{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-034-scope-branchcache-client-policy-before-enabling-its-firewall-rules/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-034-scope-branchcache-client-policy-before-enabling-its-firewall-rules/",
        "slug": "dse-20260908-034-scope-branchcache-client-policy-before-enabling-its-firewall-rules",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-034-scope-branchcache-client-policy-before-enabling-its-firewall-rules/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-034-scope-branchcache-client-policy-before-enabling-its-firewall-rules.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-034-scope-branchcache-client-policy-before-enabling-its-firewall-rules/"
        },
        "title": "Scope BranchCache client policy before enabling its firewall rules",
        "summary": "Which client population should receive a BranchCache mode and its traffic rules?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:16:37+00:00",
        "modified_at": "2026-09-08T18:17:14+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 2,
        "word_count": 226,
        "potentially_affected": "Use this review after choosing the intended BranchCache mode.",
        "dse_recommendation": "Create a pilot client inventory and map it to the proposed policy scope.",
        "primary_source": {
            "name": "Use Group Policy to Configure Domain Member Client Computers",
            "url": "https://learn.microsoft.com/en-us/windows-server/networking/branchcache/deploy/Use-Group-Policy-to-Configure-Domain-Member-Client-Computers",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft&#8217;s procedure uses Group Policy to configure domain-member clients for distributed or hosted BranchCache and to permit the associated Windows Firewall traffic. Although the walkthrough refers to a domain-wide policy location, Microsoft explicitly permits using an organizational unit or another container appropriate to the deployment. The instructions create a named Group Policy Object for the BranchCache client configuration. <a href=\"https://learn.microsoft.com/en-us/windows-server/networking/branchcache/deploy/Use-Group-Policy-to-Configure-Domain-Member-Client-Computers\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft documentation</a>.</p>\n<h2>Applicability</h2>\n<p>Use this review after choosing the intended BranchCache mode. Identify the client computer accounts that should participate and the administrative owner of their policy scope. Treat example domain names as placeholders, not deployment settings.</p>\n<h2>DSE recommendation</h2>\n<p>Create a pilot client inventory and map it to the proposed policy scope. Review the selected mode together with the firewall rules the procedure calls for. Have the directory and network owners confirm the target population before linking the policy. Include a representative computer outside the scope in the acceptance plan, and preserve the prior policy configuration for recovery.</p>\n<h2>Verification</h2>\n<p>Inspect effective policy and firewall state on participating clients after the approved change. Verify the chosen BranchCache behavior through a controlled content-access test. Check that the excluded client did not receive the new configuration. Record scope mistakes or unexpected rules as separate findings before expanding the policy to additional organizational units.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/networking/branchcache/deploy/Use-Group-Policy-to-Configure-Domain-Member-Client-Computers\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Use Group Policy to Configure Domain Member Client Computers</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nMicrosoft’s procedure uses Group Policy to configure domain-member clients for distributed or hosted BranchCache and to permit the associated Windows Firewall traffic. Although the walkthrough refers to a domain-wide policy location, Microsoft explicitly permits using an organizational unit or another container appropriate to the deployment. The instructions create a named Group Policy Object for the BranchCache client configuration. Microsoft documentation.\nApplicability\nUse this review after choosing the intended BranchCache mode. Identify the client computer accounts that should participate and the administrative owner of their policy scope. Treat example domain names as placeholders, not deployment settings.\nDSE recommendation\nCreate a pilot client inventory and map it to the proposed policy scope. Review the selected mode together with the firewall rules the procedure calls for. Have the directory and network owners confirm the target population before linking the policy. Include a representative computer outside the scope in the acceptance plan, and preserve the prior policy configuration for recovery.\nVerification\nInspect effective policy and firewall state on participating clients after the approved change. Verify the chosen BranchCache behavior through a controlled content-access test. Check that the excluded client did not receive the new configuration. Record scope mistakes or unexpected rules as separate findings before expanding the policy to additional organizational units.\nOfficial references\nMicrosoft Learn: Use Group Policy to Configure Domain Member Client Computers. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft’s procedure uses Group Policy to configure domain-member clients for distributed or hosted BranchCache and to permit the associated Windows Firewall traffic. Although the walkthrough refers to a domain-wide policy location, Microsoft explicitly permits using an organizational unit or another container appropriate to the deployment. The instructions create a named Group Policy Object for the BranchCache client configuration. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/networking/branchcache/deploy/Use-Group-Policy-to-Configure-Domain-Member-Client-Computers).\n\n## Applicability\n\nUse this review after choosing the intended BranchCache mode. Identify the client computer accounts that should participate and the administrative owner of their policy scope. Treat example domain names as placeholders, not deployment settings.\n\n## DSE recommendation\n\nCreate a pilot client inventory and map it to the proposed policy scope. Review the selected mode together with the firewall rules the procedure calls for. Have the directory and network owners confirm the target population before linking the policy. Include a representative computer outside the scope in the acceptance plan, and preserve the prior policy configuration for recovery.\n\n## Verification\n\nInspect effective policy and firewall state on participating clients after the approved change. Verify the chosen BranchCache behavior through a controlled content-access test. Check that the excluded client did not receive the new configuration. Record scope mistakes or unexpected rules as separate findings before expanding the policy to additional organizational units.\n\n## Official references\n\n[Microsoft Learn: Use Group Policy to Configure Domain Member Client Computers](https://learn.microsoft.com/en-us/windows-server/networking/branchcache/deploy/Use-Group-Policy-to-Configure-Domain-Member-Client-Computers). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-034-scope-branchcache-client-policy-before-enabling-its-firewall-rules/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-034-scope-branchcache-client-policy-before-enabling-its-firewall-rules/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-034-scope-branchcache-client-policy-before-enabling-its-firewall-rules/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Scope BranchCache client policy before enabling its firewall rules",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-034-scope-branchcache-client-policy-before-enabling-its-firewall-rules/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-034-scope-branchcache-client-policy-before-enabling-its-firewall-rules/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-034-scope-branchcache-client-policy-before-enabling-its-firewall-rules/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-034-scope-branchcache-client-policy-before-enabling-its-firewall-rules/",
                "headline": "Scope BranchCache client policy before enabling its firewall rules",
                "description": "Which client population should receive a BranchCache mode and its traffic rules?",
                "abstract": "Which client population should receive a BranchCache mode and its traffic rules?",
                "articleBody": "Source facts\nMicrosoft’s procedure uses Group Policy to configure domain-member clients for distributed or hosted BranchCache and to permit the associated Windows Firewall traffic. Although the walkthrough refers to a domain-wide policy location, Microsoft explicitly permits using an organizational unit or another container appropriate to the deployment. The instructions create a named Group Policy Object for the BranchCache client configuration. Microsoft documentation.\nApplicability\nUse this review after choosing the intended BranchCache mode. Identify the client computer accounts that should participate and the administrative owner of their policy scope. Treat example domain names as placeholders, not deployment settings.\nDSE recommendation\nCreate a pilot client inventory and map it to the proposed policy scope. Review the selected mode together with the firewall rules the procedure calls for. Have the directory and network owners confirm the target population before linking the policy. Include a representative computer outside the scope in the acceptance plan, and preserve the prior policy configuration for recovery.\nVerification\nInspect effective policy and firewall state on participating clients after the approved change. Verify the chosen BranchCache behavior through a controlled content-access test. Check that the excluded client did not receive the new configuration. Record scope mistakes or unexpected rules as separate findings before expanding the policy to additional organizational units.\nOfficial references\nMicrosoft Learn: Use Group Policy to Configure Domain Member Client Computers. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:16:37+00:00",
                "dateModified": "2026-09-08T18:17:14+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-034-scope-branchcache-client-policy-before-enabling-its-firewall-rules/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-034-scope-branchcache-client-policy-before-enabling-its-firewall-rules/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Scope BranchCache client policy before enabling its firewall rules"
                },
                "articleSection": [
                    "IT",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "IT",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 226,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Use Group Policy to Configure Domain Member Client Computers",
                    "url": "https://learn.microsoft.com/en-us/windows-server/networking/branchcache/deploy/Use-Group-Policy-to-Configure-Domain-Member-Client-Computers"
                }
            }
        ]
    }
}