question

brichardi avatar image
0 Votes"
brichardi asked brichardi commented

Configure GPO settings for Windows Defender Firewall with Advance Security.

Hello GPO guru,

I am trying to configure domain GPO settings for the Windows Defender Firewall with Advance Security for Tier domain access.

This is the requirements:

From IT Desktops:
Outbound: Denied RDP from all IT Desktops to all users Workstations, and Member Servers.

From PAW (Privilege Access Workstation)
Inbound: Only except RDP connection from IT Desktops or a subnet.

I try everything I can think of, but nothing is working.

Thanks for your help

windows-group-policy
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

TKujala avatar image
0 Votes"
TKujala answered brichardi commented
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

I've seen the article that you included, I tested it, but its not working. Anyway, I figured out, and now it working. Everyone is denied when they are RDP directly to server/desktop unless they're RDP from the PAW server.

Another issue that I have configured the FW on the local desktop/server to test and everything is working fine, but when I transfer the GPO setting to domain GPO, I can see the GPO is applied, but the RDP policies settings didn't work.

I have made sure the test PC/Server is in a test OU with Block inheritance, so there is no conflict with other GPO.

May be there are differences in GPO templates. My servers are windows 2016, PCs are windows 10, and Domain Controller still 2012 R2.

0 Votes 0 ·