📁 last tech Posts

How to Block a Program from Accessing the Internet on Windows

How to block a program from accessing the internet on Windows 10 and Windows 11 using Windows Defender Firewall — 2026 step-by-step guide

Block any app's internet access in minutes — no third-party tools required, just Windows Defender Firewall.

If you've ever wanted to stop a program from accessing the internet — whether that's a game phoning home for updates at the worst moment, software you don't fully trust, or an app you want to use offline only — Windows has a built-in way to do exactly that. No paid firewall tool needed.

In this updated 2026 guide, I'll show you how to block a program from accessing the internet on Windows 10 and Windows 11 using Windows Defender Firewall — the tool that's already on your machine. I'll also cover three alternative methods: using the Command Prompt, using PowerShell (the modern approach), and using a lightweight free tool for those who prefer a visual interface.

From my experience helping dozens of people with this, the most common reason they end up here is one of three things: a game that won't stop downloading updates mid-session, software that sends telemetry they didn't agree to, or an app that simply works better when it can't reach its activation server. Whatever your reason, you're in the right place. Let's get into it.

I'm Mostafa Amaan, and on Valley4Techs I write practical tech guides built around real-world use cases — not textbook theory.

Why Would You Want to Block a Program's Internet Access?

Before diving into the steps, it's worth understanding the common scenarios — because the why often determines which method makes the most sense for you.

  • Stopping unwanted auto-updates. Some programs update themselves in the background, interrupting your work or consuming bandwidth at inconvenient times. Blocking them gives you full control over when updates happen.
  • Preventing telemetry and data collection. Many apps send usage data back to their servers by default. If you'd rather keep that information local, cutting off internet access at the firewall level is more reliable than hunting for opt-out settings buried in menus.
  • Testing offline behavior. Developers often need to see how an app behaves without a network connection. Blocking it at the OS level is cleaner than disconnecting the whole machine.
  • Security and containment. If you're running software you're not 100% sure about — maybe an old utility you found on a hard drive — preventing it from reaching the internet limits the damage it can do.
  • Parental controls and focus. Blocking a game from connecting online forces offline-only mode, which can be exactly what you need during study time.
💡 Good to know: Windows Defender Firewall blocks happen at the network layer. The program still runs normally — it just can't send or receive data over the internet. From the app's perspective, it's as if there's no network. Most apps handle this gracefully; a few will show a "no connection" error inside their own interface.

Method 1: Block a Program Using Windows Defender Firewall (Recommended)

This is the cleanest and most reliable method. It works on Windows 10 and Windows 11, requires no downloads, and gives you a persistent rule that survives reboots. Here's how to do it step by step.

🎬 Prefer watching? Here's a quick video walkthrough:

Full step-by-step video guide — follow along or continue reading below.

Step 1: Open Windows Defender Firewall with Advanced Security

Press Windows + R to open the Run dialog, type wf.msc, and press Enter. This opens the advanced firewall console directly — faster than going through the Control Panel.

Run Dialog

wf.msc

Alternatively, search for "Windows Defender Firewall with Advanced Security" in the Start menu. If Windows asks for administrator permission, click Yes — you'll need admin rights to create firewall rules.

Step 1: Opening Windows Defender Firewall with Advanced Security using the Run dialog (wf.msc) on Windows

Opening Windows Defender Firewall with Advanced Security via the Run dialog.

💡 Windows 11 24H2 note: Starting with the 2025–2026 updates, Windows may prompt you with a Windows Hello biometric verification (fingerprint or face recognition) when modifying firewall rules. This is a new "Identity Check" security feature — just authenticate normally and proceed. It doesn't change any of the steps below.

Step 2: Navigate to Outbound Rules

In the left panel of the Firewall console, you'll see three options: Inbound Rules, Outbound Rules, and Connection Security Rules. Click Outbound Rules. This is the one that controls traffic leaving your PC — which is what we want to block.

Step 2: Selecting Outbound Rules in the Windows Defender Firewall with Advanced Security console

Navigating to Outbound Rules in the Firewall console's left panel.

