Emergency server help: get in touch

Windows Firewall Group Policy: 5 Steps to Deploy Secure Rules

Manage Windows Defender Firewall on Windows 11 and Windows Server 2025 from a GPO: profile defaults, inbound rules for RDP, WinRM, ICMP and SMB, rule merging, logging, PowerShell GPO sessions, Intune and verification.

Published Updated 12 min read

A Windows Firewall Group Policy object lets you set the firewall state, default actions and inbound rules for every domain-joined computer from one place, instead of clicking through wf.msc on each machine. You need it when you open management ports such as RDP or WinRM to an admin subnet only, when you want local administrators to stop adding their own exceptions, or when auditors ask for firewall logs. This guide covers the GPO console, PowerShell against a GPO, Intune, verification with the ActiveStore, troubleshooting and rollback.

Applies to Windows 11 Pro, Enterprise and Education; Windows Server 2016 to 2025

Short answer: Create a GPO linked to the computer OU and open Computer Configuration » Policies » Windows Settings » Security Settings » Windows Defender Firewall with Advanced Security. In Properties set each profile to On, inbound Block, outbound Allow. Add inbound rules for the ports you need, scoped to your management subnet, then check the result with Get-NetFirewallRule -PolicyStore ActiveStore.

Which method to use

MethodBest forProsCons
GPO console (Windows Defender Firewall with Advanced Security node)Most domainsSame wizard as wf.msc; predefined rule groupsSlow for dozens of rules
PowerShell with -PolicyStore or Open-NetGPORepeatable builds, many rulesScriptable, reviewable, fastNeeds the NetSecurity and GroupPolicy modules
Administrative Templates » Network » Network Connections » Windows Defender FirewallLegacy onlySimple on/off settingsOlder model; do not mix with the node above
Intune Endpoint security » FirewallEntra joined or co-managed devicesCloud-managed; up to 150 rules per profileSeparate model; avoid managing the same device from both

For a domain we recommend the Windows Defender Firewall with Advanced Security node for profile settings and PowerShell for building the rules, so the rule list can live in source control.

Prerequisites

Before you build a Windows Firewall Group Policy object, collect the following:

  • Windows 11 Pro, Enterprise or Education, or Windows Server 2016 to 2025, joined to the domain.
  • Rights to create and link GPOs, and the Group Policy Management Console. PowerShell steps need the GroupPolicy and NetSecurity modules (installed with RSAT).
  • The subnets of your management hosts, jump servers and monitoring servers. Rules scoped to these are much safer than rules open to Any.
  • A test OU with one workstation and one server, and a second machine to test connections from.

Step 1: Create the GPO and set the profiles

  1. In Group Policy Management, right-click the workstation OU and choose Create a GPO in this domain, and Link it here. Name it, for example, SEC – Firewall Workstations. Use a separate GPO for servers.
  2. Edit the GPO and go to Computer Configuration » Policies » Windows Settings » Security Settings » Windows Defender Firewall with Advanced Security.
  3. Right-click Windows Defender Firewall with Advanced Security – LDAP://… and choose Properties.
  4. On the Domain Profile, Private Profile and Public Profile tabs set Firewall state to On (recommended), Inbound connections to Block (default) and Outbound connections to Allow (default).

Every value in a new Windows Firewall Group Policy object starts as Not configured, which means “use the local setting”. Setting the state explicitly stops a local administrator from turning a profile off.

Understand the three profiles

  • Domain applies when Windows can authenticate to a domain controller on that network (Get-NetConnectionProfile shows DomainAuthenticated).
  • Private applies to networks a user or policy marked as private.
  • Public applies to everything else, such as hotel and cafĂ© Wi-Fi.

Create management rules for the Domain profile only. A laptop on public Wi-Fi then keeps RDP and WinRM closed even though the same GPO applies.

Step 2: Control rule merging, notifications and logging

Turn off local rule merging

  1. On each profile tab, under Settings, click Customize….
  2. Under Rule merging, set Apply local firewall rules to No. Set Apply local connection security rules to No as well if you manage IPsec centrally.
  3. Set Display a notification to No so users are not prompted when a program is blocked.

With merging off, only rules from Group Policy (and MDM) are active; rules that installers or local admins create are ignored. Microsoft notes that apps which create their own rules at install time then need those rules deployed centrally, so build your inventory first. Start by leaving merging on for the Domain profile and turning it off for Public, then tighten the Domain profile once your GPO contains every rule you need.

Configure logging

  1. On each profile tab, under Logging, click Customize….
  2. Set Name to a per-profile file, for example %SystemRoot%\System32\LogFiles\Firewall\pfirewall_Domain.log.
  3. Set Size limit (KB) to at least 20480; the maximum is 32767.
  4. Set Log dropped packets to Yes. Set Log successful connections to Yes only while you are investigating, because it grows the log quickly.

The Windows Defender Firewall service writes the log as NT SERVICE\mpssvc. If you choose a new folder, give that account Full Control or no log file appears.

Step 3: Add inbound rules for remote management

Most Windows Firewall Group Policy work is inbound rules for management traffic. Right-click Inbound Rules and choose New Rule…. The wizard offers Program, Port, Predefined and Custom. Predefined groups add the same rules Windows ships with; Custom gives every page, including Scope. After creating a predefined rule, open it and set Scope » Remote IP address to your management subnet and Advanced » Profiles to Domain.

NeedPredefined group or ruleProtocol and port
Remote Desktop“Remote Desktop” (User Mode TCP-In and UDP-In)TCP 3389, UDP 3389
PowerShell remoting“Windows Remote Management” (HTTP-In)TCP 5985 (HTTPS listener: TCP 5986, custom rule)
PingCustom rule, ICMPv4 type 8 and ICMPv6 type 128ICMP echo request
File shares and admin shares“File and Printer Sharing” (SMB-In)TCP 445
Event Viewer, Services, Task Scheduler, Disk Management remotely“Remote Event Log Management”, “Remote Service Management”, “Remote Scheduled Tasks Management”, “Remote Volume Management”RPC endpoint mapper and dynamic RPC
WMI and many monitoring agents“Windows Management Instrumentation (WMI)”RPC / DCOM

Create an ICMP echo rule

  1. Choose Custom, then All programs.
  2. Set Protocol type to ICMPv4, click Customize…, choose Specific ICMP types and tick Echo Request.
  3. Scope: remote IP addresses of your monitoring servers. Action: Allow the connection. Profile: Domain. Name it MGMT – ICMPv4 Echo Request.
  4. Repeat for ICMPv6 with Echo Request if you use IPv6.

Enabling RDP needs more than a port. The “Allow users to connect remotely by using Remote Desktop Services” policy turns the listener on; the firewall rule only lets traffic reach it.

Step 4: Build the same Windows Firewall Group Policy with PowerShell

The NetSecurity cmdlets accept a GPO as the policy store in the form domain\GPO display name. Each call opens and saves the GPO, so for more than a few rules use Open-NetGPO, make all changes in one session and write them once with Save-NetGPO.

$name = 'SEC - Firewall Workstations'
New-GPO -Name $name | New-GPLink -Target 'OU=Workstations,DC=contoso,DC=com'
$store = "contoso.com\$name"
$mgmt  = '10.10.50.0/24'
$s = Open-NetGPO -PolicyStore $store
Set-NetFirewallProfile -GPOSession $s -Profile Domain,Private,Public -Enabled True `
    -DefaultInboundAction Block -DefaultOutboundAction Allow -NotifyOnListen False
Set-NetFirewallProfile -GPOSession $s -Profile Public -AllowLocalFirewallRules False
Set-NetFirewallProfile -GPOSession $s -Profile Domain -LogBlocked True `
    -LogMaxSizeKilobytes 20480 `
    -LogFileName '%SystemRoot%\System32\LogFiles\Firewall\pfirewall_Domain.log'
New-NetFirewallRule -GPOSession $s -DisplayName 'MGMT - RDP (TCP-In)' -Direction Inbound `
    -Protocol TCP -LocalPort 3389 -RemoteAddress $mgmt -Profile Domain -Action Allow
New-NetFirewallRule -GPOSession $s -DisplayName 'MGMT - RDP (UDP-In)' -Direction Inbound `
    -Protocol UDP -LocalPort 3389 -RemoteAddress $mgmt -Profile Domain -Action Allow
New-NetFirewallRule -GPOSession $s -DisplayName 'MGMT - WinRM HTTP (TCP-In)' -Direction Inbound `
    -Protocol TCP -LocalPort 5985 -RemoteAddress $mgmt -Profile Domain -Action Allow
New-NetFirewallRule -GPOSession $s -DisplayName 'MGMT - ICMPv4 Echo Request' -Direction Inbound `
    -Protocol ICMPv4 -IcmpType 8 -RemoteAddress $mgmt -Profile Domain -Action Allow
New-NetFirewallRule -GPOSession $s -DisplayName 'MGMT - SMB (TCP-In)' -Direction Inbound `
    -Protocol TCP -LocalPort 445 -RemoteAddress $mgmt -Profile Domain -Action Allow
Save-NetGPO -GPOSession $s

