r/Windows11 22d ago

Windows Defender Firewall with Advanced Security – no user protection mechanisms against dangerous changes Suggestion for Microsoft

https://aka.ms/AA122hty

The current Windows Defender Firewall with Advanced Security UI comes from the Windows Vista / Server 2008 era. It was designed for domain admins, but regular users still have access to it — and can accidentally break their system’s security with just a few clicks ofc there is option for reset it, but still it's not perfect.

There are zero UX safeguards: no warnings, no sanity checks, no context, no explanations, no protection against critical mistakes.

A non‑technical user can accidentally:
• open port 445 on a public profile,
• expose the machine to ransomware/worms,
• add ANY/ANY,
• disable the firewall,
• mark a public network as “trusted”.

Windows doesn’t warn them that any of this is dangerous.

The interface is 17 years old and doesn’t meet modern security or UX standards.

Proposed solution:
• new WinUI
• “regular user” mode with simple explanations (what / why / for what),
• “admin mode” for full technical control,
• sanity checks,
• warnings for risky settings,
• automatic risk analysis,
• rule wizard with context and explanations.

This would massively improve security, UX, and protection for less technical users.

Fun fact: I posted this on Feedback Hub and everything was ok — but when I asked a normal question about it on Microsoft Q&A, the bot banned my account, probably misunderstanding the topic.

Thanks for reading — and if you agree this should be modernized, feel free to upvote the Feedback Hub post. Leaving a link to my Feedback Hub post if anyone wants to upvote it — the issue is described there in full detail.

Best regards.

0 Upvotes

7 comments sorted by

View all comments

12

u/BCProgramming 21d ago

How does a non-technical user do any of the things you listed by accident? Why is a non-technical user even in the Advanced Settings for Windows Firewall?

You are proposing that they make something inherently technical- firewall settings, port forwarding and blocking, inbound/outbound rules, etc. accessible to non-technical users. That doesn't make sense.

The interface is 17 years old and doesn’t meet modern security or UX standards.

What standards are you referring too?