Windows 11 includes several security features that can help prevent potentially unwanted or unsafe applications from running on your computer. Windows Security works with Microsoft Defender and other built-in protection features to help protect your system from malicious software and suspicious applications.
There may also be situations where you want to block a specific application yourself. For example, you might want to prevent an untrusted program from accessing protected files or stop an application from communicating through the Windows firewall.
Windows provides several ways to accomplish this depending on what you want to block. You can use Windows Security, Microsoft Defender Firewall, Controlled Folder Access, or Windows Defender Firewall with Advanced Security.
Method 1: Block an App Through Windows Firewall
Windows Firewall can prevent an application from making network connections. This is useful when you want to stop a particular program from accessing the internet while still allowing the application to remain installed.
Follow these steps:
- Press Windows + S.
- Search for Windows Defender Firewall.
- Open it.
- Click Advanced settings on the left.
- Select Outbound Rules.
- Click New Rule on the right.
- Select Program.
- Click Next.
- Select This program path.
- Click Browse.
- Locate the application’s executable file.
- Select the program.
- Click Next.
- Select Block the connection.
- Click Next.
- Keep the available network profiles selected unless you have a specific reason to change them.
- Click Next.
- Enter a name for the rule.
- Click Finish.
Windows Firewall will now block outbound network connections for that application according to the rule you created.
This does not uninstall or disable the application itself. It primarily prevents the program from establishing the network connections covered by the firewall rule.
Method 2: Block an App Using Windows Defender Firewall With Advanced Security
You can create more specific firewall rules through Windows Defender Firewall with Advanced Security.
Follow these steps:
- Press Windows + R.
- Type:
wf.msc
- Press Enter.
- Select Outbound Rules.
- Click New Rule.
- Select Program.
- Click Next.
- Specify the application’s executable file.
- Select Block the connection.
- Choose the network profiles where the rule should apply.
- Give the rule a recognizable name.
- Click Finish.
The new rule will appear under Outbound Rules.
You can later right-click the rule to disable, delete, or modify it.
This method is useful when you need more control over application network access than the standard Windows Security interface provides.
Method 3: Block Incoming Connections for an App
If your goal is to prevent other devices or network connections from reaching an application on your computer, you can create an inbound firewall rule.
Follow these steps:
- Open Windows Defender Firewall with Advanced Security.
- Select Inbound Rules.
- Click New Rule.
- Select Program.
- Click Next.
- Choose This program path.
- Browse to the application’s executable file.
- Click Next.
- Select Block the connection.
- Click Next.
- Choose the appropriate network profiles.
- Click Next.
- Enter a name for the rule.
- Click Finish.
The application will now be blocked from receiving the network traffic covered by the rule.
Inbound and outbound rules serve different purposes. If you want to stop an application from connecting to the internet, an outbound rule is usually the more relevant choice.
Method 4: Use Controlled Folder Access to Restrict an App
If you want to prevent an application from modifying important files rather than blocking its network access, Controlled Folder Access can be useful.
Follow these steps:
- Open Windows Security.
- Click Virus & threat protection.
- Select Manage ransomware protection.
- Open Manage Controlled folder access.
- Make sure Controlled folder access is enabled.
- Add important folders under Protected folders.
When an application attempts to modify files inside protected folders, Windows can restrict applications that are not trusted or allowed.
This approach is different from a firewall block. Controlled Folder Access focuses on protecting files, while Windows Firewall controls network traffic.
If a trusted application needs access to a protected folder, you can add it through Allow an app through Controlled folder access.
Method 5: Block Potentially Unwanted Applications
Windows Security also includes protection against potentially unwanted applications, commonly referred to as PUAs.
These applications may not always be classified as traditional malware, but they can exhibit undesirable behavior such as unwanted advertising, bundled software, or other potentially unwanted activity.
To check the relevant protection settings:
- Open Windows Security.
- Select App & browser control.
- Open Reputation-based protection.
- Review the available protection options.
- Enable the appropriate potentially unwanted app protection settings.
Windows can use reputation-based protection to help identify potentially unwanted or suspicious applications.
This is different from manually blocking one specific application. Instead, Windows uses security and reputation information to help prevent potentially unwanted software from being installed or executed.
Method 6: Block an App With a Custom Firewall Rule
If you frequently need to manage application network access, you can create individual firewall rules for specific programs.
For example, you may want to block an application’s executable from making outbound connections.
Start by identifying the program’s executable file.
You can often find the application by:
- Right-clicking its shortcut.
- Selecting Properties.
- Checking the Target field.
- Identifying the executable path.
Then:
- Open Windows Defender Firewall with Advanced Security.
- Select Outbound Rules.
- Click New Rule.
- Select Program.
- Enter the application’s executable path.
- Select Block the connection.
- Select the appropriate profiles.
- Give the rule a descriptive name.
- Click Finish.
Avoid blocking Windows system processes unless you understand their purpose. Some Windows components require network access for updates, security services, licensing, synchronization, or other functions.
Method 7: Check and Manage Existing App Blocking Rules
If an application suddenly stops connecting to the internet, an existing firewall rule could be responsible.
You can check the configured rules.
Follow these steps:
- Press Windows + R.
- Enter:
wf.msc
- Press Enter.
- Check Inbound Rules and Outbound Rules.
- Look for rules associated with the application.
- Right-click a relevant rule.
- Choose Properties.
From the Properties window, you can review the program path, action, profiles, and other rule settings.
If you discover that a rule is causing an unwanted block, you can disable or delete it.
This is useful when troubleshooting an application that previously worked correctly but can no longer access a network resource.
Conclusion
Windows 11 provides several ways to block applications depending on what you want to restrict. If you want to prevent a program from accessing the internet, Windows Defender Firewall is generally the most appropriate option.
You can create inbound or outbound firewall rules and specify the application’s executable file. For protecting personal files, Controlled Folder Access provides a different type of restriction by limiting which applications can modify protected folders.
Windows Security’s reputation-based protection can also help identify potentially unwanted applications automatically.
Before blocking an application, determine whether you want to restrict its network access, file access, or installation/execution. Using the appropriate Windows security feature avoids unnecessary restrictions and reduces the chance of interfering with legitimate system functions.
FAQs
1. Can Windows Security block a specific application?
Yes. Depending on what you want to prevent, you can use Windows Defender Firewall to restrict an application’s network access or Controlled Folder Access to restrict its ability to modify protected files.
2. How do I block an application from accessing the internet?
Open Windows Defender Firewall with Advanced Security, select Outbound Rules, create a new Program rule, choose the application’s executable file, and select Block the connection.
3. Does blocking an app with Windows Firewall uninstall it?
No. A firewall rule does not uninstall the application. It controls the network traffic allowed to or from the program.
4. Why did Windows Security block an application?
Windows may block an application because it is considered suspicious, potentially unwanted, or unauthorized to perform a particular action. Check the Windows Security notification and investigate the application before allowing it.
Quick Summary
- Use Windows Defender Firewall to block an application’s network access.
- Create an Outbound Rule when you want to prevent a program from connecting to the internet.
- Use Controlled Folder Access when your goal is to protect files from unauthorized application changes.
- Use Reputation-based protection to help Windows detect potentially unwanted applications.





