# Scope BranchCache client policy before enabling its firewall rules

> Which client population should receive a BranchCache mode and its traffic rules?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-034-scope-branchcache-client-policy-before-enabling-its-firewall-rules/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:16:37+00:00
- Modified: 2026-09-08T18:17:14+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Which client population should receive a BranchCache mode and its traffic rules?

## Potentially affected

Use this review after choosing the intended BranchCache mode.

## DSE recommendation

Create a pilot client inventory and map it to the proposed policy scope.

## Article

## Source facts

Microsoft’s procedure uses Group Policy to configure domain-member clients for distributed or hosted BranchCache and to permit the associated Windows Firewall traffic. Although the walkthrough refers to a domain-wide policy location, Microsoft explicitly permits using an organizational unit or another container appropriate to the deployment. The instructions create a named Group Policy Object for the BranchCache client configuration. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/networking/branchcache/deploy/Use-Group-Policy-to-Configure-Domain-Member-Client-Computers).

## Applicability

Use this review after choosing the intended BranchCache mode. Identify the client computer accounts that should participate and the administrative owner of their policy scope. Treat example domain names as placeholders, not deployment settings.

## DSE recommendation

Create a pilot client inventory and map it to the proposed policy scope. Review the selected mode together with the firewall rules the procedure calls for. Have the directory and network owners confirm the target population before linking the policy. Include a representative computer outside the scope in the acceptance plan, and preserve the prior policy configuration for recovery.

## Verification

Inspect effective policy and firewall state on participating clients after the approved change. Verify the chosen BranchCache behavior through a controlled content-access test. Check that the excluded client did not receive the new configuration. Record scope mistakes or unexpected rules as separate findings before expanding the policy to additional organizational units.

## Official references

[Microsoft Learn: Use Group Policy to Configure Domain Member Client Computers](https://learn.microsoft.com/en-us/windows-server/networking/branchcache/deploy/Use-Group-Policy-to-Configure-Domain-Member-Client-Computers). Source reviewed September 8, 2026.

## Primary reference

- Name: Use Group Policy to Configure Domain Member Client Computers
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/networking/branchcache/deploy/Use-Group-Policy-to-Configure-Domain-Member-Client-Computers
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Scope BranchCache client policy before enabling its firewall rules,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-034-scope-branchcache-client-policy-before-enabling-its-firewall-rules/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
