# A clean Windows install for agent work

2026-10-05

I reinstalled Windows 11 on my machine on 30 September, and a Synology NAS is the next thing to go in. Before it does, I set the machine up for the way I work: several Claude Code sessions at once, each running with my own user rights. Portmaster and Defender were in use before the reinstall, and so were my own agent gates. The agent's deny list and its newest gate are new. Setting everything up together showed me what each layer covers that the others leave open, and I found none I would drop.

## Why set everything up at once?

The gap in one layer is easiest to see next to the others. Before the reinstall each protection had arrived on its own day for its own reason, and I never looked at them side by side. This time I set them up together and measured the machine after each step.

## What was off after the cleanup?

After the reinstall I ran O&O ShutUp10++, which I need before Windows is usable for me at all. I also ran RemoveWindowsAI by zoicware with every option except the one for Defender's AI protection, to remove Recall and Copilot along with the other Windows AI features. A measurement afterwards found three protections off. The tool's registry option disables what it calls experimental agentic features, so it had disabled the agent isolation service and added four agent policies. Defender's protection for AI agents was off as well, but I had left the tool's Defender option unchecked, and the off state was Defender's own default on this machine. Resetting it to the default does not turn it on, so it has to be set to Block explicitly. Cloud protection was off because of a policy I had set myself earlier.

A reviewed script returned the agent isolation service to manual start. It removed the four agent policies and set three Defender values on: protection for AI agents, its network inspection and cloud protection. It recorded how to undo each step. Group Policy then undid part of that, because my own local policy file still set cloud protection off and still held the agent policies the script had removed. On 5 October I took three of those policies out of the file and changed cloud protection there to Advanced MAPS. Group Policy now sets it again at every policy refresh, along with virtualization-based security and memory integrity. The fourth policy turns off only the AI search in the Settings app, and I left it in place. The Windows toggle for the agent workspace stays gone, because the tool removed its packages, and I do not use that feature. Everything else the tool removed stays removed. A tool that removes features can remove protections in the same run, so I measure after every such tool. RemoveWindowsAI also often leaves something in Windows broken. It is easy to put right if you know Windows and read a little on the tool's GitHub page, and I have used the tool for a long time.

Several of Windows' own protections were already on when I measured them: virtualization-based security with memory integrity, LSA protection and the vulnerable driver blocklist. Defender's real-time protection and Tamper Protection were on as well. I have checked Secure Boot and the TPM myself, and both are on.

## What does the firewall decide?

Portmaster decides which app may connect where. Its default action is Block, so a connection that no rule allows is refused. I also have it set to block incoming connections in its global settings. Connections made straight to an IP address without a DNS lookup first are blocked for every app except the browsers. The browsers do not work with that block, and I think it is because they resolve names through a modDNS setup of their own. In Portmaster I turned off its own relay network and set all 64 app profiles to match.

Windows Firewall stays on in all three profiles. It allows outgoing traffic by default, so for outgoing connections Portmaster makes the decision. On 1 October I removed 25 allow rules, nearly all for telemetry or for Store and system packages that Portmaster does not allow, such as the Xbox packages and Clipchamp. A second round since then removed 18 more and switched others off. Windows Firewall has 485 rules today, and 354 of them are switched off. Of the 131 allow rules that are on, 78 are Windows' own built-in rules and 39 belong to app packages, nearly all of them parts of Windows. The other 14 belong to apps I use, the browsers among them. I also disabled 22 services, among them the telemetry service and the SSDP and UPnP discovery services.

## What did the DNS setting show?

Portmaster has a setting called Block Secure DNS Bypassing. It stops programs from sending name lookups past Portmaster's own Secure DNS resolver, for example to DNS over HTTPS or to public resolvers. The setting was on before the reinstall too. After the reinstall, before I had forced it on again, I watched Portmaster show the same kind of warning again and again. Two of the warnings name a program, one Portmaster calls Git Curl and one it calls Python. Each says the program uses its own Secure DNS resolver, which would go past Portmaster.

I first guessed that Node and Python do this by default. Python's standard name lookup asks the resolver the operating system is configured with, so I doubt the Python warning came from Python's default behaviour. Later I noticed that I also had Portmaster's Ignore System/Network Servers setting on, so it does not use the DNS servers that Windows or the network hands out. I think that setting is the likely cause of the warnings. With Block Secure DNS Bypassing forced on, I no longer get a notification. I did not test which of those two settings explains what I saw, and I did not trace which program behind either warning made the lookups.

A third case I know of is my own code, from before the reinstall, so it is not one of the warnings I saw. My local resolver did not answer the mail server queries of my sending script, so in August I made the script ask DNS over HTTPS first, with the system resolver and public resolvers as fallbacks. When Portmaster blocked those paths in September, the script learned to skip a blocked path and use the system resolver, which on this machine is Portmaster's.

