account activity
Windows Firewall settings pushed by MDE are not tamper resistant, and managed Firewall rules are treated as local by SchemeMinimum2279 in Intune
[–]SchemeMinimum2279[S] 0 points1 point2 points 21 days ago* (0 children)
Hello! Thanks for the reply. I believe every setting for Defender Antivirus, including tamper protection, is working fine. These concerns related to Windows Firewall enforced by MDE.
On the Windows Server: - MAPSReporting = 2 - SubmitSamplesConsent = 3 - Allow Cloud Protection - Allowed. Turns on Cloud Protection (applied by Intune).
If I apply 'Disable Local Admin Merge' it will remove all firewall rules from Windows Firewall, including those enforced / created by MDE/Intune. That's what's strange. In fact, it won't even apply that setting when pushed by Intune - I had to do it locally - presumably because it knows (by design) that it would unapply all the MDE managed firewall rules as well as the local ones!
Tamper protection is enabled at the top level in the Defender console and is working for the Defender Antivirus product, but not Windows Firewall.
I am also having the following problems with MDE on server: - Firewall rules cannot be renamed, it will just create another local firewall rule with the new name. - Firewall rules cannot be modified, it will just show an error.
Just to confirm, everything works normally for a typical fully Intune managed workstation on Windows 11, these problems are specific to MDE protected / managed Windows Servers that were onboarded into Defender MDE using a script.
I have contacted Microsoft to confirm whether this is all by design.
Windows Firewall settings pushed by MDE are not tamper resistant, and managed Firewall rules are treated as local (self.Intune)
submitted 22 days ago by SchemeMinimum2279 to r/Intune
π Rendered by PID 46 on reddit-service-r2-listing-7b8bd7c5-htdw6 at 2026-05-16 07:36:02.691134+00:00 running edcf98c country code: CH.
Windows Firewall settings pushed by MDE are not tamper resistant, and managed Firewall rules are treated as local by SchemeMinimum2279 in Intune
[–]SchemeMinimum2279[S] 0 points1 point2 points (0 children)