Microsoft Intune lets you create and deploy Windows Firewall rules to managed devices. You can allow or block traffic based on ports, protocols, applications, and IP addresses. In this guide, I will create an inbound rule that allows Remote Desktop traffic from a specific source IP address to selected Windows devices. I will also explain how to verify the rule and troubleshoot connectivity.
Contents
Firewall Profiles
Microsoft Intune provides the following Windows Defender Firewall profiles that you can configure for managed Windows devices.
| Profile | Purpose |
|---|---|
| Windows Firewall | Configure firewall settings, including network profiles and default traffic behaviour. For more details on managing the Windows firewall, refer to the link: Manage Windows Defender Firewall Using Intune. |
| Windows Firewall rules | Create individual rules that allow or block specific traffic. |
| Windows Hyper-V Firewall Rules | Controls network traffic to and from supported Hyper-V containers, including Windows Subsystem for Linux (WSL). |
Use Endpoint security > Firewall to manage these profiles. Each Windows Firewall rules policy supports up to 150 custom rules. Multiple rules policies can apply to the same device. Creating an allow rule does not enable the application or service that receives the connection. For example, an RDP firewall rule does not turn on Remote Desktop.
Prerequisites
- Windows devices enrolled in Intune.
- Intune permissions to create and assign endpoint security policies.
- A Microsoft Entra device group containing the destination devices.
- Windows Firewall enabled on the relevant network profiles.
- Application’s required ports, protocols, and address ranges.
- A test device for validating the configuration.
For this RDP example, Remote Desktop must also be enabled on a supported Windows edition, and the connecting user must have permission to sign in remotely.
Understand Local and Remote Settings
Before we go through the steps to create an inbound Windows Firewall rule using Intune, it’s important to understand what local and remote ports and local and remote addresses mean with respect to inbound rules.
| Setting | Meaning |
|---|---|
| Local address | Destination address on the managed device |
| Remote address | Source address of the connecting device |
| Local port | Destination port on the managed device |
| Remote port | Source port used by the connecting device |
For an outbound connection, the local device is the sender. Local and remote still refer to the managed device and the other endpoint, respectively.
Example Configuration
To demonstrate how to create a Windows Firewall rule in Intune, we will use the following example: Allow inbound TCP traffic on port 3389 (RDP) from the remote IP address 10.1.1.2 to assigned devices, but only for local IP addresses within the 10.2.3.0/24 subnet.
Before creating any firewall rule, make sure you have all the required information, such as the protocol, port number, local and remote IP addresses, and the action (allow or block), to ensure the rule is configured correctly.
- Source device: 10.1.1.2
- Destination devices: Devices with addresses in 10.2.3.0/24
- Protocol: TCP
- Destination port:
3389 - Direction: Inbound
Create a Firewall Rules Policy
Let’s go through the steps to create a custom Windows Defender Firewall rule using the Intune admin center.
- Sign in to the Intune admin center > Endpoint Security > Firewall.
- Select Create Policy.
- Select:
- Platform: Windows
- Profile: Windows Firewall Rules.
- Select Create.

- On the Basics page, provide a name and description of the policy. Click Next.
| Name | Cloudinfra RDP Allow Rule |
| Description | Allow inbound TCP 3389 from 10.1.1.2 to assigned devices with local addresses in 10.2.3.0/24. |
Configure the Inbound Rule
Under Configuration settings, click + Add to create a new firewall rule. Enter a Name for the rule, and then click Edit instance to configure its settings.

On the Edit instance page, configure the firewall rule settings as shown below. The configuration in this example matches the scenario discussed earlier. You can modify these settings to meet your own network and security requirements.
| Setting | Value |
|---|---|
| Name | Allow RDP from 10.1.1.2 |
| Enabled | Enabled |
| Direction | Inbound |
| Action | Allow |
| Protocol | 6 — TCP |
| Local Port Ranges | 3389 |
| Remote Port Ranges | Leave unconfigured — any source port |
| Local Address Ranges | 10.2.3.0/24 |
| Remote Address Ranges | 10.1.1.2 |
| Network Types / Profiles | Domain and Private for this example |
| Interface Types | All |
| Edge Traversal | Disabled |

- Scope tags (optional): A scope tag in Intune is an RBAC label that you assign to resources such as policies, apps, and devices to control which administrators can view and manage them. For more information, see How to use scope tags in Intune.
- Assignments: Assign the policy to Microsoft Entra security groups that include the target devices. As a best practice, start with a small pilot group, and once validated, expand the assignment more broadly. For guidance on assignment strategy, see Intune assignments: User groups vs. Device groups.
- Review + create: Review the deployment summary and click Create.

