How to set up a proxy in Windows 11 and Windows 10
Open Settings > Network & internet > Proxy, click Set up next to Use a proxy server, switch it on, enter the gateway IP and port, and click Save. Edge, Chrome and most Windows apps follow it at once. Command-line tools and background services need their own settings, covered below.
Windows has one proxy setting per user account that most of the system reads: Edge, Chrome, Microsoft Store apps, .NET programs and PowerShell all pick it up. Set it once and a large part of the machine goes through your proxy. That’s handy on a work VPS or a dedicated research PC, and surprising on a home laptop when OneDrive, Teams and Windows Update suddenly share your proxy threads too.
The settings page also hides a second, separate proxy: WinHTTP, used by Windows services and some background tools, which ignores the Settings app entirely. And a whole class of programs (curl, Node.js, Java, Git, games) ignores both unless you configure them directly.
This guide covers the Settings app on Windows 11 and 10, the exceptions list, which programs obey the proxy and which don’t, netsh winhttp for services, and PowerShell commands to check and switch everything from a terminal.
Which Storm plan fits
A system-wide proxy sends far more than your browser through the gateway, so size the plan for it: a rotating 40- or 80-thread plan on the 15-minute gateway is a comfortable start, and the 10-thread package is only for testing. If the PC runs one account or tool that must always show the same IP, a private dedicated proxy is the better fit, and it’s the only Storm product with username and password login.
Rotating proxies (from $14/mo): 700,000+ IPs behind fixed gateway IP:PORTs. New IP on every request, or every 3 or 15 minutes. USA, EU, USA+EU or Worldwide. Unlimited bandwidth on every plan.
Get 40 threads for $39/mo See all rotating proxies plansBefore you start
- Log in to the member area and copy your gateway
IP:PORTs. They never change; the rotation happens on our side. - Add the public IP of the computer or server that will run your tool under Authorized IPs, click Save, and allow up to 15 minutes before testing. Rotating and residential proxies use IP authentication, so there is no username or password.
- Dedicated proxies work with either IP authentication or a username and password. Use user:pass if your IP changes or the tool runs on several machines.
- Count your threads: the tool’s total open connections must stay within your plan (for example 40 threads on the 40-thread plan).
Set a manual proxy in Windows, step by step
- Authorize this PC’s public IP first
Rotating and residential gateways have no password. Log in to the member area, add this computer’s public IP under Authorized IPs, click Save, and allow up to 15 minutes. Do it before switching the proxy on, because once it’s on, an unauthorized gateway cuts off every app that follows it.
- Open the Proxy page
Press Win + I and go to Network & internet > Proxy. On Windows 10 the same page is Settings > Network & Internet > Proxy.
- Decide on automatic detection
Under Automatic proxy setup, Automatically detect settings looks for a proxy script on your network. At home there’s none, and leaving it on can slow the first connection. Turn it off unless your company network uses it.
- Turn on the manual proxy
Windows 11: next to Use a proxy server click Set up, switch Use a proxy server on. Windows 10: switch Use a proxy server on directly. Enter the gateway in Proxy IP address and its number in Port. Don’t add
http://in front. - Fill in the exceptions
In the exceptions box, list addresses that should go direct, separated by semicolons, with
*as a wildcard, for example*.example.local;203.0.113.*. Leave Don’t use the proxy server for local (intranet) addresses ticked so your printer, NAS and router pages keep working. - Save and restart open apps
Click Save. New connections use the proxy straight away, but apps that cached the old setting (or keep long-lived connections) need a restart. Then check the exit IP in Edge or with the PowerShell commands below.
- Set WinHTTP if a service must use the proxy
Windows services and tools that run as SYSTEM don’t read the Settings app. Open Terminal as administrator and run
netsh winhttp set proxy GATEWAY_IP:PORT, or copy your user setting withnetsh winhttp import proxy source=ie.
PowerShell and netsh commands
Run the checks in a normal PowerShell window. The netsh winhttp lines change machine-wide settings, so they need an administrator terminal. Replace GATEWAY_IP:PORT with a gateway from your member area.
Get-ItemProperty 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Internet Settings' |
Select-Object ProxyEnable, ProxyServer, ProxyOverride
# which proxy Windows would pick for a given URL
[System.Net.WebRequest]::GetSystemWebProxy().GetProxy('https://api.ipify.org')# follows the system proxy
Invoke-RestMethod https://api.ipify.org
# talks to the gateway directly, whatever Windows is set to
curl.exe -x http://GATEWAY_IP:PORT https://api.ipify.org$key = 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Internet Settings'
# on
Set-ItemProperty $key ProxyServer 'GATEWAY_IP:PORT'
Set-ItemProperty $key ProxyOverride '<local>;*.example.local'
Set-ItemProperty $key ProxyEnable 1
# off
Set-ItemProperty $key ProxyEnable 0
# restart apps (or sign out and in) so they re-read the settingnetsh winhttp show proxy
netsh winhttp set proxy proxy-server="GATEWAY_IP:PORT" bypass-list="<local>;*.example.local"
netsh winhttp import proxy source=ie # copy the current user setting
netsh winhttp reset proxy # back to direct# current PowerShell window only
$env:HTTP_PROXY = 'http://GATEWAY_IP:PORT'
$env:HTTPS_PROXY = 'http://GATEWAY_IP:PORT'
$env:NO_PROXY = 'localhost,127.0.0.1'
# permanent for your user (new windows only)
setx HTTP_PROXY "http://GATEWAY_IP:PORT"
setx HTTPS_PROXY "http://GATEWAY_IP:PORT"
# Git keeps its own setting
git config --global http.proxy http://GATEWAY_IP:PORTWhich apps follow the Windows proxy, and which don’t
“Set a proxy in Windows” really means “set the proxy that apps can choose to read”. Here’s how common software behaves:
- Follow it: Microsoft Edge, Google Chrome (see the Chrome guide), Microsoft Store apps, most .NET programs, PowerShell’s
Invoke-WebRequestandInvoke-RestMethod, and Python’srequests, which reads the Windows setting when no environment variable is set. - Follow it if told to: Firefox, when Connection Settings says Use system proxy settings (the Firefox guide covers its own proxy). Java, with
-Djava.net.useSystemProxies=true. - Ignore it:
curl.exe, Node.js, Git, many command-line tools (they useHTTP_PROXYvariables or their own config), most games and launchers, and anything that sends UDP traffic. - Use WinHTTP instead: Windows services, tasks running as SYSTEM, and some updaters and agents.
