I opened a ticket to Azure support (REG:118083118906763) and after 2 months of escalations they stated this does not work on Intune:
“Basically, the capability of enabling a rule in Firewall that will enable a port such as TCP 3389 using custom policies is not currently possible using a CSP. There, just, aren’t any CSPs currently available to allow ports in Windows Firewall.”
⚠ Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.
Can anyone from the product group confirm this doesn't work?
At first glance, it appears as if the statement from Azure support makes the Firewall CSP page less useful than what is documented on the page itself.
I don't know who specifically to ask for an authoritative answer on this topic , but I will chance a ping to @egallagh to ask if he knows something about this.
@officedocsbot assign @e0i
@egallagh Would you be able to clarify regarding this topic if the time permits? Thank you.
This question can be best answered via Windows 10 Support channels.
Please consider opening a product support ticket by the following link below for your problem so that it gets resolved quickly.
The issues section of this repository is intended for product documentation issues only.
Thank you.
Please read the case.
I already got a response from Microsoft support. And it states that your documentation is Wrong.
@ClaudioRifo An independent contributor is going to follow-up with a PR based on your suggestion. Thank you for the clarification.
@ClaudioRifo - Thank you for sharing the details. Can you please attach the support case response so that I can make adjustments in the document.
Thanks
Imran.
For the second time, please read the case. On the first post is the support ticket number and also quoted the support response.
Also. With the release of the new option to create firewall rules on Endpoint Security, you should just delete this references and point to that functionality.
From: ImranHabib notifications@github.com
Sent: Wednesday, June 17, 2020 3:39 AM
To: MicrosoftDocs/windows-itpro-docs windows-itpro-docs@noreply.github.com
Cc: Claudio P. Rifo Wahl claudio.rifo@marcaria.com; Mention mention@noreply.github.com
Subject: Re: [MicrosoftDocs/windows-itpro-docs] MS support confirmed this does not work on Intune. (#2295)
@ClaudioRifohttps://github.com/ClaudioRifo - Thank you for sharing the details. Can you please attach the support case response so that I can make adjustments in the document.
Thanks
Imran.
—
You are receiving this because you were mentioned.
Reply to this email directly, view it on GitHubhttps://github.com/MicrosoftDocs/windows-itpro-docs/issues/2295#issuecomment-645208093, or unsubscribehttps://github.com/notifications/unsubscribe-auth/AFUQY42MTQJSDJIHUVTY2BDRXBXIFANCNFSM4GI67DVQ.
@ClaudioRifo The proposed changes based on your feedback has been rejected by the document author via the following rationale,
Per the product team, the statement in the comment is not true. They could test a syncml to add a rule that would allow TCP port 3389 (both local and remote port worked).
Additionally, Intune has support to be able to configure firewall rules via an endpoint protection device configuration profile as well as through a firewall endpoint security profile.
I am closing this PR as the note added here is not applicable/required. Thanks!
(via https://github.com/MicrosoftDocs/windows-itpro-docs/pull/6993#issuecomment-674971500)
Hope you find this explanation useful.
Thank you.
Hi there.
Just for the record, the statement was correct when the case was opened (2018).
From the moment I opened the case till now this functionality has been correctly implemented on Endpoint protection as stated (and I do believe this a 2020 feature).
From: Onur notifications@github.com
Sent: Monday, August 17, 2020 3:16 PM
To: MicrosoftDocs/windows-itpro-docs windows-itpro-docs@noreply.github.com
Cc: Claudio P. Rifo Wahl claudio.rifo@marcaria.com; Mention mention@noreply.github.com
Subject: Re: [MicrosoftDocs/windows-itpro-docs] MS support confirmed this does not work on Intune. (#2295)
@ClaudioRifohttps://github.com/ClaudioRifo The proposed changes based on your feedback has been rejected by the document author via the following rationale,
Per the product team, the statement in the comment is not true. They could test a syncml to add a rule that would allow TCP port 3389 (both local and remote port worked).
Additionally, Intune has support to be able to configure firewall rules via an endpoint protection device configuration profile as well as through a firewall endpoint security profile.
I am closing this PR as the note added here is not applicable/required. Thanks!
(via #6993 (comment)https://github.com/MicrosoftDocs/windows-itpro-docs/pull/6993#issuecomment-674971500)
Hope you find this explanation useful.
Thank you.
—
You are receiving this because you were mentioned.
Reply to this email directly, view it on GitHubhttps://github.com/MicrosoftDocs/windows-itpro-docs/issues/2295#issuecomment-675063113, or unsubscribehttps://github.com/notifications/unsubscribe-auth/AFUQY46SH5X73KWOZELZJ6TSBF6XXANCNFSM4GI67DVQ.
Most helpful comment
Hi there.
Just for the record, the statement was correct when the case was opened (2018).
From the moment I opened the case till now this functionality has been correctly implemented on Endpoint protection as stated (and I do believe this a 2020 feature).
From: Onur notifications@github.com
Sent: Monday, August 17, 2020 3:16 PM
To: MicrosoftDocs/windows-itpro-docs windows-itpro-docs@noreply.github.com
Cc: Claudio P. Rifo Wahl claudio.rifo@marcaria.com; Mention mention@noreply.github.com
Subject: Re: [MicrosoftDocs/windows-itpro-docs] MS support confirmed this does not work on Intune. (#2295)
@ClaudioRifohttps://github.com/ClaudioRifo The proposed changes based on your feedback has been rejected by the document author via the following rationale,
Per the product team, the statement in the comment is not true. They could test a syncml to add a rule that would allow TCP port 3389 (both local and remote port worked).
Additionally, Intune has support to be able to configure firewall rules via an endpoint protection device configuration profile as well as through a firewall endpoint security profile.
I am closing this PR as the note added here is not applicable/required. Thanks!
(via #6993 (comment)https://github.com/MicrosoftDocs/windows-itpro-docs/pull/6993#issuecomment-674971500)
Hope you find this explanation useful.
Thank you.
—
You are receiving this because you were mentioned.
Reply to this email directly, view it on GitHubhttps://github.com/MicrosoftDocs/windows-itpro-docs/issues/2295#issuecomment-675063113, or unsubscribehttps://github.com/notifications/unsubscribe-auth/AFUQY46SH5X73KWOZELZJ6TSBF6XXANCNFSM4GI67DVQ.