Summary
The firewall check evaluates all three Windows profiles equally and issues a warning as soon as one is disabled. On domain-joined computers, however, the “Private” and “Public” profiles are regularly disabled without creating a security vulnerability—the domain profile is the only one that applies anyway. The result is warnings that no one can turn off without completely disabling the check. I’d like to be able to choose which profiles are evaluated.
What the check currently offers
Two toggles, both applicable to all profiles:
If a profile is causing issues, my only option is to disable warnOnDisabled for the entire device. This means I also lose the information about the profile that I’m actually interested in.
How this affects my setup
From my test instance, as of today: