Block any app's internet access in minutes — no third-party tools required, just Windows Defender Firewall.
If you've ever wanted to stop a program from accessing the internet — whether that's a game phoning home for updates at the worst moment, software you don't fully trust, or an app you want to use offline only — Windows has a built-in way to do exactly that. No paid firewall tool needed.
In this updated 2026 guide, I'll show you how to block a program from accessing the internet on Windows 10 and Windows 11 using Windows Defender Firewall — the tool that's already on your machine. I'll also cover three alternative methods: using the Command Prompt, using PowerShell (the modern approach), and using a lightweight free tool for those who prefer a visual interface.
From my experience helping dozens of people with this, the most common reason they end up here is one of three things: a game that won't stop downloading updates mid-session, software that sends telemetry they didn't agree to, or an app that simply works better when it can't reach its activation server. Whatever your reason, you're in the right place. Let's get into it.
I'm Mostafa Amaan, and on Valley4Techs I write practical tech guides built around real-world use cases — not textbook theory.
Why Would You Want to Block a Program's Internet Access?
Before diving into the steps, it's worth understanding the common scenarios — because the why often determines which method makes the most sense for you.
- Stopping unwanted auto-updates. Some programs update themselves in the background, interrupting your work or consuming bandwidth at inconvenient times. Blocking them gives you full control over when updates happen.
- Preventing telemetry and data collection. Many apps send usage data back to their servers by default. If you'd rather keep that information local, cutting off internet access at the firewall level is more reliable than hunting for opt-out settings buried in menus.
- Testing offline behavior. Developers often need to see how an app behaves without a network connection. Blocking it at the OS level is cleaner than disconnecting the whole machine.
- Security and containment. If you're running software you're not 100% sure about — maybe an old utility you found on a hard drive — preventing it from reaching the internet limits the damage it can do.
- Parental controls and focus. Blocking a game from connecting online forces offline-only mode, which can be exactly what you need during study time.
Method 1: Block a Program Using Windows Defender Firewall (Recommended)
This is the cleanest and most reliable method. It works on Windows 10 and Windows 11, requires no downloads, and gives you a persistent rule that survives reboots. Here's how to do it step by step.
🎬 Prefer watching? Here's a quick video walkthrough:
Full step-by-step video guide — follow along or continue reading below.
Step 1: Open Windows Defender Firewall with Advanced Security
Press Windows + R
to open the Run dialog, type wf.msc,
and press Enter. This opens the advanced firewall console directly — faster than going through the Control
Panel.
Run Dialog
wf.msc
Alternatively, search for "Windows Defender Firewall with Advanced Security" in the Start menu. If Windows asks for administrator permission, click Yes — you'll need admin rights to create firewall rules.
Opening Windows Defender Firewall with Advanced Security via the Run dialog.
Step 2: Navigate to Outbound Rules
In the left panel of the Firewall console, you'll see three options: Inbound Rules, Outbound Rules, and Connection Security Rules. Click Outbound Rules. This is the one that controls traffic leaving your PC — which is what we want to block.
Navigating to Outbound Rules in the Firewall console's left panel.
Step 3: Create a New Outbound Rule
In the right panel (Actions), click "New Rule…". The New Outbound Rule Wizard will open. Follow these selections:
- Rule Type: Select Program and click Next. This tells Windows you want to target a specific executable file.
- Program Path: Select "This program path"
and click Browse. Navigate to the
.exefile of the program you want to block. Common locations areC:\Program Files\orC:\Program Files (x86)\. Click Next when done. - Action: Select "Block the connection" and click Next.
- Profile: Leave all three checkboxes selected (Domain, Private, Public). This ensures the block applies regardless of which network you're connected to. Click Next.
- Name: Give the rule a descriptive name, like
Block [AppName] Internet. This makes it easy to find and remove later. Click Finish.
The New Outbound Rule Wizard — select Program, browse to the .exe, and block the connection.
The rule is now active. Your chosen program will no longer be able to reach the internet — immediately, without requiring a reboot.
Step 4: Test and Verify the Block
Open the program and try to do something that requires internet access — check for updates, log in online, or load a web-connected feature. It should fail. If the app has a "check for updates" option, that's the quickest test. A network timeout or "no connection" message from the app confirms the rule is working.
For a more technical verification, you can use any of these methods:
- Resource Monitor: Press
Windows + R, typeresmon, and go to the Network tab. If the blocked program appears with zero activity or "filtered" status, your rule is working. - Command line check: Run
netstat -bin an admin Command Prompt to see all active connections by process name. Your blocked app should not appear. - Firewall logs: Open
wf.msc→ right-click "Windows Defender Firewall with Advanced Security" → Properties → under the relevant profile tab, enable Logging. Blocked connections will be recorded in%systemroot%\system32\LogFiles\Firewall\pfirewall.log.
