While the above solution does work... needing to allow svhost full (outbound at least) access is less than ideal. Inbound was never really a concern with a hardware firewall already in place, but the outbound is exactly what I wanted to have blocked outside of approved apps like xbox. I don't need svhost being used to…