⚠️ Inbound vs. Outbound — which one matters? Inbound rules control connections coming into your PC (like someone trying to connect to a server you're running). Outbound rules control what your programs send out. For blocking an app's internet access, you almost always want an Outbound rule. Some guides tell you to create both — that's fine for extra caution, but outbound alone is sufficient for most use cases.

Step 3: Create a New Outbound Rule

In the right panel (Actions), click "New Rule…". The New Outbound Rule Wizard will open. Follow these selections:

  1. Rule Type: Select Program and click Next. This tells Windows you want to target a specific executable file.
  2. Program Path: Select "This program path" and click Browse. Navigate to the .exe file of the program you want to block. Common locations are C:\Program Files\ or C:\Program Files (x86)\. Click Next when done.
  3. Action: Select "Block the connection" and click Next.
  4. Profile: Leave all three checkboxes selected (Domain, Private, Public). This ensures the block applies regardless of which network you're connected to. Click Next.
  5. Name: Give the rule a descriptive name, like Block [AppName] Internet. This makes it easy to find and remove later. Click Finish.
Step 3: Creating a new outbound rule in the Windows Defender Firewall wizard to block a program's internet access

The New Outbound Rule Wizard — select Program, browse to the .exe, and block the connection.

The rule is now active. Your chosen program will no longer be able to reach the internet — immediately, without requiring a reboot.

💡 Can't find the .exe file? The easiest way is to right-click the program's shortcut on your desktop or taskbar, select Properties, and look at the "Target" field. That's the full path to the executable. Copy it and paste it directly into the program path field in the wizard.

Step 4: Test and Verify the Block

Open the program and try to do something that requires internet access — check for updates, log in online, or load a web-connected feature. It should fail. If the app has a "check for updates" option, that's the quickest test. A network timeout or "no connection" message from the app confirms the rule is working.

For a more technical verification, you can use any of these methods:

  • Resource Monitor: Press Windows + R, type resmon, and go to the Network tab. If the blocked program appears with zero activity or "filtered" status, your rule is working.
  • Command line check: Run netstat -b in an admin Command Prompt to see all active connections by process name. Your blocked app should not appear.
  • Firewall logs: Open wf.msc → right-click "Windows Defender Firewall with Advanced Security" → Properties → under the relevant profile tab, enable Logging. Blocked connections will be recorded in %systemroot%\system32\LogFiles\Firewall\pfirewall.log.

Method 2: Block Internet Access Using Command Prompt

If you prefer working from the command line, or you need to script this for multiple machines, you can create the same firewall rule to block internet access in a single command. This is the approach I use when setting up lab machines — it's faster once you know the path.

Open Command Prompt as Administrator (right-click the Start button → "Windows Terminal (Admin)" or search for cmd and choose "Run as administrator"), then run:

Command Prompt (Admin)

netsh advfirewall firewall add rule name="Block AppName Internet" dir=out action=block program="C:\Path\To\Your\program.exe" enable=yes

Replace "Block AppName Internet" with a meaningful rule name, and update the path to match the actual .exe location. If the path contains spaces, make sure the quotes around it are there — otherwise the command will fail silently.

To block both outbound and inbound traffic (for complete network isolation), run the command twice — once with dir=out and once with dir=in.

Block both directions

netsh advfirewall firewall add rule name="Block AppName Outbound" dir=out action=block program="C:\Path\To\program.exe" enable=yes
netsh advfirewall firewall add rule name="Block AppName Inbound" dir=in action=block program="C:\Path\To\program.exe" enable=yes

To verify the rule was created, you can list all firewall rules filtered by name:

Verify the rule

netsh advfirewall firewall show rule name="Block AppName Internet"

Method 3: Block a Program Using PowerShell (Modern Approach)

PowerShell is the modern replacement for netsh when it comes to managing Windows Defender Firewall rules. The syntax is cleaner, more readable, and significantly easier to script — especially if you need to block internet access for multiple programs at once.

