Windows Defender Firewall can block a traditional desktop application’s network connections by creating an outbound rule for that program. This is useful for testing or restricting software you control, but it is not a substitute for removing malware or applying organization-wide network policy.
Block an app with Windows Defender Firewall
- Open Start and search for Windows Defender Firewall with Advanced Security.
- Select Outbound Rules.
- Choose New Rule and select Program.
- Browse to the executable file for the application you want to restrict.
- Choose Block the connection.
- Select the network profiles to which the rule should apply, give the rule a descriptive name, and finish the wizard.
Close and reopen the application, then test it. Some programs use several executable files, services, or helper processes, so one rule may not cover every network connection.
Undo the block
Return to Outbound Rules and disable or delete the rule you created. Naming the rule clearly makes it easier to identify later.
Know the limitations
Blocking outbound traffic can break sign-in, licensing, synchronization, updates, cloud features, and security checks. Do not block an application’s update mechanism merely to keep an obsolete or vulnerable version running.
On a work or school computer, firewall settings may be centrally managed. Use the organization’s approved controls instead of overriding policy. If an unknown program is making suspicious connections, disconnect sensitive activity as appropriate and run trusted security scans rather than assuming a firewall rule has removed the threat.

Matt Jacobs has been working as an IT consultant for small businesses since receiving his Master’s degree in 2003. While he still does some consulting work, his primary focus now is on creating technology support content for SupportYourTech.com.
His work can be found on many websites and focuses on topics such as Microsoft Office, Apple devices, Android devices, Photoshop, and more.