How is the Windows firewall configured through Group Policy, and what happens when a user tries to switch it off?
A GPO sets the firewall per network profile (domain, private, public), for example on, inbound blocked, outbound allowed, logging on; the user then sees the setting as managed by the organisation and cannot turn it off.
Windows keeps three firewall profiles and picks one by the network it is on: Domain (a DC of its own domain is reachable), Private and Public. A hardened domain profile looks like this:
- Firewall state: On
- Inbound connections: Block (unless a rule allows them)
- Outbound connections: Allow
- Log dropped packets and successful connections: Yes (log size 16 MB)
The setting lives in Computer Configuration > Policies > Windows Settings > Security Settings > Windows Defender Firewall with Advanced Security.
Because a policy setting overrides local configuration, the switch in the Windows Security app is greyed out for that profile, with a notice that the setting is managed by the system administrator. Even a local admin's change would be overwritten at the next policy refresh. That is the point of central configuration: the security baseline does not depend on each user's choices.
Go deeper:
Microsoft Learn: Configure firewall rules with Group Policy — the three profiles and where the settings live in a GPO.
Microsoft Learn: Turn on the firewall and configure default behavior — state, inbound/outbound defaults and logging, step by step.