## What else sits between the machine and the internet?

My connection goes out through IVPN, which I have set to rotate its WireGuard key every day. Its firewall is set to always on, so it starts at boot before any other process and blocks traffic outside the VPN even when the IVPN app is not running. It lets through traffic to IVPN's own servers and to my local network. Windows treats both the IVPN tunnel and my wired connection as public networks, so its firewall applies its most restrictive profile to both. IVPN is behind three of these pieces: it runs the VPN and modDNS, and in December 2024 it bought Safing, the company behind Portmaster. In the IVPN app I have set modDNS as the custom DNS, and it filters with the HaGeZi Threat Intelligence Feeds and Pro lists, plus a HaGeZi list of domains registered within the last seven days. I have checked that my lookups reach it. For one day I collected the domains modDNS blocked, and I copied every one whose block breaks nothing into the Windows hosts file, as a second block in Windows itself. After that they disappeared from the modDNS log, so those lookups now stop in Windows before they reach it. The browsers have a modDNS setup of their own. HaGeZi publishes stricter lists than Pro, so I still count these list choices as relaxed. I use these lists in all my work. If the machine ever reached my router without the VPN, the router runs the NextDNS CLI with much stricter HaGeZi lists. As far as I know, that has never happened without me choosing it.

## What may an agent session not touch?

On this machine a Claude Code session runs commands as me, and there is no sandbox between a command and my files. So I closed off what a session has no reason to reach:

- My password manager and the apps behind my sign-in keys.
- My encrypted vaults, read from the vault app's own settings at run time.
- Portmaster and its control interface.
- Every drive letter except C:, the system drive. That covers the backup clone of the system disk and any vault I open, because an open vault gets a drive letter of its own.
- The browser I use myself, because the agent has a browser of its own.
- Writes to the agent's own user settings and its installed plugin, so that a session cannot switch these rules off.

Two layers do this. Claude Code's own settings carry 161 deny rules, and a gate in my own plugin reads each command and tool call as text before it runs.

The vaults are on the list because of a warning from a session. I had unlocked an encrypted vault, and the session I was working in warned me that its secrets were now open. While a vault is unlocked, its files are readable by every program that runs with my rights, the agent session included. That was the moment I understood the list had to be much wider than the one vault.

## How do I know the gate holds?

I test the gate with mutations. Each mutation breaks one condition in a copy of the gate's code and runs the whole suite of 309 tests. It counts as caught only when the run goes red and the test that fails is that gate's own test. The plugin has 239 mutation cases, and 70 of them belong to this gate. A full run is 73 851 test runs. The run that started just after midnight on 5 October had caught 226 of 226 when Windows Update restarted the machine an hour and 50 minutes in. That morning I reran the group of 19 cases that held the other 13. Eighteen were caught at once. The nineteenth could not find the line it was meant to break, because a fix had moved that code and the case still looked for it at the old place. After I pointed it at the new place, it was caught as well, so all 239 are caught.

The gate reads the text of a command, so it is a filter and not a boundary in the operating system. It catches a session's mistakes. Anything that touches a closed area I run myself, after reading its dry run.

## Why does the hardware matter?

The model runs at Anthropic, and everything around it runs here: several sessions at once, their Node and Python processes, the test suites and the two hour mutation run. The machine has an Intel Core i9-14900KS, 48 GB of DDR5 at 8000 MT/s and an RTX 4080 Super.

On 4 October the pump in the liquid cooler stopped. Without the pump the radiator and its push and pull fans cannot carry heat away from the processor, and all work stopped. A new cooler is in, and the machine is ready for the week ahead.

## What comes next?

Two 8 TB drives go into the NAS, and my disk images will go there. Once the first image is on it, I will test a restore from it.

## What does this not show?

It does not show that this machine cannot be broken into. The gate stops mistakes made by a session I started myself, and its limits are above. Portmaster named two programs in two warnings. I did not trace which script or command behind them made each attempt, or test whether my Ignore System/Network Servers setting caused them. I have no count of how often each layer has mattered. The two hours for a full run is extrapolated from the 226 cases that ran in one go. This is one person's machine.

## Frequently asked

**Does an agent session on Windows run with my user rights?**

On my machine it does. Claude Code runs commands as my user, so whatever my account can read or change, a command it runs can too. That is why the deny rules and the gate exist.

**Why keep the agent away from the backup disk?**

The clone is a full copy of the system disk. A session that can read it can read everything on that disk, and one that can write to it can damage the copy I would restore from.

**What does Block Secure DNS Bypassing do in Portmaster?**

It prevents apps from going past Portmaster's Secure DNS resolver, for example by using DNS over HTTPS or a public resolver. Lookups then go through Portmaster, which can filter them.

## Related

- [What agent memory in local files gets me](/blog/local-agent-memory)
- [Five rounds before the agent signed anything](/blog/five-rounds-before-the-agent-signed)
- [Define what an agent may do with your data](/guides/letting-agents-act-on-data)