Verify Firewall Rule Creation
Use the following steps to verify that the Windows Firewall rule has been successfully applied to the target devices.
- Press Windows key + R to open the Run dialog box.
- Type
wf.mscto open Windows Defender Firewall with Advanced Security console.

- Open Monitoring > Firewall.
- Locate the firewall rule that you created. In this example, the rule is named Allow RDP from 10.1.1.2. As shown in the screenshot below, the rule has been created successfully and is present in Windows Defender Firewall with Advanced Security.

- You can double-click the firewall rule to view its detailed configuration.

You can also verify that the firewall rule has been created successfully by running the following PowerShell command on one of the target devices.
Get-NetFirewallRule -PolicyStore ActiveStore -DisplayName 'Allow RDP from 10.1.1.2' -ErrorAction Stop

Manage Windows Defender Firewall using OMA-URI
You can also manage Windows Defender Firewall rules by using OMA-URI settings through the Firewall CSP. If you require more advanced or custom firewall configurations, refer to the Firewall CSP documentation.
Firewall Rule Settings
Below is a quick reference that explains each Windows Firewall rule setting. Use this section to quickly understand the purpose of each option. If you need more detailed information about any setting, refer to the following section of this guide.
- Name: A descriptive name for the firewall rule.
- Description: Explains the rule’s purpose.
- Enabled: Turns the rule on or off.
- Direction: Applies the rule to inbound or outbound traffic.
- Action: Allows or blocks matching traffic.
- Network Types: Selects the applicable profiles: Domain, Private, or Public.
- Interface Types: Selects LAN, Wireless, Remote Access, or All.
- Protocol: Specifies the protocol, such as TCP (6) or UDP (17).
- Local Address Ranges: Specifies IP addresses or subnets on the managed device.
- Remote Address Ranges: Specifies IP addresses or subnets of the other endpoint.
- Local Port Ranges: Specifies ports on the managed device, such as
3389. - Remote Port Ranges: Specifies ports on the other endpoint.
- Service Name: Restricts the rule to a Windows service’s short name.
- Package Family Name: Identifies the packaged application the rule targets.
- Local User Authorized List: Restricts the rule to specified local user identities using SDDL.
- ICMP Types and Codes: Filters specific ICMP messages.
- Edge Traversal: Allows eligible inbound traffic through Teredo NAT traversal.
- Remote Address Dynamic Keywords: References dynamically maintained address definitions.
- File Path: Specifies the application executable’s full path. Wildcard paths are unsupported.
- Policy App ID: Targets applications tagged by an App Control for Business AppID policy.
In Windows Defender Firewall rules, Local always refers to the device receiving the policy or the traffic, while Remote refers to the other endpoint that is sending or receiving the network traffic.
| More Detailed Information about Each Firewall Setting |
|---|
| Enabled: Indicates whether the rule is enabled or disabled. If not specified – a new rule is disabled by default. Name: Specifies the friendly name of the firewall rule. Interface Types: Multiple interface types can be included in the string by separating each value with a “,”. Acceptable values are “RemoteAccess”, “Wireless”, “Lan”, and “All”. If more than one interface type is specified, the strings must be separated by a comma. File Path: The file path of an app is its location on the client device. For example, C:\Windows\System\Notepad.exe or %WINDIR%\Notepad.exe. You can define one application to be used in each Firewall rule. If you specify multiple conditions in a single rule, these will be treated as an AND operation. i.e program=svchost.exe AND service=mpssvc, etc. All of the app-related conditions in a single rule work to scope the traffic even further, so they must all correspond to the specific app/service. Remote Port Ranges: List of remote port ranges. Valid values include A valid port number between 0 and 65535. For example, a 200 A port range in the format of “start port – end port” with no spaces included, where the start port is less than the end port. For example, 300-320 If not specified, the default is “All ports.” When defining multiple local and remote port ranges, the Firewall rule will be evaluated as OR operations within an individual field, and AND operations across rule fields. i.e. (local port A OR local port B) AND (remote port A OR remote port B). When setting this field in a firewall rule, the protocol field must also be set to 6 (TCP) or 17 (UDP). Edge Traversal: Indicates whether edge traversal is enabled or disabled for this rule. The EdgeTraversal property indicates that specific inbound traffic can tunnel through NATs and other edge devices using the Teredo tunneling technology. The application or service with the inbound firewall rule must support IPv6 for this setting to work correctly. The primary application of this setting allows listeners on the host to be globally addressable