Method 2: Block Internet Access Using Command Prompt
If you prefer working from the command line, or you need to script this for multiple machines, you can create the same firewall rule to block internet access in a single command. This is the approach I use when setting up lab machines — it's faster once you know the path.
Open Command Prompt as Administrator (right-click the Start button → "Windows Terminal (Admin)" or search for cmd and choose "Run as administrator"), then run:
Command Prompt (Admin)
netsh advfirewall firewall add rule name="Block AppName Internet" dir=out action=block program="C:\Path\To\Your\program.exe" enable=yes
Replace "Block AppName
Internet" with a meaningful rule name, and update the path to match the actual
.exe
location. If the path contains spaces, make sure the quotes around it are there — otherwise the command
will fail silently.
To block both outbound and inbound traffic (for complete network isolation), run the command twice
—
once with dir=out
and once with dir=in.
Block both directions
netsh advfirewall firewall add rule name="Block AppName Outbound" dir=out action=block program="C:\Path\To\program.exe" enable=yes netsh advfirewall firewall add rule name="Block AppName Inbound" dir=in action=block program="C:\Path\To\program.exe" enable=yes
To verify the rule was created, you can list all firewall rules filtered by name:
Verify the rule
netsh advfirewall firewall show rule name="Block AppName Internet"
Method 3: Block a Program Using PowerShell (Modern Approach)
PowerShell is the modern replacement for netsh
when it comes to managing
Windows Defender Firewall rules. The syntax is cleaner, more readable, and significantly easier to
script — especially
if you need to block internet access for multiple programs at once.
Open PowerShell as Administrator (right-click the Start button → "Windows Terminal (Admin)"), then run:
PowerShell (Admin) — Block outbound
New-NetFirewallRule -DisplayName "Block AppName Internet" `
-Program "C:\Path\To\Your\program.exe" `
-Action Block `
-Direction Outbound `
-Profile Domain, Private, Public
Managing the rule afterward is just as straightforward:
PowerShell — Verify, disable, re-enable, or remove
# Check if the rule exists Get-NetFirewallRule -DisplayName "Block AppName Internet" # Temporarily disable the rule (restore internet access) Disable-NetFirewallRule -DisplayName "Block AppName Internet" # Re-enable the rule Enable-NetFirewallRule -DisplayName "Block AppName Internet" # Remove the rule entirely Remove-NetFirewallRule -DisplayName "Block AppName Internet"
Batch Blocking: Block Multiple Programs at Once
Need to block internet connection for several apps simultaneously — like all Adobe telemetry executables, or every game launcher on a shared PC? Here's a PowerShell script that handles it:
PowerShell — Block multiple apps at once
$appsToBlock = @(
"C:\Program Files\App1\app1.exe",
"C:\Program Files\App2\app2.exe",
"C:\Program Files (x86)\App3\app3.exe"
)
foreach ($app in $appsToBlock) {
$name = "Block " + (Split-Path $app -Leaf)
New-NetFirewallRule -DisplayName $name `
-Program $app `
-Action Block `
-Direction Outbound `
-Profile Domain, Private, Public
Write-Host "Blocked: $app" -ForegroundColor Green
}
*-NetFirewallRule
cmdlets as the modern replacement for netsh advfirewall.
PowerShell offers better error handling, is easier to integrate into automation scripts, and returns structured
objects you can pipe into other commands. Use netsh
if you're on an older system or working in a plain Command Prompt; use PowerShell for everything else.
How to Remove the Block (Restore Internet Access)
Blocking is reversible. Here's how to undo it using both methods.
Removing via the Firewall GUI
- Open
wf.mscagain. - Click Outbound Rules in the left panel.
- Find the rule you created by name (this is why naming it well matters).
- Right-click it and select Delete. Confirm, and the block is gone instantly.
Alternatively, you can right-click the rule and choose Disable Rule instead of deleting it. This keeps the rule saved for later reuse without actually enforcing it — useful if you plan to toggle the block on and off regularly.
Removing via Command Prompt
Command Prompt (Admin)
netsh advfirewall firewall delete rule name="Block AppName Internet"
Use the exact same name you used when creating the rule. If you're not sure of the name, you can list all custom rules with:
List all outbound block rules
netsh advfirewall firewall show rule dir=out action=block
Common Problems and How to Fix Them
The firewall approach is straightforward, but I've seen a few specific issues come up repeatedly. Here's what to do when the block doesn't seem to work as expected.
Problem: The Program Is Still Connecting
The most common reason for this: the program has multiple executables. Some software
separates its updater or launcher into a different
.exe
file from the main app. For example, a game might have
game.exe
and updater.exe
— you blocked one but not the other.
To find all executables in a folder quickly, open Command Prompt and run:
Command Prompt
dir "C:\Program Files\AppName\" /s /b *.exe
This lists every .exe
in the app's folder and subfolders. Block each one that might be responsible for the connection.