For an app that has no proxy option and ignores all of the above, use a proxifier tool that redirects its connections; see the Proxifier guide.
A system proxy uses more threads than you think
Your plan’s thread count is the number of connections open at once through the gateway. With a system-wide proxy, that includes every background sync client, update check, chat app and browser tab. A browser tab alone uses around 10 threads. On a 10-thread plan, Windows can use up the whole allowance before you open a page, and sites then load slowly or not at all.
Two ways to keep it under control:
- Send background traffic direct. Add domains you don’t need proxied to the exceptions box, for example
*.microsoft.com;*.windowsupdate.com;*.office.com. They stop counting against your threads. - Proxy only the apps that need it. Set the proxy inside the browser or the tool, or use Proxifier rules, and leave Windows itself direct.
Pick the gateway with the same care. The Main rotating gateway hands out a new IP per connection, which confuses Microsoft account sign-in and any site you’re logged in to. For a whole-PC proxy, the 15-minute gateway keeps behaviour closest to a normal connection, and the 3-minute gateway (USA only) suits registrations and social sites. Keep Google and other search engines on the Main gateway, within a quarter of your threads.
Username and password proxies on Windows
The Windows proxy page has no username or password fields. When a proxy asks for credentials, each app handles it on its own: Edge and Chrome show a sign-in box, other apps simply fail. That’s why IP authorization is the smoother option on Windows. Rotating and residential plans use it only, and private dedicated proxies support it too. Switch your dedicated proxies to IP authorization in the member area if an app keeps failing with a 407 error.
VPNs, Ethernet and other users
The manual proxy applies to your Windows user account on every network you join, Wi-Fi or Ethernet. A VPN connection is the exception: it has its own proxy setting under Network & internet > VPN, the connection’s Advanced options, then Proxy settings for this VPN connection. While the VPN is connected, that setting wins.
Other Windows users on the same PC have their own proxy settings and aren’t affected by yours. If your work PC is managed by a company, group policy may lock or overwrite the proxy page, which shows as greyed-out switches; ask your IT team before changing it.
If the authorized IP is your home connection and it changes, every proxied app stops at once. Authorize a free dynamic DNS hostname (No-IP or similar) instead of the raw IP, or run the work on a VPS with a fixed IP.
Common errors and fixes
curl.exe -x.HTTP_PROXY variables, or route it with Proxifier.netsh winhttp show proxy, then netsh winhttp set proxy or import proxy source=ie as administrator.407 Proxy Authentication Required in appsWindows can’t pass a username and password for most apps. Use IP authorization on dedicated proxies; rotating and residential gateways don’t send a 407 for an unauthorized IP (they reset the connection), so a 407 there comes from another proxy in the chain. See proxy error 407.FAQ
Does the Windows proxy setting apply to all browsers?
Edge and Chrome follow it. Firefox follows it only when set to Use system proxy settings; otherwise it uses its own Connection Settings.
How do I check if a proxy is on in Windows from the command line?
Run the Get-ItemProperty command above to see ProxyEnable and ProxyServer for your user, and netsh winhttp show proxy for the services proxy. Invoke-RestMethod https://api.ipify.org shows the IP the internet sees.
What is the difference between the Settings proxy and netsh winhttp?
The Settings app stores a per-user proxy that browsers and desktop apps read. WinHTTP is a separate machine-wide setting used by services and some system components. Setting one doesn’t change the other unless you import it.
Can I enter a Storm proxy username and password in Windows?
Rotating and residential plans have no username or password at all: you authorize the PC’s public IP in the member area. Private dedicated proxies offer user:pass, but Windows has no field for it, so IP authorization is easier there too.
Which Storm plan fits a whole-PC proxy?
A rotating plan with enough threads for every app on the machine, usually 40 or 80, on the 15-minute gateway. Bandwidth is unlimited on every plan, so updates and downloads don’t cost extra, but they do take threads while they run.
How do I turn the proxy off in Windows?
Go back to Network & internet > Proxy, open Edit next to Use a proxy server and switch it off, then Save. If you set WinHTTP, also run netsh winhttp reset proxy as administrator.
Still have questions? Contact us here. A real person answers.
Related guides
Tool facts checked against the official documentation (October 2026): Microsoft: Use a proxy server in Windows · Microsoft Learn: netsh winhttp. Storm Proxies facts: our plans page and refund policy.
Unlimited bandwidth. One flat monthly price.
Access is live the moment you pay, and the smallest package of each proxy type has a 24-hour money-back guarantee on your first order.