile, or set the conflicting setting to its previous value, and sync the device.

Back up the GPO before each change (`Backup-GPO -Name 'SEC - Firewall Workstations' -Path C:\GPOBackup`) and roll every Windows Firewall Group Policy update to a pilot OU before the rest of the estate.

## Windows Firewall Group Policy at a glance

**Official documentation:** [Manage Windows Firewall with the command line](https://learn.microsoft.com/en-us/windows/security/operating-system-security/network-security/windows-firewall/configure-with-command-line), [Windows Firewall rules](https://learn.microsoft.com/en-us/windows/security/operating-system-security/network-security/windows-firewall/rules), [Firewall policy for endpoint security in Intune](https://learn.microsoft.com/en-us/intune/intune-service/protect/endpoint-security-firewall-policy).

**Related guides:** [Enable Remote Desktop Group Policy and Firewall Rules Made Easy](/guides/enable-remote-desktop-group-policy/) · [SMB signing and disabling SMBv1 with Group Policy](/guides/smb-signing-group-policy/) · [Troubleshoot Group Policy not applying: gpresult, RSoP and Events 1058/1030](/guides/group-policy-not-applying/).

## Frequently asked questions

### Does a Windows Firewall Group Policy override rules created locally?

Rules from the GPO and local rules are combined by default. If you set “Apply local firewall rules” to No for a profile, only Group Policy and MDM rules apply on that profile and local rules are ignored.

### Why does my GPO firewall rule work on some laptops but not others?

The rule is probably scoped to the Domain profile. Laptops on home or public networks use the Private or Public profile, so the rule does not apply there, which is usually what you want for management ports.

### How do I add firewall rules to a GPO with PowerShell?

Use New-NetFirewallRule with -PolicyStore “domain\GPO name”, or open the GPO once with Open-NetGPO, pass the session with -GPOSession to each cmdlet and write the changes with Save-NetGPO.

### How can I see which firewall rules are actually active on a computer?

Run Get-NetFirewallRule -PolicyStore ActiveStore. It returns the sum of local and Group Policy rules, and the PolicyStoreSourceType property shows which ones came from Group Policy.
