I have managed to block port 445 in the windows firewall using Group Policy, now the server that has this GPO applied is unable to read further GPO updates from the domain controller.
Is there any way to fix this short of dropping it from the domain, fixing it, then adding it back to the domain? Or would that even work?