NetBird Client PoliciesGroup Policy template for NetBird client MDM-managed settings. Values are written under HKLM\Software\Policies\NetBird and consumed by the netbird daemon at startup and every 1-minute reload tick.NetBirdNetBird Client 0.40+Management URLURL of the NetBird management server. Format: https://host[:port]. When set, users cannot override this value via UI or CLI.Pre-shared keyWireGuard pre-shared key used as an additional symmetric secret on every peer-to-peer tunnel. Secret value.Disable auto-connectWhen enabled, the NetBird tunnel does not auto-connect at daemon startup. Equivalent to --disable-auto-connect.Disable autostartWhen enabled, the NetBird GUI is prevented from registering itself as an OS autostart entry on fresh installs, and any existing OS autostart entry registration is removed on the next GUI launch (Windows Registry Run key, macOS Login Item, Linux .desktop). Once the admin lifts the policy, the setting stays off until the user re-enables it in Settings.Disable client routesWhen enabled, this client will not consume routes advertised by routing peers. Equivalent to --disable-client-routes.Disable server routesWhen enabled, this client will not act as a routing peer for other clients. Equivalent to --disable-server-routes.Block inboundWhen enabled, the client firewall blocks all inbound peer traffic on the WireGuard interface. Equivalent to --block-inbound.Allow server SSHWhen enabled, this client accepts incoming SSH sessions via NetBird SSH. Equivalent to --allow-server-ssh.Enable RosenpassEnables Rosenpass post-quantum key exchange on WireGuard tunnels. Both peers must support it.Rosenpass permissiveWhen enabled, the client falls back to plain WireGuard if a peer does not support Rosenpass; otherwise it refuses the connection.WireGuard portUDP port used by the local WireGuard interface. Allowed range: 1-65535.Split tunnelRestrict the NetBird tunnel to or from a chosen list of application package names. Choose either the allow mode (only the listed apps route through NetBird) or the disallow mode (the listed apps bypass NetBird; everything else routes through). The mode is mutually exclusive — only one can be active at a time. Android-only at the daemon level; Windows/macOS/iOS clients ignore this policy.Allow only listed apps (everything else bypasses)Disallow listed apps (everything else routes)Disable update settingsWhen enabled, blocks every configuration change from the client UI and from the CLI (netbird up / login / setconfig). The Settings view stays viewable but read-only. Equivalent to --disable-update-settings.Disable profilesWhen enabled, the client UI/CLI cannot list, create, switch or remove NetBird connection profiles. Equivalent to --disable-profiles.Disable networksWhen enabled, the client UI/CLI cannot list, select or deselect NetBird networks (the corresponding daemon RPCs return Unavailable). Equivalent to --disable-networks.Disable metrics collectionReserved for a future client telemetry feature. The client recognizes this setting but it has no effect in current releases.Disable advanced viewWhen enabled, the client hides the advanced section of its interface. This policy only changes what the interface offers: it is not part of the daemon configuration and never causes a configuration change to be rejected. Setting it to Disabled explicitly re-enables the section.Lazy connectionsLocal override for lazy connections. Enabled forces lazy connections on, Disabled forces them off, and leaving the policy Not Configured defers to the Management setting. The NB_LAZY_CONN environment variable takes precedence over this policy.Allow remote jobsAllows management-requested remote jobs, such as debug bundle requests, to run on this peer. Off by default; equivalent to --allow-remote-jobs. Configuring this policy at either value locks the corresponding client toggle, so Disabled pins remote jobs off.Debug bundle upload URLOverrides the upload service used for debug bundles produced by remote jobs, taking precedence over the value requested by Management. Must be an https URL including a host.Enable local metrics endpointExposes the client's local Prometheus /metrics endpoint. Unrelated to "Disable metrics collection".Local metrics listen addressListen address of the local Prometheus /metrics endpoint. Defaults to 127.0.0.1:9191 when the endpoint is enabled and this policy is Not Configured.https://api.netbird.io:443WireGuard UDP port:Mode:127.0.0.1:9191