Reset Windows Firewall to Default in Windows 11 and 10 (and Across a Fleet)

Logeshwaran
—

Resetting Windows Firewall puts every rule, every profile setting and every exception back to the way Windows shipped, and it takes one click in Windows Security or one command: netsh advfirewall reset. It is the right fix when an app stopped connecting after years of installers adding rules, when a removed antivirus left its rules behind, or when you simply can't tell any more which of four hundred rules is the one blocking a port. This guide shows the three ways to reset on Windows 11 and 10, what the reset does and doesn't touch, how to export the current rules first so "reset" isn't "regret", and, for anyone managing PCs, why a firewall governed by Group Policy or Intune can't be reset locally at all and what to do instead.

⚡ Quick Answer

• Reset it (GUI): Windows Security → Firewall & network protection → Restore firewalls to default → Restore defaults. Steps.

• Reset it (command): elevated terminal → netsh advfirewall reset. Steps.

• Back up first: netsh advfirewall export C:\temp\firewall-before.wfw. Why.

• Just one app's rules, not everything: Get-NetFirewallRule -DisplayName "AppName" | Remove-NetFirewallRule. Steps.

• "Some settings are managed by your organization" / Restore defaults grayed: the firewall is policy-managed; the reset is done in Group Policy or Intune, not on the PC. The admin section.

• Firewall service won't start at all: that's a different problem, fixed here.

If you only read this box: export, reset, re-allow the two or three apps that actually need it. Most rules you'll lose were never needed.

Four hundred rules and one printer that stopped answering

Jake's shop has a network printer that every PC could see until, one Tuesday, the counter PC couldn't. Same cable, same printer, same everything, except the day before Jake had uninstalled a trial antivirus that had come with the PC.

"It'll be the firewall," Ethan said, and opened Windows Defender Firewall with Advanced Security on the counter PC. The Inbound Rules list scrolled for a long time: rules from the till software, four versions of it; rules from the trial antivirus, still there, some of them Block; rules from a remote-support tool from two IT people ago; duplicate rules for the same game launcher. Four hundred and twelve rules on a PC that runs a till.

"I could find the one blocking the printer discovery," Ethan said. "Or we could put this back to factory, which takes eleven seconds, and re-allow the till software, which takes another twenty."

They exported the rules first (habit), reset, and re-allowed the till. The printer answered. The exported file still exists, unread, which is exactly what a backup is for.

📚 READ THESE FIRST

New to running AI on your own machine? These five make the rest of this guide easy:

⚡ Two minutes each. Come back here when they are done.

What "reset" actually does, and what it leaves alone

Windows Defender Firewall keeps, per profile (Domain, Private, Public): whether the firewall is on, the default inbound and outbound behavior (block inbound, allow outbound), notification settings, logging settings, and the rules. A reset:

ResetsLeaves alone
Every rule you or an installer added, inbound and outboundThe built-in rules Windows ships (Core Networking, File and Printer Sharing, Remote Desktop and so on): they're restored to their default enabled/disabled state, not deleted
Profile settings: firewall on for all three profiles, inbound blocked, outbound allowedWhich profile a network is in (Private or Public); that's a network setting, not a firewall one
Logging and notification settingsRules pushed by Group Policy or Intune: they come straight back at the next refresh, and on a policy-managed PC the reset may not be allowed at all
Connection security (IPsec) rulesThird-party firewalls from antivirus suites: they have their own reset, and while one is active, Windows Firewall is usually off

So after a reset, apps that need to accept incoming connections (a game server, a media server, remote access, the till's network sync) will prompt again the first time they listen, or need re-allowing; apps that only make outgoing connections (browsers, Office, most things) keep working, because outbound is allowed by default.

Step 0: export the current rules (eleven seconds you'll thank yourself for)

In an elevated terminal (how to open one):

netsh advfirewall export "C:\temp\firewall-before.wfw"

That single file is the whole policy: rules, profiles, logging. Restore it later with netsh advfirewall import "C:\temp\firewall-before.wfw". For a readable copy you can search (which rule mentioned port 9100?), also dump the rules to a spreadsheet:

Get-NetFirewallRule | Select-Object DisplayName, Direction, Action, Enabled, Profile |
  Export-Csv C:\temp\firewall-rules-before.csv -NoTypeInformation

If a reset fixes the problem and you never open either file, that's fine. If it breaks something (a licensing server, a backup agent), the .wfw puts it all back in one line.

