Restoring QuickBooks Desktop Firewall and UAC Rules After a Windows Feature Update

When a Windows feature update wipes your QuickBooks hosting and port exceptions, here is how to rebuild them without reinstalling QuickBooks Desktop.

Windows semi-annual feature updates (and certain cumulative updates) can reset Windows Defender Firewall rules, overwrite inbound port exceptions, and in some cases revert User Account Control behavior. After the update completes, multi-user mode stops working: the host machine can open the company file, but workstations see H-series errors (H202, H503) or cannot locate the file on the network. The QuickBooks Database Server Manager service may also be reset to a disabled or manual start state. None of this requires reinstalling QuickBooks. The fix is to manually re-establish the firewall exceptions, confirm the service state, and verify UAC settings so the database manager can bind to the correct ports.

What actually breaks during the update

A feature update creates a fresh Windows image and migrates installed applications into it. During that migration, third-party firewall rules are frequently dropped or reset to their default block state. QuickBooks relies on inbound TCP exceptions for several executables — QuickBooksDBxx, QBW32.exe, QBDBMgrN.exe, and FileManagement.exe among them — as well as dynamic port reservations. When those rules disappear, the Database Server Manager can no longer accept connections from other machines on the LAN.

UAC is less commonly reset, but when it is, the symptom is subtle: QuickBooks appears to open normally in single-user mode on the host, but the Database Server Manager cannot elevate sufficiently to register the company file for shared access. The file shows as available locally but never appears in the server manager's list of shared files.

Step 1: Verify the Database Server Manager service

Open services.msc and locate QuickBooksDBXX (where XX corresponds to your QuickBooks version year — for example, QuickBooksDB35 for 2024). Confirm the following:

  • Status is Running.
  • Startup type is Automatic.
  • Log On As is set to Local System (or the account specified during your original installation).

If the service is stopped or set to Manual, right-click, select Properties, set Startup type to Automatic, and start the service. If the service is missing entirely, that indicates the update removed the service registration — run the QuickBooks Install Diagnostic Tool from the Tool Hub, which re-registers services without uninstalling the application.

Step 2: Rebuild the firewall exceptions

Open Windows Defender Firewall with Advanced Security (wf.msc). Select Inbound Rules and create new rules for each QuickBooks executable. The core programs and their default paths are:

  • C:\Program Files\Intuit\QuickBooks YEAR\QBW32.exe
  • C:\Program Files\Common Files\Intuit\QuickBooks\QBDBMgrN.exe
  • C:\Program Files\Intuit\QuickBooks YEAR\FileSyncClient.exe

For each, create a Port rule allowing TCP on the ports assigned to your version. QuickBooks uses version-specific dynamic ports. To find the exact ports your installation uses, open the QuickBooks Database Server Manager (Start menu), click the Ports tab or review the QBSDKConf log, and note the port range listed. Common defaults are 8019 (the QBDBMgrN listener) plus a dynamically assigned port in the 50000–53000 range.

Set each rule to Allow the connection, apply it to all three profiles (Domain, Private, Public — though we recommend removing Public if your network topology does not require it), and name it clearly (for example, QB Desktop YEAR — QBW32 Inbound).

Step 3: Confirm UAC settings

Open Change User Account Control settings from the Start menu. The slider should be at the second-from-top position (Notify me only when apps try to make changes to my computer). If the update dropped it to the bottom (Never Notify), the Database Server Manager cannot properly register files for hosting. Move it back, restart, and rescan.

Step 4: Rescan and verify hosting

Open the QuickBooks Database Server Manager, add your company file folder under the Folders tab, and click Scan. When the scan completes, your company file should appear in the results with a Status of Monitored. If it does not, the folder permissions were likely reset during the update — right-click the folder, select Properties, and under the Security tab confirm that the Everyone group or the specific Windows user accounts on the workstations have Full Control or at minimum Modify access.

On the host machine, open QuickBooks, go to File → Utilities, and confirm that Stop Hosting Multi-User Access is visible (meaning hosting is currently ON). On each workstation, confirm the opposite: Host Multi-User Access should be visible, meaning the workstation is NOT hosting.

Step 5: Test from a workstation

Map a persistent drive letter to the host's shared folder if you have not already. Open the company file via Open a company file and browse to the .ND file in the shared folder. If the connection succeeds and the mode indicator reads Multi-User, the rebuild is complete.

If workstations still cannot connect after all of the above, the .ND network descriptor file may contain stale IP information. Delete the .ND file (QuickBooks regenerates it automatically) and reopen the company file. For deeper file-level issues such as corruption discovered during this process, a full Verify and Rebuild cycle should be run before further troubleshooting.

Keep going

Your Desktop doesn’t have to end when Intuit says so.

Start with the master survival guide, or jump straight to the fix you need.