MH IT SOLUTION — Production Tech Knowledge Base & IT Troubleshooting Guides ▶ YouTube Channel

Hardening Windows Server with Defender Firewall & Audit Policies

MH IT SOLUTION Editorial Team · Updated August 17, 2026 · 9 min readAdvanced

Lock down inbound rules, enable advanced auditing, and verify the results with PowerShell on Windows Server 2019, 2022 and 2025.

Common Symptoms and Quick Fixes

Symptom Likely Cause Quick Fix
Unknown inbound connections Default allow rules Set default inbound action to Block
No record of logons Auditing disabled Enable advanced audit policy
Locked out after firewall change RDP rule missing Allow RDP only from the admin LAN first

Method 1: Default-Deny Firewall

Block inbound by default on all profiles, then allow only what the server needs.

Set-NetFirewallProfile -Profile Domain,Private,Public -Enabled True -DefaultInboundAction Block -DefaultOutboundAction Allow
New-NetFirewallRule -DisplayName "Allow RDP from Admin LAN" -Direction Inbound -Protocol TCP -LocalPort 3389 -RemoteAddress 10.0.0.0/24 -Action Allow
Pro Tip for AdministratorsCreate the RDP rule before blocking, and test it from a second session before disconnecting.

Method 2: Enable Auditing

Log logons and account lockouts, then verify.

auditpol /set /subcategory:"Logon" /success:enable /failure:enable
auditpol /set /subcategory:"Account Lockout" /failure:enable
auditpol /get /category:"Logon/Logoff"

Method 3: Review and Export Rules

Export the enabled inbound rules for review.

Get-NetFirewallRule -Direction Inbound -Enabled True -Action Allow | Select-Object DisplayName, Profile | Export-Csv C:\inbound-rules.csv -NoTypeInformation

Frequently Asked Questions (FAQ)

Q: Will this break Windows Update?

No. Outbound traffic stays allowed and updates are initiated outbound.

Q: Should I apply this by Group Policy?

Yes for many servers. Test on one server first, then deploy by GPO.

Leave a Reply

Your email address will not be published. Required fields are marked *