Method 1: Windows Security → Restore firewalls to default

  1. Start → Windows Security (or Settings → Privacy & security → Windows Security) → Firewall & network protection.
  2. Scroll down and choose Restore firewalls to default.
  3. Click Restore defaults, confirm at the User Account Control prompt, and confirm again.

The older route does the same thing: Control Panel → System and Security → Windows Defender Firewall → Restore defaults (left pane). Both reset all three profiles at once. If the button is missing or grayed, or you see "Some settings are managed by your organization", skip to the admin section: the reset lives elsewhere.

Method 2: netsh advfirewall reset (and the PowerShell equivalent)

Elevated terminal:

netsh advfirewall reset

It prints "Ok." and it's done; no restart. It's the same operation as the button, which makes it the one to script or run remotely. Two useful companions:

netsh advfirewall set allprofiles state on        # make sure all three profiles are on afterwards
netsh advfirewall show allprofiles                # confirm: State ON, inbound BlockInbound, outbound AllowOutbound

PowerShell, if you'd rather stay in one language: there's no Reset-NetFirewall cmdlet, but the COM object the GUI uses is one line:

(New-Object -ComObject HNetCfg.FwPolicy2).RestoreLocalFirewallDefaults()
Get-NetFirewallProfile | Select-Object Name, Enabled, DefaultInboundAction, DefaultOutboundAction

Both netsh and the COM call are supported on Windows 10 and 11; netsh advfirewall has been "deprecated in favor of PowerShell" for a decade and still works everywhere.

Method 4: the Advanced Security console (reset one profile, or restore the default policy)

Win+R → wf.msc opens Windows Defender Firewall with Advanced Security, the full console behind the Windows Security page. Two resets live here that the simple page doesn't offer:

- Restore Default Policy (right-click the root node, or Action menu): the same full reset as the button and netsh advfirewall reset, with a clear confirmation of what it removes. - Per-profile reset without touching the rules: right-click the root → Properties → the Domain, Private and Public tabs → set Firewall state On, Inbound connections Block (default), Outbound connections Allow (default). That fixes a profile someone switched to "Allow all inbound" while keeping every rule in place.

The console is also where a reset's aftermath is easiest to read: Inbound Rules, sorted by Group, shows the built-in groups back at their defaults, with your own additions gone. Sort by Action to confirm no stray Block rules survived. For the corporate version of this console (the same tree inside a Group Policy Object), see the admin section.

Method 3: Remove one app's rules instead of everything

When you know which app is the problem (typically the one you just uninstalled, or one that installed four sets of rules over four versions), take out its rules and leave the rest:

Get-NetFirewallRule -DisplayName "*TrialAntivirus*" | Select-Object DisplayName, Direction, Action, Enabled
Get-NetFirewallRule -DisplayName "*TrialAntivirus*" | Remove-NetFirewallRule

Or by the program path the rules point at, which catches rules with unhelpful names:

Get-NetFirewallApplicationFilter | Where-Object Program -like "*\OldVendor\*" | Get-NetFirewallRule | Remove-NetFirewallRule

And to find Block rules specifically, which are the ones that cause "it can't connect" mysteries:

Get-NetFirewallRule -Action Block -Enabled True | Select-Object DisplayName, Direction, Profile

To allow a program again afterwards, Windows Security → Firewall & network protection → Allow an app through firewall, or our allow or block an app guide, which covers the Private/Public distinction that trips people up.

🙋‍♂️ Jake's Reality Check

"Will resetting the firewall make my PC less safe?"

The straight answer: no; if anything, safer. The defaults are the secure ones: firewall on for every profile, everything inbound blocked unless a rule allows it, everything outbound allowed. What you lose are the exceptions, and most of those were opened by installers for programs you may not even have any more. The only way a reset weakens you is if a policy or a security tool had deliberately added Block rules, and on a PC where that's the case, the reset is done centrally anyway.

After the reset: the four things to check

  1. All three profiles on. netsh advfirewall show allprofiles, or the three green shields on the Firewall & network protection page. Our check your firewall status guide has the details.
  2. Re-allow what listens. Anything that accepts connections: remote desktop, a media or game server, the till's sync, a NAS backup agent. The prompt appears the first time each one listens; if you dismissed it, use Allow an app through firewall.
  3. Network discovery and file sharing are separate switches (Settings → Network & internet → Advanced network settings → Advanced sharing settings); a reset can leave them on while their firewall rules are back to defaults for the Public profile. If a shared printer or folder vanished, that's the check.
  4. Third-party antivirus. If a suite with its own firewall is installed, Windows Firewall may be off by design and the reset changed nothing; look in the suite.