Read the rules back from the GPO without touching any client:

Get-NetFirewallRule -PolicyStore 'contoso.com\SEC - Firewall Workstations' |
    Format-Table DisplayName, Enabled, Direction, Action, Profile

Keep this script in source control. Changing a rule later is a matter of editing the script and running Set-NetFirewallRule or Remove-NetFirewallRule with the same -PolicyStore.

Step 5: Intune firewall policies

For Microsoft Entra joined devices, go to Endpoint security » Firewall » Create policy and choose platform Windows:

  • The Windows Firewall profile sets the state, default actions, logging and local policy merge for each network type. Local policy merge maps to the Firewall CSP value AllowLocalPolicyMerge.
  • The Windows Firewall rules profile holds the rules. Each profile supports up to 150 rules; rules from several non-conflicting profiles merge on the device.

Two Windows Firewall profiles that set the same setting to different values conflict, and Intune does not send that setting. On co-managed devices, decide whether Group Policy or Intune owns the firewall and keep the other one empty.

Targeting and exceptions

One Windows Firewall Group Policy object rarely fits every machine. Plan the scope before you add rules:

  • Separate GPOs by role. Workstations, member servers and domain controllers need different inbound rules. Do not add workstation rules to the Default Domain Policy.
  • Scope, not exceptions. Restrict each allow rule with Remote IP address rather than creating block rules. Microsoft’s precedence is: explicit block rules win over allow rules, and more specific rules win over less specific ones, so a stray block rule can override your whole design.
  • Security filtering or WMI filters. Use a computer group with Apply group policy denied to exclude a machine, or a WMI filter to apply a server rule set only to a given OS.
  • Connection security rules (optional). Under Connection Security Rules you can require IPsec authentication between domain members. An inbound rule with Allow the connection if it is secure then accepts traffic only from authenticated computers. Pilot this carefully; a mistake can cut off management traffic.

Verify it works

Check each Windows Firewall Group Policy change on a test machine before you widen the link.

  1. Refresh policy and confirm the GPO applies:
    gpupdate /force
    gpresult /scope computer /r
  2. Check the network category. Domain rules only work if the adapter is on the Domain profile:
    Get-NetConnectionProfile | Format-Table InterfaceAlias, NetworkCategory
  3. List the effective rules that came from Group Policy. The ActiveStore is the sum of all stores:
    Get-NetFirewallRule -PolicyStore ActiveStore |
    Where-Object PolicyStoreSourceType -eq 'GroupPolicy' |
    Format-Table DisplayName, Enabled, Profile, Action
    Get-NetFirewallRule -PolicyStore RSOP | Measure-Object
    Get-NetFirewallProfile -PolicyStore ActiveStore |
    Format-Table Name, Enabled, DefaultInboundAction, AllowLocalFirewallRules, LogBlocked
  4. Inspect a rule’s port and address filters: Get-NetFirewallRule -PolicyStore ActiveStore -DisplayName 'MGMT - RDP (TCP-In)' | Get-NetFirewallPortFilter and … | Get-NetFirewallAddressFilter.
  5. Test from a management host with Test-NetConnection -ComputerName PC-0142 -Port 3389, and from a host outside the scope, which should fail.
  6. Policy rules are stored under HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\FirewallRules; netsh advfirewall show allprofiles shows state and logging for each profile.

