---
title: Manage Defender Firewall
description: Use this operation to add or remove firewall rules in Microsoft Defender Firewall.
---

[Skip to content](https://knowledge.sittadel.com/manage-defender-firewall#main-content)

[![Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent copy](https://knowledge.sittadel.com/hs-fs/hubfs/Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent%20copy.png?width=55&height=55&name=Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent%20copy.png)](https://sittadel.com/)

- [About Sittadel](https://sittadel.com/about/)
- [Capabilities](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
  
  Show submenu for Capabilities

    - [Microsoft Security Architecture](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
    - [Detection & Response](https://sittadel.com/capabilities/managed-detection-and-response/)
    - [Employee Training](https://sittadel.com/capabilities/security-awareness-training/)
    - [Security Risk Advisors](https://sittadel.com/capabilities/virtual-information-security-officer/)
- [Resources](https://sittadel.com/resources/)
- [Knowledge Base](https://knowledge.sittadel.com/)

Open main navigation

Close main navigation

- [About Sittadel](https://sittadel.com/about/)
- [Capabilities](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
  
  Show submenu for Capabilities

    - [Microsoft Security Architecture](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
    - [Detection & Response](https://sittadel.com/capabilities/managed-detection-and-response/)
    - [Employee Training](https://sittadel.com/capabilities/security-awareness-training/)
    - [Security Risk Advisors](https://sittadel.com/capabilities/virtual-information-security-officer/)
- [Resources](https://sittadel.com/resources/)
- [Knowledge Base](https://knowledge.sittadel.com/)
- [Get Sittadel](https://sittadel.com/start/)

[Get Sittadel](https://sittadel.com/start/)

 Find answers to your security questions.

- There are no suggestions because the search field is empty.

1. [Sittadel Knowledge Base](https://knowledge.sittadel.com/?hsLang=en)
2. [TechOps](https://knowledge.sittadel.com/techops?hsLang=en)
3. [Device Security](https://knowledge.sittadel.com/techops?hsLang=en#device-security)

# Manage Defender Firewall

## Use this operation to add or remove firewall rules in Microsoft Defender Firewall.

### **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Jan-19-2024-04-04-16-2156-PM.png?width=125&height=133&name=image-png-Jan-19-2024-04-04-16-2156-PM.png)Role Requirements**

Procedure Scope: **Administrators**

Required Group Membership: **Admin.Security**

### **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Jan-19-2024-04-13-05-5511-PM.png?width=125&height=148&name=image-png-Jan-19-2024-04-13-05-5511-PM.png)**

### **Handbook Reference**

Package: **Device Security**

Domain: **Firewall Management**

Modifies: **Allowed Defender Firewall Traffic, Blocked Defender Firewall Traffic**

### **![2024-12-17\_9-49-52](https://knowledge.sittadel.com/hs-fs/hubfs/Canva%20images/2024-12-17_9-49-52.png?width=125&height=103&name=2024-12-17_9-49-52.png)**

### **When to Perform this Operation**

As Needed: **Proactive or in Response to User/Security**

#### ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Nov-15-2024-06-17-56-3267-PM.png?width=670&height=47&name=image-png-Nov-15-2024-06-17-56-3267-PM.png)

### Technical Description and Importance

Managing Defender Firewall rules ensures that only authorized network traffic is allowed, reducing the risk of unauthorized access while maintaining operational flexibility. By explicitly defining allowed and blocked traffic, administrators can enforce network security policies while minimizing disruptions to business processes. Regular updates to firewall rules help mitigate emerging threats and ensure compliance with organizational security guidelines. This proactive management supports a secure network infrastructure while allowing necessary business applications and services to function.

### Management Options

- [Add a Firewall Rule](https://knowledge.sittadel.com/manage-defender-firewall#Add-a-Firewall-Rule)
- [Remove a Firewall Rule](https://knowledge.sittadel.com/manage-defender-firewall#Remove-a-Firewall-Rule)

#### ![2024-12-17\_10-15-21](https://knowledge.sittadel.com/hs-fs/hubfs/2024-12-17_10-15-21.png?width=670&height=81&name=2024-12-17_10-15-21.png)

#### Add a Firewall Rule:

> **Purpose**  
> *Adds a new firewall rule to allow or block specific traffic.*  
> **Use Case**  
> *A business-critical application requires a new network exception to function properly.*

#### Remove a Firewall Rule:

> **Purpose**  
> *Deletes an existing firewall rule to restrict or stop specific traffic.*  
> **Use Case**  
> *A deprecated application no longer needs network access, and its associated rule should be removed.*

*![2024-12-17\_10-15-21-1](https://knowledge.sittadel.com/hs-fs/hubfs/2024-12-17_10-15-21-1.png?width=670&height=81&name=2024-12-17_10-15-21-1.png)*

| ###### **Operation** | ###### **Action** | ###### **Target** |
| --- | --- | --- |
| Add a Firewall Rule | **Addition** | Allowed Defender Firewall Traffic, Blocked Defender Firewall Traffic  |
| Remove a Firewall Rule | **Removal** | Allowed Defender Firewall Traffic, Blocked Defender Firewall Traffic |

#### ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Nov-15-2024-06-17-56-3267-PM.png?width=670&height=47&name=image-png-Nov-15-2024-06-17-56-3267-PM.png)

### Add a Firewall Rule

This operation adds a new rule to the Defender Firewall to allow or block specified network traffic.

