Skip to content
How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr

How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr

Written By Anoop C Nair
Last Updated July 27, 2026
Posted In SCCM
SHARE

How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr. Creating Windows Firewall Rules for SCCM or ConfigMgr clients is pretty straightforward.

I was trying to deploy a client in my lab, and I don’t want to disable the Windows Firewall to get the SCCM 2012 client to work.

Usually, I used to disable Windows Firewall in the LAB environment to have an easy life ;). In this case, the SCCM 2012 client push was not working because the Firewall was getting in between.

The TechNet documentation for creating Windows Firewall Rule Settings is excellent. For more details, see the TechNet documentation. However, this kind of post would be beneficial for newbies.

Patch My PC
Index
Create Windows Firewall Inbound Rules
How to Create Windows Firewall Inbound Rules for SCCM
How Do We Create the WMI Inbound Windows Firewall Rule for SCCM ConfigMgr 2012 Client Push?
How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr – Table 1

Create Windows Firewall Inbound Rules

This will help them create and master Inbound rules in Windows Firewall settings. Another post discusses “How to Create Windows Firewall Outbound Rules Using PowerShell for SCCM ConfigMgr 2012 Client.”

How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr - Fig.1
How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr – Fig.1

This post teaches us to create Inbound Windows Firewall Rules for SCCM (ConfigMgr) clients. SCCM client uses components like WMI, RPC End Point Mapper, Remote Control, ICMP for wakeup lan & File, and Printer Sharing to communicate with SCCM site servers.

These connections/communications are blocked by Windows Firewall (by default), so we need to specifically open the required ports and applications, whichever is needed.

This step-by-step guide (not very specific to SCCM/ConfigMgr) will help anyone create an Inbound Windows Firewall rule(s). We can make Windows firewall inbound Rules with different rule types, such as Program, Port, Predefined, and Custom. In the next post, I’ll cover the guide to creating Outbound Rules in Windows Firewall.

How to Create Windows Firewall Inbound Rules for SCCM

In this post, I’m going to cover the following step-by-step guides. I’ve not covered all the Firewall rules required for all the features of SCCM 2012. However, I tried to cover one example each with all scenarios.

  1. How do you create a “WMI” Inbound Windows Firewall Rule for the SCCM ConfigMgr 2012 client push?
  2. How do you create a “File and Printer Sharing” Inbound Firewall Rule for the SCCM ConfigMgr client?
  3. How do you configure the Windows firewall to “Allow ICMP or Ping Response”?
  4. How do we create an inbound “custom port TCP or UDP in Windows Firewall?

How Do We Create the WMI Inbound Windows Firewall Rule for SCCM ConfigMgr 2012 Client Push?

Type WF from the command prompt to launch Windows Firewall with Advanced Security.

How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr - Fig.2
How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr – Fig.2

2. On the Windows Firewall with Advanced Security page, Right-click on Inbound Rules and click on the new rule.

How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr - Fig.3
How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr – Fig.3

3. On the Rule Type page, Select the Predefined Rule Creation option and from the drop-down list, select the Windows Management Instrumentation (WMI) rule and click NEXT.

How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr - Fig.4
How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr – Fig.4

4. On the Predefined Rules page, we need to select all the rules of WMI Inbound connections, which we need to enable for Client push and other SCCM ConfigMgr-related activities, and then Click NEXT.

We’re going to create the rules Windows Management Instrumentation (ASync-In), Windows Management Instrumentation (WMI-In), Windows Management Instrumentation (DCOM-In), Windows Management Instrumentation (ASync-In), Windows Management Instrumentation (WMI-In), and Windows Management Instrumentation (DCOM-In).

How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr - Fig.5
How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr – Fig.5

5. On the Action page, Select Allow the Connection option in the WMI inbound rule and click FINISH.

How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr - Fig.6
How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr – Fig.6

On the Windows Firewall with Advanced Security page, Right-click on Inbound Rules and click on the new rule.

How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr - Fig.7
How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr – Fig.7

2. On the Rule Type page, Select the Predefined Rule Creation option and from the drop-down list, select the File and Printer Sharing rule and click NEXT

How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr - Fig.8
How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr – Fig.8

3. On the Predefined Rules page, we need to select all the File and Printer Sharing Inbound connections rules to enable the Client to push and other SCCM ConfigMgr-related activities, then Click NEXT.

