Quantcast
Channel: Group Policy forum
Viewing all articles
Browse latest Browse all 19997

GPO for firewall inbound connections still allows change from "Block (Default)" to "Block all connections"

$
0
0

Hello,

I found an interesting issue where I set a GPO to control the firewall policy to "Block (default)" the inbound connections, however that setting is not completely enforced. It still allows an administrator to alter it from "Block (default)" to "Block all connections". Why is the GPO not forcing the setting I provided?

In more detail:

The settings i'm referring to are in:

  1. Go to Windows Advanced Firewall
  2. Right click on properties
  3. Under any profile tab, in my case Doman Profile
  4. State > Inbound Connections

The GPO is set explicitly to "Block (default)", however this option can still be changed once the GPO is applied.

GPO Setting:

GPO result on server where the policy is applied:

Thanks,

Paul


Viewing all articles
Browse latest Browse all 19997

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>