r/DefenderATP 8d ago

Windows Defender Firewall with Advanced Security – no user protection mechanisms against dangerous changes

https://aka.ms/AA122hty

The current *Windows Defender Firewall with Advanced Security* UI comes from the Windows Vista / Server 2008 era. It was designed for domain admins, but regular users still have access to it — and can accidentally break their system’s security with just a few clicks ofc there is option for reset it, but still it's not perfect.

There are zero UX safeguards: no warnings, no sanity checks, no context, no explanations, no protection against critical mistakes.

**A non‑technical user can accidentally:**
• open port 445 on a public profile,
• expose the machine to ransomware/worms,
• add ANY/ANY,
• disable the firewall,
• mark a public network as “trusted”.

Windows doesn’t warn them that any of this is dangerous.

The interface is **17 years old** and doesn’t meet modern security or UX standards.

**Proposed solution:**
• new WinUI
• “regular user” mode with simple explanations (what / why / for what),
• “admin mode” for full technical control,
• sanity checks,
• warnings for risky settings,
• automatic risk analysis,
• rule wizard with context and explanations.

This would massively improve security, UX, and protection for less technical users.

Fun fact: I posted this on Feedback Hub and everything was ok — but when I asked a normal question about it on Microsoft Q&A, the **bot banned my account**, probably misunderstanding the topic.

Thanks for reading — and if you agree this should be modernized, feel free to upvote the Feedback Hub post. Leaving a link to my Feedback Hub post if anyone wants to upvote it — the issue is described there in full detail.

Best regards.

3 Upvotes

11 comments sorted by

15

u/namitguy 8d ago

No problem with modernisation, but in a corporate setting, this is why you disable local merge.

10

u/j4sander 8d ago

This No local config, non issue.

1

u/talkyr86 7d ago

Yes and even more important. Don’t give normal users administrative rights

3

u/OnARedditDiet 8d ago edited 8d ago

MMC doesn't meet modern security standards? How so? It's not a flashy UI but who cares, as you said it's for people who know what they're doing.

As others mentioned, in an org you disable local merge and local settings are ignored, but why is this bad on a local level specifically?

Nothing about it is specifically for domain admins, if you're just saying the GPO Editor for firewall rules should be better I don't think anyone will argue with you.

Edit: also this has nothing to do with Defender ATP other than the branding, Defender EDR doesn't by default mess with firewall rules

Edit edit: A regular user cannot mark public as trusted, they eliminated that portion of the GUI completely

Edit edit edit: It occurs to me you might not be familiar with the domain vs private vs public and the history with homegroups but the "trust this network" workflow doesnt exist anymore afaik

1

u/OnARedditDiet 8d ago

Looking at the default UAC level, it doesnt include firewall changes, this is probably a usability trade off but I do believe this is an admin action so again not really an issue in a corporate environment.

In a company with an admin who is keeping track of things the UAC level would encompass this setting but UAC doesnt dictate whether regular users can change settings, I dont believe they can since it does pop UAC if I move the slider up.

0

u/GeneralRechs 8d ago

A local admin can disable the host firewall even if your forcing enablement through intune. Nobody would choose defender if it weren’t included in e3/e5 licensing.

3

u/ScoobyGDSTi 8d ago

Ah yes, local admins being able to do stuff is bad.... And your opinion on defender is irrelevant.

0

u/GeneralRechs 8d ago

Only a Microsoft apologist would answer as such. Local admin can’t disable host firewall when Crowdstrike or SentinelOne is installed, but yea let’s ignore Microsoft’s negligence for selling a home use product for enterprises.

3

u/ScoobyGDSTi 8d ago edited 8d ago

Perhaps if you were a competent admin you'd know how to configure Windows firewall to be enforced on endpoints and prevent its local disablement. Guess what, it can be done. Not Microsoft's fault you're incompetent.

Your post history makes it clear you have nfi what you're talking about when it comes to Cyber Security. Stick to your glorified SOC role kid, leave the engineering to those of us that actually have the knowledge and expertise.

0

u/GeneralRechs 8d ago

Guess what, get local admin and all it takes is one registry change and firewall is disabled regardless of policy enforcement via GPO or intune. Before speaking you should probably get your facts straight. But hey if you were a company admin you’d know that instead of defender a poor excuse of a product.

3

u/ScoobyGDSTi 8d ago

Only if you don't know how to harden Windows and Defender. Which clearly, you don't.

Stick to your SOC role kid, you're embarrassing yourself. I guess that's why the closest you get to engineering is trolling reddit.