Enabling Intune’s Disallow Network Connectivity Active Tests setting prevents Windows from making NCSI active probes to determine whether it has Internet connectivity. The name is easy to misread: in the Settings Catalog, selecting Allow allows the disallow policy, so active probes are turned off. For most devices, leave the setting unconfigured unless you have a specific network or compliance requirement and have tested the effects.
What Windows NCSI does
The Network Connectivity Status Indicator (NCSI) helps Windows classify a connection as having Internet access, limited to a local network, or requiring further action such as captive-portal authentication. It combines active probes with passive signals from the network stack.
Active probes
On modern Windows, active probing generally includes resolving www.msftconnecttest.com, requesting http://www.msftconnecttest.com/connecttest.txt, and checking for a successful response containing the expected “Microsoft Connect Test” text. NCSI also uses a DNS probe involving dns.msftncsi.com. Microsoft’s current troubleshooting guidance lists ipv6.msftconnecttest.com for the IPv6 web probe. The specific results depend on the network path, DNS, proxy, firewall, and IPv4 or IPv6 configuration. See Microsoft’s NCSI troubleshooting guidance.
Windows 10 version 1607 and later use Microsoft Connect Test endpoints; older Windows versions used www.msftncsi.com/ncsi.txt. Do not assume that older endpoint is the current default on modern Windows. See Microsoft’s NCSI FAQ.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
- Electrical supplies, monitoring software
- Can analyze, control, and save sending and receiving records
- It is a comprehensive multifunctional analyzer
- Users can use all the functions of the software
Passive signals
This Intune setting blocks active tests; it does not turn off every NCSI mechanism. Passive polling is configured separately and can continue. Microsoft’s FAQ identifies a 15-second default passive-polling period in applicable conditions. Separate policies also cover corporate NCSI configuration and passive polling; they are not controlled by this setting. See the NCSI Policy CSP and the NCSI FAQ.
What the Intune setting means
The Settings Catalog entry is Disallow Network Connectivity Active Tests, under Connectivity. It is a device-scoped integer policy at ./Device/Vendor/MSFT/Policy/Config/Connectivity/DisallowNetworkConnectivityActiveTests. Microsoft lists support for Windows 10 version 1703 and later on Pro, Enterprise, Education, and IoT Enterprise editions. Consult the Connectivity Policy CSP for the current supported-version and edition details.
| Intune/CSP state | Effect |
|---|---|
Allow / enabled (CSP value 1) |
Enables the policy that disallows active NCSI tests; probes are blocked. |
Disabled (CSP value 0) |
The policy does not block active tests. |
| Not configured | The policy is not imposed; Windows retains its normal active-probing behavior. |
The policy corresponds to the Group Policy setting Turn off Windows Network Connectivity Status Indicator active tests and maps to HKLMSoftwarePoliciesMicrosoftWindowsNetworkConnectivityStatusIndicator, value NoActiveProbe. A value of 1 disables the probes. This is not a bandwidth monitor, uptime monitor, synthetic transaction, or Intune device-health test; it changes the NCSI active-probe behavior. CSP mapping details are in Microsoft’s policy documentation.
Should you disable active tests?
Microsoft cautions that Windows components and applications may rely on NCSI status. Blocking probes can make connectivity classification less accurate and can affect status indicators or portal-related behavior. It is not a general privacy or security improvement, and it should not be used as a default way to quiet firewall logs. See Microsoft’s guidance on NCSI and network connectivity.
| Situation | Practical approach |
|---|---|
| Ordinary corporate Internet access | Leave the setting unconfigured unless there is a documented requirement. |
| A policy prohibits connections to Microsoft probe endpoints | Consider a targeted deployment after testing dependent applications and documenting the reason and rollback plan. |
| A proxy, firewall, or inspection system causes false connectivity status | Investigate the network path first; test disabling probes only as a scoped mitigation. |
| Isolated or tightly restricted network | Consider whether the policy fits the device’s role and what connectivity signals users and applications need. |
| Devices frequently use captive portals | Avoid broad deployment until guest Wi-Fi and other authenticated portals have been tested. |
| The network icon is inaccurate while applications work | Compare NCSI status with DNS, proxy, VPN, firewall, and actual application connectivity rather than assuming the policy will fix the cause. |
Create the policy in Intune
-
Sign in to the Microsoft Intune admin center with an account that can create device configuration policies. The Settings Catalog workflow is under Devices > Configuration > Create > New policy; portal labels can change. The workflow is also documented in HTMD’s Intune walkthrough.