Open PowerShell as Administrator (right-click the Start button → "Windows Terminal (Admin)"), then run:

PowerShell (Admin) — Block outbound

New-NetFirewallRule -DisplayName "Block AppName Internet" `
    -Program "C:\Path\To\Your\program.exe" `
    -Action Block `
    -Direction Outbound `
    -Profile Domain, Private, Public

Managing the rule afterward is just as straightforward:

PowerShell — Verify, disable, re-enable, or remove

# Check if the rule exists
Get-NetFirewallRule -DisplayName "Block AppName Internet"

# Temporarily disable the rule (restore internet access)
Disable-NetFirewallRule -DisplayName "Block AppName Internet"

# Re-enable the rule
Enable-NetFirewallRule -DisplayName "Block AppName Internet"

# Remove the rule entirely
Remove-NetFirewallRule -DisplayName "Block AppName Internet"

Batch Blocking: Block Multiple Programs at Once

Need to block internet connection for several apps simultaneously — like all Adobe telemetry executables, or every game launcher on a shared PC? Here's a PowerShell script that handles it:

PowerShell — Block multiple apps at once

$appsToBlock = @(
    "C:\Program Files\App1\app1.exe",
    "C:\Program Files\App2\app2.exe",
    "C:\Program Files (x86)\App3\app3.exe"
)

foreach ($app in $appsToBlock) {
    $name = "Block " + (Split-Path $app -Leaf)
    New-NetFirewallRule -DisplayName $name `
        -Program $app `
        -Action Block `
        -Direction Outbound `
        -Profile Domain, Private, Public
    Write-Host "Blocked: $app" -ForegroundColor Green
}
💡 Why PowerShell over netsh? Microsoft has been recommending PowerShell's *-NetFirewallRule cmdlets as the modern replacement for netsh advfirewall. PowerShell offers better error handling, is easier to integrate into automation scripts, and returns structured objects you can pipe into other commands. Use netsh if you're on an older system or working in a plain Command Prompt; use PowerShell for everything else.

How to Remove the Block (Restore Internet Access)

Blocking is reversible. Here's how to undo it using both methods.

Removing via the Firewall GUI

  1. Open wf.msc again.
  2. Click Outbound Rules in the left panel.
  3. Find the rule you created by name (this is why naming it well matters).
  4. Right-click it and select Delete. Confirm, and the block is gone instantly.

Alternatively, you can right-click the rule and choose Disable Rule instead of deleting it. This keeps the rule saved for later reuse without actually enforcing it — useful if you plan to toggle the block on and off regularly.

Removing via Command Prompt

Command Prompt (Admin)

netsh advfirewall firewall delete rule name="Block AppName Internet"

Use the exact same name you used when creating the rule. If you're not sure of the name, you can list all custom rules with:

List all outbound block rules

netsh advfirewall firewall show rule dir=out action=block

Common Problems and How to Fix Them

The firewall approach is straightforward, but I've seen a few specific issues come up repeatedly. Here's what to do when the block doesn't seem to work as expected.

Problem: The Program Is Still Connecting

The most common reason for this: the program has multiple executables. Some software separates its updater or launcher into a different .exe file from the main app. For example, a game might have game.exe and updater.exe — you blocked one but not the other.

To find all executables in a folder quickly, open Command Prompt and run:

Command Prompt

dir "C:\Program Files\AppName\" /s /b *.exe

This lists every .exe in the app's folder and subfolders. Block each one that might be responsible for the connection.

Problem: The Rule Was Created But the App Still Has Internet

Double-check that the path in your firewall rule exactly matches the actual executable location. A common mistake is blocking C:\Program Files\App\app.exe when the app actually installed to C:\Program Files (x86)\App\app.exe. Open the rule in the firewall GUI and verify the path is correct.