For per-connection evidence, enable Audit Filtering Platform Connection under Advanced Audit Policy Configuration » System Audit Policies » Object Access. Security event 5157 then records blocked connections and 5156 records allowed ones. This is noisy, so enable it for a short test only.

Troubleshooting

When a Windows Firewall Group Policy rule does not behave as expected, the cause is usually the profile, a block rule or rule merging.

SymptomLikely causeFix
Rule present but port still closedAdapter on Public or Private, rule set to Domain onlyCheck Get-NetConnectionProfile; fix DNS or domain controller reachability
Allowed port is blockedAn explicit block rule from another GPO or local storeSearch ActiveStore for Action -eq 'Block' rules on that port
App stopped working after rolloutLocal rules ignored after “Apply local firewall rules = No”Add the app’s rule to the GPO, or re-enable merging for that profile
No log fileFolder lacks permissions for NT SERVICE\mpssvcUse the default folder or grant Full Control
RDP rule works, RDP still refusedRemote Desktop not enabled or user not in Remote Desktop UsersEnable the RDS connection policy and group membership
Settings flip after syncIntune and GPO both manage the firewallPick one management source
GPO rules missing entirelyGPO not applied (filtering, link, replication)Check gpresult and events 1058/1030

Roll back or undo

  1. A single rule: disable it first (Disable-NetFirewallRule -PolicyStore 'contoso.com\SEC - Firewall Workstations' -DisplayName 'MGMT - SMB (TCP-In)'), confirm nothing breaks, then remove it with Remove-NetFirewallRule.
  2. Profile settings: set the values back to Not configured in Properties; clients fall back to their local settings on the next refresh.
  3. The whole GPO: unlink it and run gpupdate /force. Policy rules are removed from the clients; local rules become active again if they were suppressed by rule merging.
  4. Intune: unassign the profile, or set the conflicting setting to its previous value, and sync the device.

Back up the GPO before each change (Backup-GPO -Name 'SEC - Firewall Workstations' -Path C:\GPOBackup) and roll every Windows Firewall Group Policy update to a pilot OU before the rest of the estate.

Windows Firewall Group Policy at a glance

Windows Firewall Group Policy summary card: Create a GPO linked to the computer OU and open Computer Configuration » Policies » Windows Settings » Security…
In short: Create a GPO linked to the computer OU and open Computer Configuration » Policies » Windows Settings » Security Settings » Windows Defender Firewall with Advanced Security.

Official documentation: Manage Windows Firewall with the command line, Windows Firewall rules, Firewall policy for endpoint security in Intune.

Related guides: Enable Remote Desktop Group Policy and Firewall Rules Made Easy · SMB signing and disabling SMBv1 with Group Policy · Troubleshoot Group Policy not applying: gpresult, RSoP and Events 1058/1030.

Frequently asked questions

Does a Windows Firewall Group Policy override rules created locally?

Rules from the GPO and local rules are combined by default. If you set “Apply local firewall rules” to No for a profile, only Group Policy and MDM rules apply on that profile and local rules are ignored.

Why does my GPO firewall rule work on some laptops but not others?

The rule is probably scoped to the Domain profile. Laptops on home or public networks use the Private or Public profile, so the rule does not apply there, which is usually what you want for management ports.

How do I add firewall rules to a GPO with PowerShell?

Use New-NetFirewallRule with -PolicyStore “domain\GPO name”, or open the GPO once with Open-NetGPO, pass the session with -GPOSession to each cmdlet and write the changes with Save-NetGPO.

How can I see which firewall rules are actually active on a computer?

Run Get-NetFirewallRule -PolicyStore ActiveStore. It returns the sum of local and Group Policy rules, and the PolicyStoreSourceType property shows which ones came from Group Policy.

Maintenance record

This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.

Maintained by
srvScripts editorial team
Supported versions
Windows 11 Pro, Enterprise and Education; Windows Server 2016 to 2025
Last full review
Next review

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.