-
Select Windows 10 and later as the platform and Settings catalog as the profile type.
-
Give the profile an effect-oriented name, such as
Windows - Disable NCSI Active Probes. A description can state that the profile enables the policy that prevents Windows NCSI active Internet-connectivity probes. -
Under Configuration settings, choose Add settings, search for
Disallow Network Connectivity Active Tests, and select it under Connectivity.Free tools Windows power users keep installed
One-click scans. No signup required.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.Rank #2
midBit Technologies, LLC SharkTapUSB Ethernet Sniffer- Ethernet Test Access Port that does not require an ethernet port, for thin notebook or netbook PCs. Uses USB 3 or USB 2 port on PC (Also provides a CAT-5 TAP port)
- A 'Test Access Port' allows you to see the packets on an ethernet link. Directly supports 10-, 100- or 1000Base-T links.
- Intended to be used with the open source Wireshark program, or equivalent.
- The Gen2 SharkTapUSB features 'carbon copy' copper repeater technology for minimum impact on the monitored network. The carbon copies of bi-directional data are aggregated onto a single wired or USB Test Access Port (TAP)
- Power-over-ethernet pass through. (For power-fail bypass, search "SharkTapBYP") 400mA current. Non-conductive plastic cover. Auto cross-over for cables. USB3 cable included
-
Set it to Allow or Allowed to disable active probes. This is the inverted-name trap: you are allowing the disallow policy, not allowing the tests. To keep normal behavior, leave it unconfigured or do not include it in the profile.
-
Set scope tags if delegated administration requires them. They are optional.
-
Assign the profile to a device group. Because this is device-scoped, plan and review device assignments rather than treating it as a user preference.
-
Review the platform, setting, value, scope tags, and assignments, then select Create.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Roll out to a limited group first
Use a pilot before broad deployment. Include representative devices and test the services and network situations that matter to your organization. Review assignment filters, exclusions, and other management policies for conflicts; avoid simultaneously managing the same setting through Intune and Group Policy unless precedence is intentional and understood.
-
Start with a small IT or test-device group.
-
Test VPN, proxy, DNS, firewall or web filtering, Windows Update, Microsoft 365, line-of-business applications, and captive portals where relevant.
-
Record why the probes are being blocked, which devices are in scope, the expected trade-offs, and how to restore the default behavior.
-
Expand through deployment rings only after checking both policy processing and user-facing behavior.
Recommended Free Tools
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.Rank #3
SENECESLI Passive Ethernet Tap for 10BASET 100BASETX Monitoring- Passive Operation: This Ethernet tap functions entirely without external power, acting as an inline cable. It provides a stealthy, portable solution for network diagnostics and traffic analysis without altering existing infrastructure.
- Directional Port Monitoring: Equipped with dedicated J3 and J4 receive-only ports, each captures unidirectional data . This enables precise traffic segregation for accurate packet analysis at monitoring stations.
- Simple Inline Setup: Connect the J1 and J2 network ports between your switch and target device using standard Ethernet cables. No configuration or drivers are required, making deployment for any IT professional.
- Software Compatible: Works seamlessly with popular packet analysis tools for deep network inspection. and decode data packets on your monitoring PC to troubleshoot issues or network performance effectively.
- Compact Portable Design: Built on a durable PCB board, this lightweight module fits easily into a toolkit or laptop bag. Its rugged construction ensures reliable performance in field service or lab environments.
Verify delivery and client behavior
Verification has several layers. An assignment is not proof of device check-in; a successful policy operation is not proof that the intended network behavior has been independently observed.
Check Intune status
-
Open the configuration profile and review its device and user check-in status.
-
Inspect the target device’s per-setting status and confirm its last check-in.
-
Investigate pending, error, or conflict states before concluding the policy has applied.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Check Windows policy processing
On the client, open Event Viewer > Applications and Services Logs > Microsoft > Windows > DeviceManagement-Enterprise-Diagnostics-Provider > Admin. Event ID 813 can help identify an MDM policy operation. It is evidence of policy processing, not standalone proof that NCSI probe traffic has stopped. The event-log verification approach is described in HTMD’s walkthrough.
