Information
This policy setting ensures that the Windows Defender Firewall is active on Windows devices. When set to require, Intune verifies that the host-based firewall is enabled on the device, regardless of which network profile (Domain, Private, or Public) is active.
The recommended state for this setting is: Require.
Host-based firewalls provide a critical layer of network traffic control at the device level, independent of perimeter network controls. Enterprise devices frequently connect from untrusted networks (home Wi-Fi, public hotspots, and guest networks) where network-layer defenses are absent or uncontrolled. Disabling the Windows Firewall on these devices exposes open ports and listening services directly to other hosts on the same network segment, significantly increasing lateral movement risk and exposure to network-based exploitation.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
To establish the recommended configuration from Microsoft Intune Admin Center:
- Navigate to Endpoint security > Compliance policies.
- Create or edit a Compliance policy.
- Under System Security\Device Security, set Firewall to Require.
Impact:
Devices where the Windows Defender Firewall has been disabled will be marked non-compliant. Non-compliant devices may lose access to corporate resources until the firewall is confirmed.
If using a third-party firewall solution that disables Windows Defender Firewall, an exception to this policy will be needed.
Note: If the device immediately syncs after a reboot, or wakes from sleep, then this setting may report as an Error. To re-evaluate the compliance status, manually sync the device.