Problem: Blocking a Microsoft Store (UWP) App

Microsoft Store apps (also called UWP apps) don't work quite the same way — they don't have a simple .exe path you can just browse to. Their executables are stored in the hidden C:\Program Files\WindowsApps folder. To block internet access for a UWP app, you have two options:

  1. Firewall method (recommended): In the New Outbound Rule Wizard, when you select "Program" as the rule type, look for the Store app in the system's program list rather than browsing manually. You may need to enable "Hidden items" in File Explorer to locate the executable path.
  2. Third-party tool: Use a tool like Simplewall or TinyWall, which can detect and list UWP apps automatically for easy blocking.
⚠️ Important clarification: You may see advice to disable "Background App Permissions" via Settings → Apps → Installed Apps → Advanced options in Windows 11 (or Privacy → Background Apps in Windows 10). This is not the same as blocking internet access. Turning off background permissions only prevents the app from running when it's not in the foreground — when you actually open the app, it will still have full internet access. To truly block an application from accessing the internet, you need a firewall rule.

Windows Firewall vs. Third-Party Tools: Which Should You Use?

Once in a while someone asks me whether they should install a dedicated firewall manager instead of using the built-in Windows Firewall. My honest take: for most people, the built-in tool is all you need. Here's a quick comparison to help you decide.

Feature Windows Firewall Third-Party Tools (e.g. TinyWall, Simplewall, GlassWire)
Cost Free (built-in) Free to paid
Ease of use Moderate (wizard-based) Easier (visual interface)
Reliability Very high (OS-level) Good (uses Windows Firewall under the hood)
Real-time monitoring Limited (via logs when enabled) Yes (live traffic dashboards)
Works on all Windows apps Yes Yes
System overhead None (built-in service) Minimal to moderate

TinyWall (v3.4.1, still actively maintained in 2025) is worth a special mention: it's a free, lightweight frontend for Windows Firewall that makes managing rules much easier without adding any extra firewall layer of its own. Simplewall is another excellent open-source option — it's the closest functional competitor to TinyWall and very popular in the privacy community for its simple block/allow rule management. If you find yourself needing software to block internet access for many apps regularly, either of these tools is a smart addition.

For most people reading this guide — blocking one or two specific programs — the built-in firewall is the right tool. If you're also interested in the broader topic of network security on your machine, our guide on firewalls and network security goes deeper into how Windows Firewall actually works at a conceptual level.

Using This for Privacy: What It Does and Doesn't Protect Against

A firewall rule is a network-level block — it stops a specific program from making network connections. That's powerful, but it's important to be realistic about what it covers and what it doesn't.

What blocking internet access does protect you from: the blocked program sending data to its home servers (telemetry, crash reports, usage analytics), automatic updates you didn't approve, and the app contacting activation or licensing servers.

What it doesn't protect against: data the app has already collected and stored locally, other programs on the same machine that might share data through their own connections, or data that was sent before you created the rule.

A note on VPNs and proxies: If your system is configured to route traffic through a VPN or proxy, a firewall block still applies — the program will be blocked before it even reaches the VPN tunnel. However, if another non-blocked application on your system acts as a relay or proxy for the blocked app, the firewall rule won't catch that indirect traffic. For most standard use cases, this isn't a concern.

For a more complete approach to device privacy — especially on smartphones and laptops — our guide on smartphone privacy protection and our article on protecting your phone from being tracked cover the subject in more depth. And if you're also thinking about what happens when you're on a shared network, take a look at our breakdown of mistakes to avoid on public Wi-Fi.

💡 Pro tip for maximum isolation: If you're truly trying to sandbox an application — meaning you want zero chance of any data leaking out — combine the firewall rule with running the app under a separate Windows user account that has restricted permissions. A firewall rule on a limited account is significantly harder to bypass than one on an administrator account.

Quick Recap: Which Method Should You Use?

Here's the short version if you want to decide fast:

  • Blocking one or two apps occasionally: Use the Windows Defender Firewall GUI (wf.msc → Outbound Rules → New Rule). It's reliable, built-in, and reversible.
  • Quick one-off block via command line: Use the netsh advfirewall command in an admin Command Prompt. Fast and effective.
  • Scripting, automation, or blocking multiple apps: Use PowerShell's New-NetFirewallRule. It's the modern approach, easier to script, and supports batch operations.
  • Frequently toggling blocks on multiple apps: Install TinyWall or Simplewall. Both are free, use Windows Firewall under the hood, and give you a much friendlier interface for managing many rules.
  • Blocking a Microsoft Store (UWP) app: Use the Firewall wizard's program list or a third-party tool like Simplewall that detects UWP apps automatically. Note: disabling "Background App Permissions" in Settings does not block internet access.