**       1. Defender Firewall Rule Addition**

> <iframe height="300" src="https://knowledge.sittadel.com/defender-firewall-rule-addition#Procedures" style="border: 1px solid #ccc; border-radius: 8px; box-shadow: 0px 4px 10px rgba(0, 0, 0, 0.1);" width="100%" allowfullscreen loading="lazy" data-mce-src="https://knowledge.sittadel.com/identity-protection-confirm-sign-in-compromised-action#Procedure" data-mce-style="border: 1px solid #ccc; border-radius: 8px; box-shadow: 0px 4px 10px rgba(0, 0, 0, 0.1);" data-mce-fragment="1">
>     </iframe>

#### ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Nov-15-2024-06-17-56-3267-PM.png?width=670&height=47&name=image-png-Nov-15-2024-06-17-56-3267-PM.png)

### Remove a Firewall Rule

This operation removes an existing firewall rule to prevent specific network traffic.

**       1. Defender Firewall Rule Removal**

> <iframe height="300" src="https://knowledge.sittadel.com/defender-firewall-rule-removal#Procedures" style="border: 1px solid #ccc; border-radius: 8px; box-shadow: 0px 4px 10px rgba(0, 0, 0, 0.1);" width="100%" allowfullscreen loading="lazy" data-mce-src="https://knowledge.sittadel.com/identity-protection-confirm-sign-in-compromised-action#Procedure" data-mce-style="border: 1px solid #ccc; border-radius: 8px; box-shadow: 0px 4px 10px rgba(0, 0, 0, 0.1);" data-mce-fragment="1">
>     </iframe>

### Need Assistance?

Reach out to your Customer Success Manager to discuss how a Sittadel cybersecurity analyst can assist in managing these tasks for you. New to our services? [Inquire](https://sittadel.com/start/) about arranging a consultation to explore optimizing your Azure environment for painless management.

- [UserOps](https://knowledge.sittadel.com/userops?hsLang=en#main-content)

    - [Access & Permissions](https://knowledge.sittadel.com/userops?hsLang=en#access-permissions)
    - [Account](https://knowledge.sittadel.com/userops?hsLang=en#account)
    - [Devices](https://knowledge.sittadel.com/userops?hsLang=en#devices)
    - [Document Sharing](https://knowledge.sittadel.com/userops?hsLang=en#document-sharing)
    - [Email](https://knowledge.sittadel.com/userops?hsLang=en#email)
    - [Requests](https://knowledge.sittadel.com/userops?hsLang=en#requests)
    - [Troubleshoot](https://knowledge.sittadel.com/userops?hsLang=en#troubleshoot)
- [TechOps](https://knowledge.sittadel.com/techops?hsLang=en#main-content)

    - [Tenant Foundations](https://knowledge.sittadel.com/techops?hsLang=en#tenant-foundations)
    - [Collaboration Security](https://knowledge.sittadel.com/techops?hsLang=en#collaboration-security)
    - [Email Security](https://knowledge.sittadel.com/techops?hsLang=en#email-security)
    - [Device Security](https://knowledge.sittadel.com/techops?hsLang=en#device-security)
    - [Identity Security](https://knowledge.sittadel.com/techops?hsLang=en#identity-security)
- [SecOps](https://knowledge.sittadel.com/secops?hsLang=en#main-content)

    - [Email SOC](https://knowledge.sittadel.com/secops?hsLang=en#email-soc)
    - [Identity SOC](https://knowledge.sittadel.com/secops?hsLang=en#identity-soc)
    - [Tenant SOC](https://knowledge.sittadel.com/secops?hsLang=en#tenant-soc)
    - [Device SOC](https://knowledge.sittadel.com/secops?hsLang=en#device-soc)
- [Deploy Intune](https://knowledge.sittadel.com/deploy-intune?hsLang=en)
- [Deploy MDE](https://knowledge.sittadel.com/deploy-mde?hsLang=en#main-content)

    - [Overview](https://knowledge.sittadel.com/deploy-mde?hsLang=en#overview)
    - [Intune Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#intune-deployment)
    - [Hands-On Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#hands-on-deployment)
    - [Azure Arc Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#azure-arc-deployment)
    - [RMM Tool Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#rmm-tool-deployment)
    - [MECM/SCCM Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#mecm-sccm-deployment)
    - [GPO Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#gpo-deployment)
- [Deploy Services](https://knowledge.sittadel.com/deploy-services?hsLang=en#main-content)

    - [Cloud Enclave](https://knowledge.sittadel.com/deploy-services?hsLang=en#cloud-enclave)
- [Azure Portals](https://knowledge.sittadel.com/azure-portals?hsLang=en#main-content)

    - [Entra ID](https://knowledge.sittadel.com/azure-portals?hsLang=en#entra-id)
    - [Intune](https://knowledge.sittadel.com/azure-portals?hsLang=en#intune)
    - [Defender](https://knowledge.sittadel.com/azure-portals?hsLang=en#defender)
    - [Purview](https://knowledge.sittadel.com/azure-portals?hsLang=en#purview)
    - [SharePoint Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#sharepoint-admin-center)
    - [Teams Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#teams-admin-center)
    - [Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#admin-center)
    - [Exchange Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#exchange-admin-center)

[![](https://knowledge.sittadel.com/hs-fs/hubfs/Sittadel_LogoH_Color_BlackText.png?width=186&height=55&name=Sittadel_LogoH_Color_BlackText.png)](https://Sittadel.com)

Security for Humans.

Copyright © 2026, Sittadel

<https://www.linkedin.com/company/sittadel> <https://outlook.office365.com/book/StartSittadelcom@sittadel.com/?ismsaljsauthenabled=true> <https://outlook.office365.com/book/StartSittadelcom@sittadel.com/?ismsaljsauthenabled=true>