Back to blog
SecurityPublished on July 25, 20268 min read

Configure the Windows firewall with Intune

Enable the Windows Defender firewall across all three network profiles with inbound blocked, deployed uniformly across your fleet through Microsoft Intune.

The Windows Defender firewall ships on every device, costs nothing and works well, yet it is often left in an inconsistent state: on here, off there, or quietly changed by an app that opened a port without asking. On a fleet of laptops that join a different network every day, that inconsistency is a real blind spot. Centralising it through Intune guarantees that all your devices enforce the same simple rule: all unsolicited inbound traffic is blocked, everywhere and all the time.

The host firewall is your last line of network defence, the one that stays active when a laptop leaves the office and joins public Wi-Fi. It is precisely in those situations that a well-configured firewall stops a compromised machine on the same network from reaching yours, whether that neighbour is another guest's infected laptop or an attacker probing the café network. Configuring it once from Intune, rather than machine by machine, is as much a security gain as a time saving, and it removes any dependence on the user remembering to leave the firewall on.

The three profiles to cover

Windows applies different firewall rules depending on the network type it detects. You must configure all three, otherwise a laptop on a public network could stay exposed even while the Domain profile is locked down.

  • Domain: corporate network managed by Active Directory or Entra, where the device authenticates the domain controller.
  • Private: trusted networks such as the user's home.
  • Public: hotel, station or café Wi-Fi, the most exposed and often the most used by laptops.

For each profile the baseline is the same: firewall on, inbound connections blocked by default, outbound connections allowed. That lets legitimate apps work while shutting the door on unsolicited connections from the network. Block by default and allow explicitly is far safer than the reverse.

Inbound traffic is blocked across all three network profiles.

Deploy via Intune without breaking line-of-business apps

In Intune the firewall is configured through a Firewall profile (Endpoint Security) or a configuration profile. The key settings are quick to set, and the order in which you apply them limits the risk of a lockout.

  1. 1Enable the Microsoft Defender firewall for the Domain, Private and Public profiles.
  2. 2Set the default inbound action to Block.
  3. 3Set the default outbound action to Allow.
  4. 4Add the legitimate inbound rules you need before locking the Public profile down.
  5. 5Block inbound connections even when a matching rule exists, on the Public profile, for maximum lockdown.

Watch out for legitimate inbound rules: printer sharing, internal remote desktop, backup agents, remote-management tools. Rather than disabling the firewall, add targeted inbound rules for those specific cases, scoped to the Domain or Private profile where possible. You keep a strict lockdown on public networks while letting internal use keep working.

Common mistakes to avoid

Configuring a firewall looks simple, but a few mistakes come up regularly and can either open a hole or cut off legitimate use.

  • Configuring only the Domain profile and forgetting Private and Public, leaving laptops exposed away from the office.
  • Allowing inbound traffic too broadly "to avoid problems", which empties the firewall of its purpose.
  • Letting the user disable the firewall locally, undoing the policy with a single click.
  • Failing to plan a rule for a legitimate business agent, then panic-disabling the whole firewall instead of adding a targeted exception.

Lock the configuration down and log

A firewall policy is only worth something if the user cannot bypass it. Prevent local disabling of the firewall and merge the rules defined by Intune rather than letting local rules override them. That way, even a user who is administrator of their own machine keeps the protection the company enforces, and the configuration stays predictable across the fleet.

Enable logging of blocked connections too: those logs, pulled during an investigation, help you understand what was refused and tell an intrusion attempt apart from an undeclared business need. It is a valuable asset the day you have to explain an incident or justify a rule to an auditor. Without logging, a blocked connection leaves no trace, and you are left guessing whether a failed application is a firewall problem or something else entirely.

A control expected by the standards

An active, properly configured host firewall is a baseline measure in ISO 27001, NIS2 and national cyber-agency guidance. Centralising the configuration also proves, at audit time, that the control is applied uniformly rather than left to each user's discretion. An Intune report showing firewall state across the whole fleet is direct evidence, far more convincing than an isolated screenshot.

A uniform configuration, verifiable at audit time.

Adapt the policy to groups and exceptions

A fleet is never perfectly uniform: a developer's workstation, a small file server or a shop-floor machine do not have the same network needs as a sales laptop. Rather than multiplying policies, it is healthier to start from a strict baseline applied to everyone, then create targeted exception groups for the justified cases. Each exception then stays documented and limited in scope, instead of weakening the general rule.

  • Create a dedicated device group for each family of network needs rather than opening a port for the whole fleet.
  • Name every inbound rule explicitly with the application and the business justification behind it.
  • Scope rules to the Domain or Private profiles when the use never involves a public network.
  • Reassess exceptions periodically and remove those whose application no longer exists.

This discipline avoids the ratchet effect where each exception is added and never removed, until the firewall blocks almost nothing. A clear inventory of inbound rules, reviewed at least once a year, keeps the configuration understandable and defensible. It is also what lets you, at audit time, explain each opening by a real need rather than a setting forgotten long ago.

How AuPoint makes the Windows firewall easy

Setting three profiles cleanly, handling exceptions and verifying enforcement across the fleet can quickly get tedious in the native console. AuPoint is a SaaS that makes Intune security and compliance easy, with no PowerShell. It provides a ready-made firewall policy aligned with best practice, with an impact preview before applying and one-click rollback. You connect your Microsoft tenant, see what will change, then deploy in a few clicks.

Frequently asked questions

Do I really need to block all outbound traffic?

No, the baseline allows outbound and blocks inbound. Filtering outbound is possible but generates many false positives and belongs to other network controls. For a host firewall, the essential thing is to block unsolicited inbound connections.

Does the Intune firewall replace a network firewall?

No, it complements it. The host firewall protects each device individually, including off the corporate network, where the perimeter firewall no longer has any effect. The two layers are complementary, and defence in depth expects both: a perimeter firewall for the office network and a host firewall that travels with every laptop.

What if a business app needs an inbound port?

Add a targeted inbound rule for that application, scoped to the Domain or Private profile if possible, rather than disabling the firewall. You keep the lockdown on public networks that way.

Does the firewall also apply to VPN connections?

Yes. When the device establishes a VPN connection, Windows applies the matching network profile, usually Domain or Private depending on the configuration. The rules defined for those profiles therefore apply to the traffic going through the tunnel, which lets you keep consistent behaviour whether the user is in the office, remote, or connected to the VPN.

Connect your Microsoft tenant to AuPoint and secure the firewall on every Windows device in minutes, with an impact preview and guaranteed rollback, no PowerShell. Start free at aupoint.io.

Secure your tenant in 15 minutes

Free trial