How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr - Fig.9
How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr – Fig.9

4. select Allow the Connection option on the Action page on the inbound rule page and click FINISH.

How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr - Fig.10
How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr – Fig.10
  1. On the Windows Firewall and Advanced Security page, Right-click on Inbound Rules and click on the new rule.
Note : When you're running SCCM /ConfigMgr 2012 R2 and above then you don't need to create this inbound Windows Firewall rule for Wakeup Proxy at SCCM Client side.
How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr - Fig.11
How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr – Fig.11

2. Select Rule Type as Custom on the Rule Type page, then click Next.

How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr - Fig.12
How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr – Fig.12

3. On the PROGRAM page, Select All Programs and click NEXT.

How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr - Fig.13
How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr – Fig.13

4. On the Protocols and Ports page, click the drop-down for Protocol type, select ICMPv4, and click the Customize button.

How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr - Fig.14
How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr – Fig.14

5. In the Customize ICMP Settings dialog box, click on Specific ICMP types, select Echo-Request, and click OK. Then, on the Inbound Wizard page, click NEXT.

How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr - Fig.15
How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr – Fig.15

6. On the SCOPE page, we need to select Any IP Address under the session “which local IP addresses this rule applies to”  and Any IP Address under the session “which remote IP addresses does this rule apply to”.

How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr - Fig.16
How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr – Fig.16

7. Select Allow the connection and click on the action page.

How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr - Fig.17
How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr – Fig.17

8. On the Profile page, select all the profiles (Domain, Private and Public); however, to wake up a proxy, you would require only Domain and hit NEXT.

How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr - Fig.18
How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr – Fig.18

9. Select a suitable name for the Inbound rule on the Name page and then click FINISH.

How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr - Fig.19
How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr – Fig.19

From the ConfigMgr SCCM client perspective, we need to create Inbound rules for the following ports: TCP Port 2701 for Remote Control and TCP port 135 for Remote Assistance and Remote Desktop.

  1. On the Windows Firewall and Advanced Security page, Right-click on Inbound Rules and click on the new rule.
How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr - Fig.20
How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr – Fig.20

2. Select Rule Type as Port on the Rule Type page, then click Next.

How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr - Fig.21
How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr – Fig.21

3. On the Protocol and Ports page, we must specify the protocols and ports to which this rule applies. Select TCP or UDP protocol depending upon your requirements. After that, type in the local ports, then click next.

How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr - Fig.22
How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr – Fig.22

4. Select Allow the connection on the Action page and click NEXT.

How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr - Fig.23
How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr – Fig.23

5. select all the required profiles on the profile page according to your requirements. I selected all three available profiles and then clicked NEXT.

How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr - Fig.24
How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr – Fig.24

6. Select a suitable name for the Inbound rule on the Name page and click FINISH.

How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr - Fig.25
How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr – Fig.25

Following are the Names of the Inbound rules I’ve created for SCCM ConfigMgr.

NameGroupProfileEnabledAction
ICMP Wake-up proxy communication AllYesAllow
RPC End Point Mapper AllYesAllow
Configuration Manager remote control AllYesAllow
Windows Management Instrumentation (ASync-In)Windows Management Instrumentation (WMI)Private, PublicYesAllow
Windows Management Instrumentation (WMI-In)Windows Management Instrumentation (WMI)Private, PublicYesAllow
Windows Management Instrumentation (DCOM-In)Windows Management Instrumentation (WMI)Private, PublicYesAllow
Windows Management Instrumentation (ASync-In)Windows Management Instrumentation (WMI)DomainYesAllow
Windows Management Instrumentation (WMI-In)Windows Management Instrumentation (WMI)DomainYesAllow
Windows Management Instrumentation (DCOM-In)Windows Management Instrumentation (WMI)DomainYesAllow
File and Printer Sharing (LLMNR-UDP-In)File and Printer SharingAllYesAllow
File and Printer Sharing (Echo Request – ICMPv6-In)File and Printer SharingPrivate, PublicYesAllow
File and Printer Sharing (Echo Request – ICMPv4-In)File and Printer SharingPrivate, PublicYesAllow
File and Printer Sharing (Spooler Service – RPC-EPMAP)File and Printer SharingPrivate, PublicYesAllow
File and Printer Sharing (Spooler Service – RPC)File and Printer SharingPrivate, PublicYesAllow
File and Printer Sharing (NB-Datagram-In)File and Printer SharingPrivate, PublicYesAllow
File and Printer Sharing (NB-Name-In)File and Printer SharingPrivate, PublicYesAllow
File and Printer Sharing (SMB-In)File and Printer SharingPrivate, PublicYesAllow
File and Printer Sharing (NB-Session-In)File and Printer SharingPrivate, PublicYesAllow
File and Printer Sharing (Echo Request – ICMPv6-In)File and Printer SharingDomainYesAllow
File and Printer Sharing (Echo Request – ICMPv4-In)File and Printer SharingDomainYesAllow
File and Printer Sharing (Spooler Service – RPC-EPMAP)File and Printer SharingDomainYesAllow
File and Printer Sharing (Spooler Service – RPC)File and Printer SharingDomainYesAllow
File and Printer Sharing (NB-Datagram-In)File and Printer SharingDomainYesAllow
File and Printer Sharing (NB-Name-In)File and Printer SharingDomainYesAllow
File and Printer Sharing (SMB-In)File and Printer SharingDomainYesAllow
File and Printer Sharing (NB-Session-In)File and Printer SharingDomainYesAllow
How to Create Windows Firewall Inbound Rules for SCCM ConfigMgr Client Configuration Manager ConfigMgr – Table 2

