You can programmatically open these mandatory ports across your fleet using local PowerShell commands: powershell
: To trigger an update on a specific server or workstation: Invoke-GPUpdate -Computer "HR-PC01" -Force . gpupdate powershell