It is not possible to lock down windows firewall, that is why you are having trouble. If you go to "windows firewall with advanced security" you will see several entries for "inbound rules" These rules should not be present unless you have a inbound computer that you want to access your computer.
As a test you can save your firewall settings and then remove all inbound rules. this will only effect any devices that you want to directly access your computer like remote control or SSH. Remember you have a saved configuration of your firewall so you can always return to the original.
Remove all "inbound rules' and you will find your computer still functions normally. But when you come back to the inbound rule later you will see the "inbound rule" has self populated without asking for administrator privilege. How can a firewall rule populate without requiring administrative privilege ? The next issue is the rules you see inbound are all the properties that are allowed to access your computer remotely, take a look at the items.