Server administrators can be prevented from configuring Windows Defender Firewall rules by defining firewall policy centrally in a Group Policy Object and linking it to the servers ' organizational unit(s); domain-based GPO firewall policy overrides any local, administrator-configured Windows Defender Firewall rules on the domain-joined servers, since Group Policy-delivered firewall settings take precedence over local policy. Adaptive network hardening in Microsoft Defender for Cloud only generates recommendations to tighten network security group (NSG) rules protecting Azure resources -- it has no visibility into or control over host-based Windows Defender Firewall configuration on on-premises servers. A network security group (NSG) in Sub1 filters traffic at the Azure virtual network boundary and has no bearing on the on-premises Chicago office servers described in the scenario. An Azure Firewall policy governs the centrally managed Azure Firewall network virtual appliance, not the host-based Windows Defender Firewall running locally on each on-premises server. Because the servers in question are on-premises and domain-joined, only a Group Policy Object can centrally enforce and lock down their local Windows Defender Firewall configuration, preventing server administrators from modifying the rules directly on each machine. Therefore, configuring a GPO is the correct way to reduce this security risk.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit