Control website access
Use URL block and allow policies for basic website access control. Use a secure web gateway, DNS filter, proxy, or approved extension when you need content inspection or category-based filtering.
Choose a model
| Goal | URL blocklist | URL allowlist |
|---|---|---|
| Allow most sites and block a few | Add only prohibited patterns | Add narrow exceptions when required |
| Allow only approved sites | Add * | Add every approved pattern and required dependency |
The most specific matching rule determines the result, and an allowlist entry is an exception to the blocklist.
Configure user or browser access
- Open Business+ → User Settings.
- Select a pilot organisational unit.
- Search for URL blocklist and URL allowlist.
- Enter one reviewed pattern per line in the matching fields.
- Check Updated setting entries.
- Click Save.
- Sign in on a pilot device and test the intended sites.
For a managed guest session, make the equivalent change under Business+ > Managed Guest Session Settings. Kiosk URL controls are under Kiosk > Settings.
Pattern examples
| Requirement | Example |
|---|---|
| Block every URL | * |
| Match a domain and subdomains | [*.]example.com |
| Match one HTTPS host | https://portal.example.com |
| Match a path | https://example.com/private/* |
| Block view-source access | view-source:* |
Test patterns against your deployed FydeOS version. Do not assume a bare domain automatically covers every scheme, subdomain, port, and path.
Allow-only deployment checklist
Before applying *, allow:
- The sign-in and identity services users require.
- Management Cloud, policy, update, certificate, and time services.
- App origins, APIs, content delivery networks, and authentication redirects.
- Proxy or captive portal pages.
- Support and remote-access services approved by your organisation.
Start with a dedicated pilot unit. Keep an administrator recovery path outside the allow-only policy until the device has completed sign-in, policy sync, restart, and normal work.
Troubleshooting
- Confirm whether the setting belongs to user, managed guest, or kiosk scope.
- Check the device and user organisational units separately.
- Look for a broader
*block and a missing dependency or redirect host. - Check URL scheme, subdomain, port, and path.
- Check proxy, DNS, Safe Browsing, extension, and certificate policies.
- Restore the previous blocklist and allowlist if management or sign-in access is affected.
URL lists are basic access controls, not a substitute for malware scanning, data loss prevention, or a complete web security service.
What's next
- Manage apps and extensions, choose the target and installation mode.
- App permissions and sources, control what managed apps can install or access.
- Configure user policies, apply related browser settings.