# Distinguish DSCP marking from outbound throttling in Windows QoS policy

> Should a Windows QoS policy mark traffic, throttle it, or apply both controls?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-131-distinguish-dscp-marking-from-outbound-throttling-in-windows-qos-policy/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:15:00+00:00
- Modified: 2026-09-08T18:23:27+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

Should a Windows QoS policy mark traffic, throttle it, or apply both controls?

## Potentially affected

Administrators creating application-scoped Windows QoS policies through Group Policy.

## DSE recommendation

Have the application and network owners agree on the selected executable or path and the intended traffic behavior.

## Article

## Source facts

Windows QoS policies combine traffic controls with Group Policy management. A DSCP setting specifies the marking used for outbound traffic. A throttle setting limits the rate of outgoing traffic, and Microsoft permits marking and throttling together. The policy can target all applications, a named executable, a path and executable, or HTTP-server applications handling a specified URL. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/networking/technologies/qos/qos-policy-manage).

## Applicability

Identify the application, traffic direction, endpoints, and the actual network treatment expected for its marking. Review whether the requirement is classification, a rate cap, or both before setting policy.

## DSE recommendation

Have the application and network owners agree on the selected executable or path and the intended traffic behavior. Record the DSCP value and any throttle separately, including the chosen rate units. Scope the GPO to a representative pilot group and retain the former policy configuration.

## Verification

Run the intended application and inspect its outbound marking and measured rate. Include another application that should remain outside the policy. Compare observed traffic with the approved settings and investigate unexpected matches or restrictions before assigning the policy to a larger device group.

## Official references

[Microsoft Learn: Manage QoS Policy](https://learn.microsoft.com/en-us/windows-server/networking/technologies/qos/qos-policy-manage). Source reviewed September 8, 2026.

## Primary reference

- Name: Manage QoS Policy
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/networking/technologies/qos/qos-policy-manage
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Distinguish DSCP marking from outbound throttling in Windows QoS policy,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-131-distinguish-dscp-marking-from-outbound-throttling-in-windows-qos-policy/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
