Hardening Windows Server with Defender Firewall & Audit Policies
Lock down inbound rules, enable advanced auditing, and verify the results with PowerShell on Windows Server 2019, 2022 and 2025.
Common Symptoms and Quick Fixes
| Symptom | Likely Cause | Quick Fix |
|---|---|---|
| Unknown inbound connections | Default allow rules | Set default inbound action to Block |
| No record of logons | Auditing disabled | Enable advanced audit policy |
| Locked out after firewall change | RDP rule missing | Allow RDP only from the admin LAN first |
Method 1: Default-Deny Firewall
Block inbound by default on all profiles, then allow only what the server needs.
Set-NetFirewallProfile -Profile Domain,Private,Public -Enabled True -DefaultInboundAction Block -DefaultOutboundAction Allow
New-NetFirewallRule -DisplayName "Allow RDP from Admin LAN" -Direction Inbound -Protocol TCP -LocalPort 3389 -RemoteAddress 10.0.0.0/24 -Action Allow
Pro Tip for AdministratorsCreate the RDP rule before blocking, and test it from a second session before disconnecting.
Method 2: Enable Auditing
Log logons and account lockouts, then verify.
auditpol /set /subcategory:"Logon" /success:enable /failure:enable
auditpol /set /subcategory:"Account Lockout" /failure:enable
auditpol /get /category:"Logon/Logoff"
Method 3: Review and Export Rules
Export the enabled inbound rules for review.
Get-NetFirewallRule -Direction Inbound -Enabled True -Action Allow | Select-Object DisplayName, Profile | Export-Csv C:\inbound-rules.csv -NoTypeInformation
Frequently Asked Questions (FAQ)
Q: Will this break Windows Update?
No. Outbound traffic stays allowed and updates are initiated outbound.
Q: Should I apply this by Group Policy?
Yes for many servers. Test on one server first, then deploy by GPO.