For IT admins: when the firewall is managed by policy, and how to "reset" a fleet

On a domain-joined or Intune-enrolled PC, the local Restore defaults button often does nothing lasting, or is grayed out, because the firewall configuration is delivered by policy and re-applied at every refresh. That's by design, and it moves the reset to where the policy lives.

Group Policy. Computer Configuration → Windows Settings → Security Settings → Windows Defender Firewall with Advanced Security. Profile settings and rules defined here override local ones. Two settings decide what a local admin can still do: in each profile's Settings → Rule merging, Apply local firewall rules and Apply local connection security rules. With those set to No, locally added rules (including anything an installer adds) are ignored entirely, which is the cleanest possible "reset": the effective rule set is exactly the policy's. To reset a fleet, fix the GPO, then gpupdate /force on the clients, and the local sprawl stops mattering.

Intune. Endpoint security → Firewall → the firewall policy sets each profile's state and defaults; Firewall rules policies carry the rules. The same local rule merge switch exists (Allow Local Policy Merge under each profile). Setting it to Disabled makes local rules irrelevant, which is what most organizations want on managed laptops.

Auditing what a reset (or an installer) did. Event Viewer → Applications and Services Logs → Microsoft → Windows → Windows Firewall With Advanced Security → Firewall. Event 2004 is a rule added, 2006 a rule deleted, 2005 modified, 2003 a profile setting changed. Filtering on 2004 shows which installer added what, and when; after a reset, a burst of 2006 entries is the receipt.

Seeing blocked connections. Turn on logging per profile (Set-NetFirewallProfile -Profile Public -LogBlocked True; the log is %systemroot%\system32\LogFiles\Firewall\pfirewall.log), reproduce the failing connection, and the DROP lines name the port and process. That's how you find which rule you actually needed after a reset, rather than guessing.

Across many machines, the export-then-reset habit scales with the same Invoke-Command pattern as the system-configuration inventory:

Invoke-Command -ComputerName (Get-Content C:\temp\pcs.txt) -ScriptBlock {
  netsh advfirewall export "C:\Windows\Temp\fw-$env:COMPUTERNAME.wfw" | Out-Null
  netsh advfirewall reset | Out-Null
  "$env:COMPUTERNAME reset; backup in C:\Windows\Temp"
}

Run it only on machines where the firewall is not policy-managed; on the managed ones, the policy is the reset.

✅ The admin's version in one line

Manage the firewall from policy with local rule merge turned off, so installers can't add rules that matter; keep 2004/2006 events in the log for the audit; and when a standalone PC needs a reset, export first, reset, re-allow what listens.

Firewall reset problems: the fix table

What you seeWhat it meansWhat to do
Restore defaults button missing or grayedFirewall managed by Group Policy or Intune, or a third-party suiteCheck gpresult /r; reset from policy; check the AV suite
"Some settings are managed by your organization"Policy present (sometimes leftover on a home PC)The managed-by-your-administrator guide
netsh advfirewall reset says the service isn't runningWindows Defender Firewall (mpssvc) or Base Filtering Engine stoppedCannot start the firewall service
Reset worked, an app now can't accept connectionsIts inbound rule is goneAllow it through the firewall; check Private vs Public
Reset worked, printer or shared folder vanishedFile and Printer Sharing rules back to default for the profileSet the network to Private, or enable the rule for Public
Rules reappear after the resetPolicy re-applying them, or an app re-creating its rules at launchExpected; manage from policy, or disable the app's own firewall helper
Still blocked after the resetNot the firewall: router, VPN, antivirus, or the app's own allow-listTurn on LogBlocked and read pfirewall.log; if nothing is dropped, look elsewhere
Windows Firewall shows "Off" and can't be turned onA third-party firewall registered as the active oneUninstall or reconfigure the suite; then netsh advfirewall set allprofiles state on
Error 0x800706d9 when changing settingsBase Filtering Engine service problemThe 0x800706d9 fix

Resetting Windows Firewall: the questions people search

How do I reset Windows Firewall to default in Windows 11?

Windows Security → Firewall & network protection → Restore firewalls to default → Restore defaults. Or, in an elevated terminal, netsh advfirewall reset. Both reset all three profiles and every added rule.

What does netsh advfirewall reset do?

