I'm pretty sure the windows defaults will be left alone. Your problem is that some programs add themselves to the exception list when they are installed. There is no way to know which programs those were until you actually try to run them and they fail to access the internet/network. At that point, you can either manually add them back into the exceptions list or reinstall the program.