Windows Connect Now (WCN) is Microsoft’s implementation of the Wi-Fi Protected Setup (WPS) protocol, designed to simplify the process of adding devices to a wireless network (e.g., using a PIN or pushing a button on a router). While convenient for home consumers, WPS/WCN represents a well-documented, catastrophic security vulnerability in strict enterprise, military, or zero-trust deployment environments. The protocol is highly susceptible to brute-force PIN attacks (such as the Reaver attack), and allowing Windows clients to interface with WCN-enabled infrastructure creates an unauthorized bridging mechanism that bypasses robust WPA2/WPA3-Enterprise 802.1X certificate-based authentication.
This guide explains how to completely disable ‘Windows Connect Now’ (WCN) via Group Policy in Windows 11, enforcing a strict zero-trust model where the OS is cryptographically prevented from participating in simplified wireless provisioning protocols.
Disable Windows Connect Now via Group Policy
To enforce a strict block that permanently neutralizes the WCN infrastructure globally across the OS, we must deploy administrative templates. Note that this requires Windows 11 Pro, Enterprise, or Education editions.
- Log into Windows 11 with an Administrator account.
- Press the Windows Key + R to open the Run dialogue box.
- Type
gpedit.mscand press Enter to launch the Local Group Policy Editor. - In the left-hand navigation pane, strictly follow this exact path:
Computer Configuration > Administrative Templates > Network > Windows Connect Now - In the right-hand pane, you will see several policies related to WCN functionality. To completely neutralize the service, we must explicitly disable them all:
- Double-click Configuration of wireless settings using Windows Connect Now. Select Disabled. Click Apply, then OK.
- Double-click Prohibit Access to the Windows Connect Now wizards. Select Enabled. Click Apply, then OK.
- Double-click Turn off Windows Connect Now. Select Enabled. Click Apply, then OK.
- (By explicitly configuring these policies, we instruct the Windows kernel and networking stack to completely ignore WPS broadcast beacons, disable the underlying `wcncsvc` service, and remove all UI elements related to PIN-based or push-button wireless setup).
Verify the Configuration Lockdown
Group Policy changes affecting the networking stack require the system to restart or the policy to be forced.
Open Command Prompt as Administrator and run gpupdate /force, then restart the computer. To verify the restriction is active, open the Network and Sharing Center or the Windows 11 Settings app (Network & internet > Wi-Fi). Any options previously available to set up a new router or access point using a PIN or push-button method will be completely removed from the UI. Furthermore, the “Windows Connect Now – Config Registrar” service (wcncsvc) will be stopped and unable to start. The Windows 11 workstation is now cryptographically bound to a strict, standard-authentication-only wireless state.