What you need to know
Should a Windows QoS policy mark traffic, throttle it, or apply both controls?
Potentially affected
Administrators creating application-scoped Windows QoS policies through Group Policy.
DSE recommendation
Have the application and network owners agree on the selected executable or path and the intended traffic behavior.
Source facts
Windows QoS policies combine traffic controls with Group Policy management. A DSCP setting specifies the marking used for outbound traffic. A throttle setting limits the rate of outgoing traffic, and Microsoft permits marking and throttling together. The policy can target all applications, a named executable, a path and executable, or HTTP-server applications handling a specified URL. Microsoft documentation.
Applicability
Identify the application, traffic direction, endpoints, and the actual network treatment expected for its marking. Review whether the requirement is classification, a rate cap, or both before setting policy.
DSE recommendation
Have the application and network owners agree on the selected executable or path and the intended traffic behavior. Record the DSCP value and any throttle separately, including the chosen rate units. Scope the GPO to a representative pilot group and retain the former policy configuration.
Verification
Run the intended application and inspect its outbound marking and measured rate. Include another application that should remain outside the policy. Compare observed traffic with the approved settings and investigate unexpected matches or restrictions before assigning the policy to a larger device group.
Official references
Microsoft Learn: Manage QoS Policy. Source reviewed September 8, 2026.
Review the official source
Manage QoS Policy · Verified September 8, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE