On global policy, you can chose to set it up ( on), to disable it ( off) or to let the computer decide on its own which policy to apply ( not configured). Right clic on Windows Firewall with advanced security. Go to Computer configuration, Windows Settings, Security settings, Windows Firewall with advanced security. here is the Microsoft documentation pages on how to do that. This is totally possible to create a policy ruling incoming connection attempts with a GPO.