STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 4 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to Microsoft Windows Defender Firewall with Advanced Security Security Technical Implementation Guide

V-242004

CAT II (Medium)

Windows Defender Firewall with Advanced Security local firewall rules must not be merged with Group Policy settings when connected to a public network.

Rule ID

SV-242004r922958_rule

STIG

Microsoft Windows Defender Firewall with Advanced Security Security Technical Implementation Guide

Version

V2R2

CCIs

CCI-001190

Discussion

A firewall provides a line of defense against attack. To be effective, it must be enabled and properly configured. Local firewall rules will not be merged with Group Policy settings on a public network to prevent Group Policy settings from being changed.

Check Content

If the system is not a member of a domain, this is NA.

If the firewall's Public Profile is not enabled (see V-17417), this requirement is also a finding.

Verify the registry value below.

If this registry value does not exist or is not configured as specified, this is a finding.

Registry Hive:  HKEY_LOCAL_MACHINE
Registry Path:  \SOFTWARE\Policies\Microsoft\WindowsFirewall\PublicProfile\

Value Name:  AllowLocalPolicyMerge

Type:  REG_DWORD
Value:  0x00000000 (0)

Fix Text

If the system is not a member of a domain, this is NA.

Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Windows Defender Firewall with Advanced Security >> Windows Defender Firewall with Advanced Security >> Windows Defender Firewall Properties (this link will be in the right pane) >> Public Profile tab >> Settings (select Customize) >> Rule merging, "Apply local firewall rules:" to "No".