Prohibit installation and configuration of Network Bridge on your DNS domain network
Verified with Windows 11 25H2 — updated on July 30, 2026
Supported on: At least Windows Server 2003 operating systems or Windows XP Professional
Path in the GPO console
Computer Configuration\Administrative Templates\Network\Network Connections Description
Determines whether a user can install and configure the Network Bridge. Important: This settings is location aware. It only applies when a computer is connected to the same DNS domain network it was connected to when the setting was refreshed on that computer. If a computer is connected to a DNS domain network other than the one it was connected to when the setting was refreshed, this setting does not apply. The Network Bridge allows users to create a layer 2 MAC bridge, enabling them to connect two or more network segements together. This connection appears in the Network Connections folder. If you disable this setting or do not configure it, the user will be able to create and modify the configuration of a Network Bridge. Enabling this setting does not remove an existing Network Bridge from the user's computer.
Registry
Software\Policies\Microsoft\Windows\Network Connections Value name: NC_AllowNetBridge_NLA
Enabled: NC_AllowNetBridge_NLA = 0
Disabled: NC_AllowNetBridge_NLA = 1
MDM / Intune (CSP)
./Device/Vendor/MSFT/Policy/Config/Connectivity/ProhibitInstallationAndConfigurationOfNetworkBridge Microsoft Learn documentation Mapping data: Microsoft Learn (CC BY 4.0)
Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Prohibit installation and configuration of Network Bridge on your DNS domain network
; State: Enabled
; Supported on: At least Windows Server 2003 operating systems or Windows XP Professional
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Network Connections]
"NC_AllowNetBridge_NLA"=dword:00000000 More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Prohibit installation and configuration of Network Bridge on your DNS domain network
# State: Enabled
# Supported on: At least Windows Server 2003 operating systems or Windows XP Professional
$path = 'HKLM:\Software\Policies\Microsoft\Windows\Network Connections'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'NC_AllowNetBridge_NLA' -Value 0 -Type DWord Intune XML
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/Connectivity/ProhibitInstallationAndConfigurationOfNetworkBridge
Data type: String
Value:
<enabled/> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Prohibit installation and configuration of Network Bridge on your DNS domain network
# State: Enabled
# Supported on: At least Windows Server 2003 operating systems or Windows XP Professional
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows\Network Connections' -Name 'NC_AllowNetBridge_NLA' -Expected 0 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Prohibit installation and configuration of Network Bridge on your DNS domain network
# State: Enabled
# Supported on: At least Windows Server 2003 operating systems or Windows XP Professional
$path = 'HKLM:\Software\Policies\Microsoft\Windows\Network Connections'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'NC_AllowNetBridge_NLA' -Value 0 -Type DWord SCCM scripts
# Exported from gporais.com
# Policy: Prohibit installation and configuration of Network Bridge on your DNS domain network
# State: Enabled
# Supported on: At least Windows Server 2003 operating systems or Windows XP Professional
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Prohibit installation and configuration of Network Bridge on your DNS domain network
# State: Enabled
# Supported on: At least Windows Server 2003 operating systems or Windows XP Professional
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows\Network Connections' -Name 'NC_AllowNetBridge_NLA' -Expected 0 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Prohibit installation and configuration of Network Bridge on your DNS domain network
# State: Enabled
# Supported on: At least Windows Server 2003 operating systems or Windows XP Professional
$path = 'HKLM:\Software\Policies\Microsoft\Windows\Network Connections'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'NC_AllowNetBridge_NLA' -Value 0 -Type DWord Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.