Inspect the policy and NCSI configuration
For the policy mapping, inspect HKLMSoftwarePoliciesMicrosoftWindowsNetworkConnectivityStatusIndicator and check whether NoActiveProbe is set to 1. For the underlying NCSI operational configuration, Microsoft’s troubleshooting guidance identifies HKLMSYSTEMCurrentControlSetServicesNlaSvcParametersInternet and the EnableActiveProbing value; 0 indicates active probing is disabled at that configuration layer. Prefer Intune or Group Policy for management rather than making unmanaged registry edits. See Microsoft’s NCSI troubleshooting guidance.
Capture traffic when you need stronger evidence
On a test device, a packet capture can show whether requests to www.msftconnecttest.com, ipv6.msftconnecttest.com, or dns.msftncsi.com occur after policy processing. Under normal conditions, the expected active-probe traffic should no longer occur when the policy is effective. A capture provides behavioral evidence; the network icon alone reports NCSI’s classification and does not establish the full policy state.
Troubleshoot common problems
The setting does not appear in the catalog
Search the exact phrase Disallow Network Connectivity Active Tests and look under Connectivity. Confirm you are using a device configuration profile and a supported Windows edition and version. The CSP path in the Microsoft Connectivity Policy CSP is the authoritative identifier.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchRank #4
- SEAMLESS INTEGRATION: Features precise interface design for easy installation and compatibility with multiple mounting configurations
- WIRELESS : Efficiently captures wireless data packets for and CDC device development, providing comprehensive monitoring and analysis capabilities
- VERSATILE FUNCTIONALITY: Functions as both a packet and development board, offering multiple use cases for wireless communication applications
- PROFESSIONAL CHIPSET: Incorporates high-performance CC2531 chipset for reliable data and precise control capabilities
- DURABLE CONSTRUCTION: Built with premium materials to withstand extended use and various operating conditions while maintaining consistent performance
The profile is assigned but the device has not changed
Check enrollment and MDM management status, last check-in, assignment filters, exclusions, conflicts, and OS support. Review the DeviceManagement-Enterprise-Diagnostics-Provider log and local policy values. Another management system may set the same policy. Whether a restart or service refresh is needed can depend on the Windows build and circumstances; verify the client rather than assuming assignment alone applied the setting.
Users still report “No Internet”
Blocking active probes can reduce NCSI’s ability to classify connectivity, and it does not repair a failed network path. Compare the NCSI indication with actual DNS resolution, HTTP/HTTPS access, proxy configuration, VPN state, firewall or TLS inspection behavior, captive-portal requirements, and Windows Update access.
Captive portals behave unexpectedly
NCSI participates in detecting conditions that can lead to portal-related behavior. Proxy or network restrictions that prevent probes from completing can contribute to browser redirection behavior, and disabling probes can alter detection. Test guest Wi-Fi, hotel, conference, and other authenticated networks before expanding a deployment. See Microsoft’s connectivity guidance.
Restore normal active probing
-
Remove the device from the policy assignment, or change the setting so the disallow policy is no longer imposed. In an organization’s policy model, that can mean setting it to Not configured or removing it from the profile.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsSpecial offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy. -
Allow the device to check in and process the updated policy. If the device remains managed by another policy source, resolve that configuration as well.
-
Confirm that
NoActiveProbeis no longer enforced as1, then check the effective NCSI configuration and test the relevant network behavior. The CSP defines0as the state in which active tests are not blocked; policy refresh and precedence can affect how quickly the device returns to normal behavior. See the Connectivity Policy CSP.
Alternatives to disabling probes
Correct the failing network path
If infrastructure is blocking or altering NCSI, investigate DNS resolution for the probe hosts, HTTP access to the Microsoft Connect Test endpoint, proxy authentication and bypass rules, firewall or web-filter rules, TLS/HTTP inspection, VPN split tunneling, captive-portal configuration, and differences between IPv4 and IPv6. Microsoft lists probe endpoints and troubleshooting details in its NCSI troubleshooting guidance.
Use the separate corporate NCSI policies where appropriate
For specialized scenarios such as DirectAccess, Microsoft provides separate policies for corporate DNS probe hosts, corporate site prefixes, corporate web-probe URLs, and passive polling. These do not amount to the blanket active-test disablement policy. See the NCSI Policy CSP.
Use Group Policy for domain-managed devices
The equivalent policy is at Computer Configuration > Administrative Templates > System > Internet Communication Management > Internet Communication settings > Turn off Windows Network Connectivity Status Indicator active tests. As with Intune, coordinate policy ownership to avoid unintended conflicts. The mapping is documented in the Connectivity Policy CSP.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




