Event details
Is there any plans to bring back the "easy button" to convert Windows Firewall policy into configuration for Intune? I'm in the process of moving a lot of GPOs into Intune and the Windows Firewall Configuration Profiles look like they are going to take a whole lot of manual work.
Luke_Davidson There isn't a one-click firewall "convert" button, but a couple of things can cut down the manual effort:
- Use reusable settings groups(in public preview) for your firewall rules so you define IP ranges, ports, and apps once and reference them across many rules instead of re-entering them for each. This makes rebuilding a large GPO rule set far less tedious.
- Export your existing rules with Get-NetFirewallRule as a working inventory to build from, and you can fins a number of community PowerShell/Graph scripts can help bulk-create the Intune firewall rules from that export. Because these are community tools they are not officially supported, so test thoroughly.
For the "firewall migration easy button," please drop that request at https://aka.ms/IntuneFeedback it's a common ask (you'll likely see it there already, so you can just 👍🏻the existing feedback). Demand logged there directly helps the team prioritize it.
- Dom_CoteJul 15, 2026Iron Contributor
Joe_Lurie and Luke_Davidson For IPv6 it's actually more complicated than that – and may be out of scope for intune. (?)
IPv6 rules in Windows 11 are not "core services" anymore. So setting strict firewall rules in Intune such as "no merging" and "block all incoming" breaks IPv6. On Windows 10, IPv6 rules were "core", so they functioned even when you blocked all incoming.
It'd be AWESOME if the Intune team could work with the Windows team to bring firewall policies / presets / settings that manage IPv6, not break it.
On prem, you probably wouldn't even notice that happening. But in cloud-only environments, IPv6 matters. And you notice that certain apps and services don't work anymore.We needed to manually configure ~30 IPv6 "core" policies in Intune with a total of over 300 settings, so it'd work properly with strict firewall policies.
- Joe_LurieJul 15, 2026
Microsoft
Dom_Cote and Luke_Davidson This is a good scenario and reply, Dom, thank you for taking the time to lay it out in this much detail. You've captured this well: on Windows 10 the default IPv6 rules were effectively treated as "core" and held up under a strict baseline, whereas on Windows 11 they behave differently, so Block all inbound + no merging can disrupt IPv6 in ways that are easy to miss on-prem but very visible in a cloud-only environment. And rebuilding ~30 IPv6 rule groups and 300+ settings to keep a strict policy working is genuine effort.
Your suggestion for Intune and Windows to align on firewall presets/baselines that handle IPv6 cleanly under strict configs is a great suggestion, and I know the teams are in constant contact. But it carries more weight coming from the field with this level of specificity. Please share it at: https://aka.ms/IntuneFeedback (feel free to paste this same summary). I think it works.
- Dom_CoteJul 15, 2026Iron Contributor
Done:
https://feedbackportal.microsoft.com/feedback//idea/59d7ec23-5a80-f111-9b47-6045bdbd0989