Problem: The Rule Was Created But the App Still Has Internet
Double-check that the path in your firewall rule exactly matches the actual executable location. A common
mistake is blocking
C:\Program
Files\App\app.exe
when the app actually installed to
C:\Program Files
(x86)\App\app.exe.
Open the rule in the firewall GUI and verify the path is correct.
Problem: Blocking a Microsoft Store (UWP) App
Microsoft Store apps (also called UWP apps) don't work quite the same way — they don't have a simple
.exe
path you can just browse to. Their executables are stored in the hidden
C:\Program Files\WindowsApps
folder. To block internet access for a UWP app, you have two options:
- Firewall method (recommended): In the New Outbound Rule Wizard, when you select "Program" as the rule type, look for the Store app in the system's program list rather than browsing manually. You may need to enable "Hidden items" in File Explorer to locate the executable path.
- Third-party tool: Use a tool like Simplewall or TinyWall, which can detect and list UWP apps automatically for easy blocking.
Windows Firewall vs. Third-Party Tools: Which Should You Use?
Once in a while someone asks me whether they should install a dedicated firewall manager instead of using the built-in Windows Firewall. My honest take: for most people, the built-in tool is all you need. Here's a quick comparison to help you decide.
| Feature | Windows Firewall | Third-Party Tools (e.g. TinyWall, Simplewall, GlassWire) |
|---|---|---|
| Cost | Free (built-in) | Free to paid |
| Ease of use | Moderate (wizard-based) | Easier (visual interface) |
| Reliability | Very high (OS-level) | Good (uses Windows Firewall under the hood) |
| Real-time monitoring | Limited (via logs when enabled) | Yes (live traffic dashboards) |
| Works on all Windows apps | Yes | Yes |
| System overhead | None (built-in service) | Minimal to moderate |
TinyWall (v3.4.1, still actively maintained in 2025) is worth a special mention: it's a free, lightweight frontend for Windows Firewall that makes managing rules much easier without adding any extra firewall layer of its own. Simplewall is another excellent open-source option — it's the closest functional competitor to TinyWall and very popular in the privacy community for its simple block/allow rule management. If you find yourself needing software to block internet access for many apps regularly, either of these tools is a smart addition.
For most people reading this guide — blocking one or two specific programs — the built-in firewall is the right tool. If you're also interested in the broader topic of network security on your machine, our guide on firewalls and network security goes deeper into how Windows Firewall actually works at a conceptual level.
Using This for Privacy: What It Does and Doesn't Protect Against
A firewall rule is a network-level block — it stops a specific program from making network connections. That's powerful, but it's important to be realistic about what it covers and what it doesn't.
What blocking internet access does protect you from: the blocked program sending data to its home servers (telemetry, crash reports, usage analytics), automatic updates you didn't approve, and the app contacting activation or licensing servers.
What it doesn't protect against: data the app has already collected and stored locally, other programs on the same machine that might share data through their own connections, or data that was sent before you created the rule.
A note on VPNs and proxies: If your system is configured to route traffic through a VPN or proxy, a firewall block still applies — the program will be blocked before it even reaches the VPN tunnel. However, if another non-blocked application on your system acts as a relay or proxy for the blocked app, the firewall rule won't catch that indirect traffic. For most standard use cases, this isn't a concern.
For a more complete approach to device privacy — especially on smartphones and laptops — our guide on smartphone privacy protection and our article on protecting your phone from being tracked cover the subject in more depth. And if you're also thinking about what happens when you're on a shared network, take a look at our breakdown of mistakes to avoid on public Wi-Fi.
Quick Recap: Which Method Should You Use?
Here's the short version if you want to decide fast:
- Blocking one or two apps occasionally: Use the Windows Defender Firewall GUI
(
wf.msc→ Outbound Rules → New Rule). It's reliable, built-in, and reversible. - Quick one-off block via command line: Use the
netsh advfirewallcommand in an admin Command Prompt. Fast and effective. - Scripting, automation, or blocking multiple apps: Use PowerShell's
New-NetFirewallRule. It's the modern approach, easier to script, and supports batch operations. - Frequently toggling blocks on multiple apps: Install TinyWall or Simplewall. Both are free, use Windows Firewall under the hood, and give you a much friendlier interface for managing many rules.
- Blocking a Microsoft Store (UWP) app: Use the Firewall wizard's program list or a third-party tool like Simplewall that detects UWP apps automatically. Note: disabling "Background App Permissions" in Settings does not block internet access.
The key thing to remember is that whatever rule you create, it applies to the specific
.exe
file you selected. If the app has multiple executables, you may need to block more than one. And if you
ever want to restore internet access, deleting or disabling the rule is all it takes — no traces left
behind, no settings to undo.
Liked the hands-on approach?
Join hundreds of subscribers and get practical Windows, networking, and tech guides — real solutions, not theory — delivered to your inbox.
Yes, Subscribe Me! ✉️🔒 No spam, ever. We respect your inbox.
We'd love to hear your thoughts! Leave a comment below
and share your experience or questions.