through a Teredo IPv6 address. New rules have the EdgeTraversal property disabled by default. Local User Authorized List: Specifies the list of authorized local users for this rule. A list of authorized users cannot be specified if the authored rule targets a Windows service. If not specified, the default is all users. Network Types: Specifies the profiles to which the rule belongs: Domain, Private, Public. See FW_PROFILE_TYPE for the bitmasks that are used to identify profile types. If not specified, the default is All. Direction: Comma separated list. The rule is enabled based on the traffic direction as following. IN – the rule applies to inbound traffic. OUT – the rule applies to outbound traffic. If not specified the detault is OUT. Service Name: Short Windows service names are used when a service, not an application, sends or receives traffic. Service short names can be retrieved by running the Get-Service command from PowerShell. You can define one application to be used in each Firewall rule. If you specify multiple conditions in a single rule, these will be treated as an AND operation. i.e program=svchost.exe AND service=mpssvc, etc. All of the app-related conditions in a single rule work to scope the traffic even further, so they must all correspond to the specific app/service. Local Port Ranges: List of local port ranges. Valid values include A valid port number between 0 and 65535. For example, 200 A port range in the format of “start port – end port” with no spaces included, where the start port is less than the end port. For example, 300-320 If not specified, the default is “All ports.” When defining multiple local and remote port ranges, the Firewall rule will be evaluated as OR operations within an individual field, and AND operations across rule fields. i.e. (local port A OR local port B) AND (remote port A OR remote port B). When setting this field in a firewall rule, the protocol field must also be set, to either 6 (TCP) or 17 (UDP). Remote Address Ranges: List of remote addresses covered by the rule. Tokens are case insensitive. Valid tokens include:”*” indicates any remote address. If present, this must be the only token included. “Defaultgateway” “DHCP” “DNS” “WINS” “Intranet” (supported on Windows versions 1809+) “RmtIntranet” (supported on Windows versions 1809+) “Internet” (supported on Windows versions 1809+) “Ply2Renders” (supported on Windows versions 1809+) “LocalSubnet” indicates any local address on the local subnet. A subnet can be specified using either the subnet mask or network prefix notation. If neither a subnet mask nor a network prefix is specified, the subnet mask defaults to 255.255.255.255. A valid IPv6 address. An IPv4 address range in the “start address – end address” format with no spaces included, where the start address is less than the end address. An IPv6 address range in the “start address – end address” format with no spaces included, where the start address is less than the end address.If not specified, the default is “Any address.” Action: Specifies the action the rule enforces to block or allow network traffic. Description: Specifies the description of the rule. Policy App Id: Specifies one WDAC tag. This is a string that can contain any alphanumeric character and any of the characters “:”, “/”, “.”, and “_”. A PolicyAppId and ServiceName cannot be specified in the same rule. Package Family Name: Package family names can be retrieved by running the Get-AppxPackage command from PowerShell. You can define one application to be used in each Firewall rule. If you specify multiple conditions in a single rule, these will be treated as an AND operation. i.e program=svchost.exe AND service=mpssvc, etc. All of the app related conditions in a single rule work to scope the traffic even further, so they must all correspond to the specific app/service. Protocol: Select the protocol for this port rule. Transport layer protocols, TCP(6) and UDP(17), allow you to specify ports or port ranges. For custom protocols, enter a number between 0 and 255 representing the IP protocol. If not specified, the default is “Any.” ICMP Types And Codes: Select the protocol for this port rule. Transport layer protocols, TCP(6) and UDP(17), allow you to specify ports or port ranges. For custom protocols, enter a number between 0 and 255 representing the IP protocol. If not specified, the default is “Any.” Local Address Ranges: List of local addresses covered by the rule. Valid tokens include:”*” indicates any local address. If present, this must be the only token included. A subnet can be specified using either the subnet mask or network prefix notation. If neither a subnet mask nor a network prefix is specified, the subnet mask defaults to 255.255.255.255.A valid IPv6 address.An IPv4 address range in the format of “start address – end address” with no spaces included, where the start address is less than the end address.An IPv6 address range in the format of “start address – end address” with no spaces included, where the start address is less than the end address. If not specified, the default is “Any address.” |