Resources

SCCM Related Posts Real World Experiences Of SCCM Admins

We are on WhatsApp now. To get the latest step-by-step guides, news, and updates, Join our Channel. Click here. HTMD WhatsApp.

Author

Anoop C Nair is Microsoft MVP from 2015 onwards for consecutive 10 years! He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is a Blogger, Speaker, and Local User Group Community leader. His main focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security, Career etc…

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion · 6 comments

  1. Hi,

    So you are opening WMI, File print and sharing, RDP,…on the Public profile of the firewall, that means your clients are vulnerable when outside the corporate network.
    Isn’t it a security risk to allow all these for laptops of roaming users?

  2. This article should be called “How to ensure that you get hacked”
    No one should be exposing all these ports to the public profile, you’re just asking to get compromised.

  3. Nowhere does Microsoft say to open up the Public profile for these rules. Can you point to where that is specified in the documentation?

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Windows 11 KB5101650 KB5099414 July 2026 Patch and 3 Zero Day Vulnerabilities and 570 Flaws

Key Takeaways Windows 11 KB5101650 KB5099414 July 2026 Patch and 3 Zero Day Vulnerabilities and 570 Flaws! In the July 2026 Patch, Microsoft introduced new features designed to improve the overall Windows experience. The update adds enhancements to Windows Update for more flexible update management and introduces Point-in-Time Restore, providing an additional recovery option for […]

AC Anoop C Nair 9 min read
Intune

2026 June KB5094126 KB5093998 Windows 11 Patch | 3 Zero Day Vulnerabilities and 200 Flaws

Key Takeaways 2026 June KB5094126 KB5093998 Windows 11 Patch | 3 Zero Day Vulnerabilities and 200 Flaws! The June 2026 Windows 11 Patch Tuesday update brings several improvements to File Explorer. It adds support for additional archive formats, including UU, CPIO, XAR, and NuGet Packages (NUPKG). The update also preserves View and Sort preferences in […]

AC Anoop C Nair 10 min read
Intune

2026 May KB5089549 KB5087420 Windows 11 Patch | 0 Zero Day Vulnerabilities and 120 Flaws

Key Takeaways The Windows 11 May 2026 Patch KB5089549 KB5087420 Update brings important security fixes, performance improvements, and reliability enhancements across the operating system. The update introduces new features such as Xbox Mode for gaming, File Explorer improvements, enhanced input and sharing experiences, better taskbar and Windows Hello reliability, and additional enterprise management capabilities for […]

AC Anoop C Nair 8 min read
SCCM

ConfigMgr 2603 Introduces New Early Update Enrollment Process

Key Takeaways In this post we are discussing the ConfigMgr 2603 Introduces New Early Update Enrollment Process. Microsoft has officially released Configuration Manager version 2603 to the Early Update Ring, giving organizations an opportunity to test upcoming improvements before the global production rollout. The release is targeted at enterprises running ConfigMgr version 2409 or later […]

AC Anoop C Nair 3 min read