It restores the firewall policy to the Windows defaults: all profiles on, inbound blocked unless allowed, outbound allowed, added rules removed, built-in rules restored to their default state, logging and notification settings reset. Policy-delivered rules return at the next refresh.

Will resetting the firewall delete my rules?

Yes, every rule you or an installer added. Export first with netsh advfirewall export C:\path\backup.wfw and you can import them back in one command.

Does resetting the firewall fix internet connection problems?

Only when a rule was the cause (a leftover Block rule, a removed antivirus's rules, or an app blocked by mistake). If nothing is being dropped in the firewall log after LogBlocked is on, the problem is the router, VPN, DNS or the app, not the firewall.

How do I reset the firewall with PowerShell?

(New-Object -ComObject HNetCfg.FwPolicy2).RestoreLocalFirewallDefaults() performs the same reset the GUI does. There's no dedicated Reset cmdlet, but Get-NetFirewallRule | Remove-NetFirewallRule plus Set-NetFirewallProfile can rebuild the defaults piece by piece.

Why is Restore defaults grayed out?

The firewall is managed by Group Policy or Intune, or a third-party security suite has taken over. On a managed PC the reset happens in the policy; on a home PC with leftover policy, remove the policy registry keys or the old management enrollment.

How do I back up Windows Firewall rules?

netsh advfirewall export "C:\path\firewall.wfw" saves the complete policy; netsh advfirewall import restores it. For a readable list, Get-NetFirewallRule | Export-Csv.

How do I remove firewall rules for one program?

Get-NetFirewallRule -DisplayName "Program" | Remove-NetFirewallRule, or match the program path with Get-NetFirewallApplicationFilter | Where-Object Program -like "\Vendor\" | Get-NetFirewallRule | Remove-NetFirewallRule.

Does resetting the firewall turn it on?

Yes. The defaults have all three profiles enabled. Confirm with netsh advfirewall show allprofiles.

How do I reset the firewall on many computers?

For standalone PCs, run the export-then-reset commands through Invoke-Command against a list of computer names. For managed PCs, set the rules in Group Policy or Intune and turn off local rule merging, so the effective rules are exactly the policy's.

How can I see which rule is blocking a connection?

Enable logging (Set-NetFirewallProfile -Profile Public -LogBlocked True), reproduce the problem, and read %systemroot%\system32\LogFiles\Firewall\pfirewall.log: DROP lines show the direction, port and process. Get-NetFirewallRule -Action Block -Enabled True lists active Block rules.

Is it safe to reset Windows Firewall?

Yes. The defaults are the secure configuration. The risk is functional, not security: apps that accept incoming connections need re-allowing.

Does a reset remove third-party firewall settings?

No. Antivirus suites with their own firewall keep their own rules and often keep Windows Firewall switched off. Reset or reconfigure them in the suite.

What are Domain, Private and Public profiles?

Three rule sets applied depending on the network: Domain when joined to a company domain, Private for networks you marked as trusted (home), Public for everything else. A reset restores all three; which one is active depends on the network's setting, not the firewall.

Where are firewall events logged?

Event Viewer → Applications and Services Logs → Microsoft → Windows → Windows Firewall With Advanced Security → Firewall: 2004 rule added, 2006 rule deleted, 2005 rule modified, 2003 profile setting changed.

Does Windows 10 reset the same way?

Yes. The Windows Security page, the Control Panel button and netsh advfirewall reset are identical on Windows 10.

📖 ALSO READ

More local-AI guides, same honest voice:

⚡ Bookmark this page. The list grows as new guides land.

If your firewall has become a pile of rules nobody remembers adding, resetting it isn't giving up; it's the maintenance every installer skipped. Export first, reset, re-allow the two or three things that genuinely listen, and the firewall goes back to doing its job quietly. If a screen here has moved by the time you read it, tell me through the contact page; Windows moves these buttons between versions, and this page stays accurate because readers write in.

📌 If you keep one line from this page

Export (netsh advfirewall export), reset (netsh advfirewall reset or Restore defaults), then re-allow only what accepts incoming connections.

On a managed PC the reset lives in Group Policy or Intune; turn off local rule merging and installers can't add rules that matter.

Revision note. Originally published December 2016 for Windows 10; rewritten September 26, 2026, for Windows 11 25H2 and Windows 10, adding the export-first step, the PowerShell rule commands, the firewall event IDs and the Group Policy and Intune section. Commands are current as of that date. Next check: when Windows Security moves the Restore defaults button or Microsoft finally retires netsh advfirewall. Export, reset, re-allow.

Related