Skip to main content

Control website access

Use URL block and allow policies for basic website access control. Use a secure web gateway, DNS filter, proxy, or approved extension when you need content inspection or category-based filtering.

Choose a model​

GoalURL blocklistURL allowlist
Allow most sites and block a fewAdd only prohibited patternsAdd narrow exceptions when required
Allow only approved sitesAdd *Add every approved pattern and required dependency

The most specific matching rule determines the result, and an allowlist entry is an exception to the blocklist.

Configure user or browser access​

  1. Open Business+ → User Settings.
  2. Select a pilot organisational unit.
  3. Search for URL blocklist and URL allowlist.
  4. Enter one reviewed pattern per line in the matching fields.
  5. Check Updated setting entries.
  6. Click Save.
  7. Sign in on a pilot device and test the intended sites.

For a managed guest session, make the equivalent change under Business+ > Managed Guest Session Settings. Kiosk URL controls are under Kiosk > Settings.

Pattern examples​

RequirementExample
Block every URL*
Match a domain and subdomains[*.]example.com
Match one HTTPS hosthttps://portal.example.com
Match a pathhttps://example.com/private/*
Block view-source accessview-source:*

Test patterns against your deployed FydeOS version. Do not assume a bare domain automatically covers every scheme, subdomain, port, and path.

Allow-only deployment checklist​

Before applying *, allow:

  • The sign-in and identity services users require.
  • Management Cloud, policy, update, certificate, and time services.
  • App origins, APIs, content delivery networks, and authentication redirects.
  • Proxy or captive portal pages.
  • Support and remote-access services approved by your organisation.

Start with a dedicated pilot unit. Keep an administrator recovery path outside the allow-only policy until the device has completed sign-in, policy sync, restart, and normal work.

Troubleshooting​

  • Confirm whether the setting belongs to user, managed guest, or kiosk scope.
  • Check the device and user organisational units separately.
  • Look for a broader * block and a missing dependency or redirect host.
  • Check URL scheme, subdomain, port, and path.
  • Check proxy, DNS, Safe Browsing, extension, and certificate policies.
  • Restore the previous blocklist and allowlist if management or sign-in access is affected.

URL lists are basic access controls, not a substitute for malware scanning, data loss prevention, or a complete web security service.

What's next​