How do I lock down Windows Firewall on remote (non-domain) machines that have admin access?

Posted on 2009-05-26
Medium Priority
Last Modified: 2013-12-04
I need to provide documentation and evidence that indicates mobile devices with direct connectivity to the Internet for accessing corporate networks have personal firewall software installed and active per organizational standards and can not be altered by mobile computer users.  
I need a way to send down a script or something to run on remote machines to set the WIndows Firewall (or similar product) up and lock it down.  Can this be done using Windows Firewall?  Is there any free or really cheap firewall software out there maybe that would be easier to deploy?
Question by:ray_ray1
1 Comment
LVL 53

Accepted Solution

Will Szymkowski earned 500 total points
ID: 24476387
Hello there,

Unfortunately if they are a local administrator and not on a domain, they will be able to disable the firewall. what you might want to take a look at is the local GPO that allows remote administration exception.

You will need to set this up on the users local machine and it can be found by doing the following...
Computer Configuration>Administrative Templates>Network>Network Connections>Standard Profile
On the right side there is a remote administration exeption enable that and configure it.

Might do the trick.

Featured Post

Get your problem seen by more experts

Be seen. Boost your question’s priority for more expert views and faster solutions

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Users of Windows 10 Professional can disable automatic reboots using the policy editor. This tool is not included in the Windows home edition. But don't worry! Follow the instructions below to install (a Win7) policy editor on your Windows 10 Home e…
Our Group Policy work started with Small Business Server in 2000. Microsoft gave us an excellent OU and GPO model in subsequent SBS editions that utilized WMI filters, OU linking, and VBS scripts. These are some of experiences plus our spending a lo…
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…
Through the video, you can check the migration process of Outlook PST file to PDF. Kernel for Outlook to PDF tool can convert Outlook emails with all attributes like Subject, To, From, Cc, Bcc and other folders such as Inbox, Outbox, Sent Items, Jun…
Suggested Courses

627 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question