In the Group Policy Editor -
Computer Configuration > Administrative Templates > Network > Network
Connections > Windows Firewall. In Domain Profile, set "Windows Firewall:
Protect all network connections" to Disabled.
I would strongly suggest that you don't do this for the Standard Profile.
If you do, laptops that get taken away from your network will be unprotected.
There are other ways to do this, such as 2 levels up from the above you can
choose to disable it on your domain. But as it says in the explanation for
the above setting, this is the only way to make sure it stays off.