The key thing to remember is that whatever rule you create, it applies to the specific .exe file you selected. If the app has multiple executables, you may need to block more than one. And if you ever want to restore internet access, deleting or disabling the rule is all it takes — no traces left behind, no settings to undo.

📬

Liked the hands-on approach?

Join hundreds of subscribers and get practical Windows, networking, and tech guides — real solutions, not theory — delivered to your inbox.

Yes, Subscribe Me! ✉️

🔒 No spam, ever. We respect your inbox.

Frequently Asked Questions

❓ Does blocking a program's internet access affect how it runs otherwise?

No. The program will continue to launch and run normally on your local machine. The firewall rule only prevents it from sending or receiving data over the network. All local features — file access, processing, saving locally — continue to work as usual. The app may display an error message or a "no connection" notice inside its own interface, but it won't crash or stop functioning.

❓ Will the block survive a Windows update or a system restart?

Yes. Firewall rules are stored in Windows and persist through reboots and most updates. The rule stays in place until you manually delete or disable it. The one exception: if the program itself updates and installs a new version to a different path, your existing rule (which points to the old path) will no longer apply and you'd need to create a new one.

❓ Can I block internet for a specific app without affecting other apps?

Absolutely — that's exactly what program-specific firewall rules are designed for. The rule targets only the executable you selected. Every other application on your system continues to have normal internet access. This is one of the main advantages of using the Windows Defender Firewall over simpler network-wide blocks.

❓ Do I need administrator rights to create a firewall rule?

Yes. Creating, modifying, or deleting Windows Firewall rules requires administrator privileges. If you're on a standard (non-admin) account, you'll be prompted to enter an administrator password. On work or school computers managed by IT, your administrator may have locked the firewall settings — in that case, you'd need to ask your IT department.

❓ What's the difference between blocking inbound and outbound traffic?

An outbound block prevents the program from initiating connections to the internet — it can't send data out or make requests to servers. An inbound block prevents other computers from connecting to your program from outside. For most use cases — stopping a program from phoning home, auto-updating, or sending telemetry — an outbound block alone is sufficient. Block both directions if you want complete network isolation.

❓ Can a program bypass a Windows Firewall block?

In theory, a program running with elevated (admin) privileges could attempt to modify firewall rules. In practice, legitimate software doesn't do this, and Windows will prompt you before allowing any changes to firewall rules. Malware is a different story — but if you're dealing with malware, a firewall rule alone isn't the right tool. For trusted software you simply want to restrict, the firewall is entirely reliable.

❓ Does this work the same on Windows 10 and Windows 11?

Yes. The Windows Defender Firewall interface, the underlying netsh commands, and PowerShell's New-NetFirewallRule cmdlet are functionally identical on both Windows 10 and Windows 11. The visual design of the Settings app differs slightly between the two versions, but wf.msc opens the same advanced firewall console on both. Every step in this guide applies to both operating systems.

❓ Should I use PowerShell or netsh to block a program's internet access?

PowerShell's New-NetFirewallRule is the modern recommended approach. It offers cleaner syntax, better error handling, and is significantly easier to script — especially if you need to block multiple programs at once. Use netsh advfirewall if you're on an older system or prefer working in a plain Command Prompt. Both create identical firewall rules under the hood.

📌 Found this guide useful? Share it with someone trying to get control of their Windows network. And explore more practical Windows and networking guides at Valley4Techs — where every guide is built around real use cases.

Add Valley4Techs as a Preferred Source

Follow us on Google News for the latest updates

Add Now
Mostafa Amaan
Mostafa Amaan
Technical educational content creator on my blog and YouTube channel. My goal with this content is to eradicate information technology literacy.
Comments