How to Block an App From the Internet in Windows 10

Windows 10 can stop a specific app from using the internet with a firewall rule, which is useful for keeping an offline app offline, stopping unwanted updates, or saving data. This guide shows how to block an app with Windows Defender Firewall’s rule wizard, with a single Command Prompt or PowerShell command, how to find the right program file, and how to undo the block.

Quick Answer

Press Windows + R, type wf.msc, and press Enter. Click Outbound Rules > New Rule, choose Program, browse to the app’s .exe file, choose Block the connection, keep all profiles checked, name the rule, and click Finish.

Firewall New Outbound Rule Wizard on the Action step with Block the connection selected for a program rule
Choose Block the connection in the New Outbound Rule Wizard.

Step 1: Find the App’s Program File

  • Right-click the app’s shortcut and choose Open file location. If it opens another shortcut, right-click that and choose Open file location again.
  • Or open Task Manager while the app runs, right-click it on the Details tab, and choose Open file location.
  • Most desktop apps are in C:\Program Files or C:\Program Files (x86).

Step 2: Create an Outbound Block Rule

  1. Open Windows Defender Firewall with Advanced Security (run wf.msc, or open Control Panel > Windows Defender Firewall > Advanced settings).
  2. Click Outbound Rules in the left pane, then New Rule on the right.
  3. Choose Program and click Next.
  4. Select This program path, click Browse, and choose the app’s .exe. Click Next.
  5. Choose Block the connection and click Next.
  6. Leave Domain, Private and Public checked, then Next.
  7. Name the rule, for example “Block ExampleApp,” and click Finish.

To also stop incoming connections, create the same rule under Inbound Rules.

Method 2: One Command

Open Command Prompt as administrator:

netsh advfirewall firewall add rule name="Block ExampleApp" dir=out program="C:\Program Files\ExampleApp\app.exe" action=block

Or in PowerShell (as administrator):

New-NetFirewallRule -DisplayName "Block ExampleApp" -Direction Outbound -Program "C:\Program Files\ExampleApp\app.exe" -Action Block

Test the Block

Open the app and try something that needs the internet. If it still connects, it may use a helper or updater (for example updater.exe in the same folder). Block those files too.

Undo or Pause the Block

  • In wf.msc > Outbound Rules, right-click the rule and choose Disable Rule to pause it, or Delete to remove it.
  • Command: netsh advfirewall firewall delete rule name=”Block ExampleApp”.

Limitations

  • Microsoft Store apps run from protected folders; blocking them by path is unreliable. Some third-party firewall tools can block Store apps by package.
  • Browsers and system services share processes; blocking them can break other features.
  • Third-party security suites may use their own firewall instead of Windows Defender Firewall; add the rule there.
  • Work PCs: firewall rules may be managed by your organization.

Other Ways to Limit an App

  • Set your connection as metered to reduce background downloads.
  • Turn off Background apps for Store apps in Settings > Privacy > Background apps.
  • Use Microsoft Family Safety to limit apps for children’s accounts.

If a site stops loading after changing firewall rules, see how to allow a website through the firewall in Windows 11.

To block specific websites instead of an app, see how to block websites on Windows 10.

Frequently Asked Questions

Does blocking an app stop its updates?

Only if you block the updater too. Keep security-sensitive apps updated.

Does this work on Windows 11?

Yes, the same steps work. Windows 10 reached end of support on October 14, 2025. Related: how to allow ports through the firewall.

Summary

  1. Find the app’s .exe file.
  2. wf.msc > Outbound Rules > New Rule > Program > Block the connection.
  3. Or use netsh or New-NetFirewallRule.
  4. Disable or delete the rule to restore access.