NetBird Client Policies Group Policy template for NetBird client MDM-managed settings. Values are written under HKLM\Software\Policies\NetBird and consumed by the netbird daemon at startup and every 1-minute reload tick. NetBird NetBird Client 0.40+ Management URL URL of the NetBird management server. Format: https://host[:port]. When set, users cannot override this value via UI or CLI. Pre-shared key WireGuard pre-shared key used as an additional symmetric secret on every peer-to-peer tunnel. Secret value. Disable auto-connect When enabled, the NetBird tunnel does not auto-connect at daemon startup. Equivalent to --disable-auto-connect. Disable autostart When enabled, the NetBird GUI is prevented from registering itself as an OS autostart entry on fresh installs, and any existing OS autostart entry registration is removed on the next GUI launch (Windows Registry Run key, macOS Login Item, Linux .desktop). Once the admin lifts the policy, the setting stays off until the user re-enables it in Settings. Disable client routes When enabled, this client will not consume routes advertised by routing peers. Equivalent to --disable-client-routes. Disable server routes When enabled, this client will not act as a routing peer for other clients. Equivalent to --disable-server-routes. Block inbound When enabled, the client firewall blocks all inbound peer traffic on the WireGuard interface. Equivalent to --block-inbound. Allow server SSH When enabled, this client accepts incoming SSH sessions via NetBird SSH. Equivalent to --allow-server-ssh. Enable Rosenpass Enables Rosenpass post-quantum key exchange on WireGuard tunnels. Both peers must support it. Rosenpass permissive When enabled, the client falls back to plain WireGuard if a peer does not support Rosenpass; otherwise it refuses the connection. WireGuard port UDP port used by the local WireGuard interface. Allowed range: 1-65535. Split tunnel Restrict the NetBird tunnel to or from a chosen list of application package names. Choose either the allow mode (only the listed apps route through NetBird) or the disallow mode (the listed apps bypass NetBird; everything else routes through). The mode is mutually exclusive — only one can be active at a time. Android-only at the daemon level; Windows/macOS/iOS clients ignore this policy. Allow only listed apps (everything else bypasses) Disallow listed apps (everything else routes) Disable update settings When enabled, blocks every configuration change from the client UI and from the CLI (netbird up / login / setconfig). The Settings view stays viewable but read-only. Equivalent to --disable-update-settings. Disable profiles When enabled, the client UI/CLI cannot list, create, switch or remove NetBird connection profiles. Equivalent to --disable-profiles. Disable networks When enabled, the client UI/CLI cannot list, select or deselect NetBird networks (the corresponding daemon RPCs return Unavailable). Equivalent to --disable-networks. Disable metrics collection Reserved for a future client telemetry feature. The client recognizes this setting but it has no effect in current releases. Disable advanced view When enabled, the client hides the advanced section of its interface. This policy only changes what the interface offers: it is not part of the daemon configuration and never causes a configuration change to be rejected. Setting it to Disabled explicitly re-enables the section. Lazy connections Local override for lazy connections. Enabled forces lazy connections on, Disabled forces them off, and leaving the policy Not Configured defers to the Management setting. The NB_LAZY_CONN environment variable takes precedence over this policy. Allow remote jobs Allows management-requested remote jobs, such as debug bundle requests, to run on this peer. Off by default; equivalent to --allow-remote-jobs. Configuring this policy at either value locks the corresponding client toggle, so Disabled pins remote jobs off. Debug bundle upload URL Overrides the upload service used for debug bundles produced by remote jobs, taking precedence over the value requested by Management. Must be an https URL including a host. Enable local metrics endpoint Exposes the client's local Prometheus /metrics endpoint. Unrelated to "Disable metrics collection". Local metrics listen address Listen address of the local Prometheus /metrics endpoint. Defaults to 127.0.0.1:9191 when the endpoint is enabled and this policy is Not Configured. https://api.netbird.io:443 WireGuard UDP port: Mode: 127.0.0.1:9191