Orchestrate Windows Defender Firewall for AI Agent Policy
Cup’n’String configures native Windows Defender rules and uses the Windows Filtering Platform (WFP) API to inject real-time security rules into workstation network interfaces — owning only its tagged rules and scanning for drift.
Support levelKernel-Level Enforcement
CategoryFirewalls
Governance capabilities
Outbound policyBlock
What Cup’n’String controls
Orchestrate Windows Defender rules via the WFP API
Translate policy intent into host firewall rules
Block unauthorized outbound AI tool calls (kernel-level enforcement)
Generate change sets before applying rules
Continuously scan for configuration drift
Record tamper-evident audit evidence
Common risks
Windows workstations need consistent, auditable AI egress policy that survives change.
Outbound AI calls that bypass centralized controls
Firewall rule drift over time
No clean change sets or rollback
Limited audit of rule changes
Inconsistent enforcement across machines
How it works
- Step 1Install / enroll the Cup’n’String Desktop Agent
- Step 2Define tenant network policy intent
- Step 3Generate a clean WFP change set
- Step 4Apply Guard-owned Defender / WFP rules (kernel-level enforcement)
- Step 5Continuously verify for drift
- Step 6Capture audit evidence and support rollback
Recommended policies
Restrict outbound AI provider access
Block risky ports unless explicitly allowed
Deny unknown destinations by default
Apply role-based egress policy
Log and audit all rule changes
Frequently asked questions
Does Cup’n’String use native Windows firewall?
Yes. It configures Windows Defender rules and uses the Windows Filtering Platform (WFP) API for kernel-level enforcement.
Will it overwrite my existing rules?
No. Guard owns only its tagged rules and performs verified, idempotent changes with rollback.
Is enforcement unbypassable?
No tool should claim that on a general-purpose workstation. Enforcement is strongest when combined with MDM (e.g. Intune) and network controls.
Are changes audited?
Yes, with a tamper-evident audit trail.
Can this work self-hosted?
Yes.
Govern Windows Filtering Platform (WFP) with Cup’n’String
Discover the environment, apply policy, shield credentials, and capture audit evidence.