I suggest that you use something like Norton Corp. or ZoneLabs integrity for client-side security. Setting up windows firewall is hardly worth the trouble since it wont deliver that much more security. ...but if you insist... You can control windows firewall using the group policy, as is mentioned here: http://www.microsoft.com/technet/security/...p/fwgrppol.mspx All you gatta do is open up AD, then right click the computer name, properties, policy tab, edit the policy and add the windows firewall snapin, then configure it.