All require approval
Configured policies
Inspects the rendered page rather than the URL alone, follows every redirect, and applies computer vision and language analysis to detect impersonation.
- Inspects the rendered pageAnalyses what the user actually sees, not the URL. Catches replicas that are visually identical to the real service.
- Follows the redirect chainResolves every hop to the final destination, defeating URL-rewriting abuse and chained trusted domains.
- Computer vision and OCRDetects official emblems, logos and credential-harvesting layouts on domains that have no business displaying them.
- Language analysisIdentifies social-engineering phrasing and fake security or government notices, including AI-generated copy.
- Classification-awareRecognises when a form is requesting data types mapped to regulated datasets, and raises enforcement accordingly.
- Blocks data entryStops the submission itself, not just navigation to the page.
Uses Discovery classification to recognise regulated data types. Blocks submission when a user is about to enter classified personal data into an untrusted or newly seen site.
- Inspects the rendered pageAnalyses what the user actually sees, not the URL. Catches replicas that are visually identical to the real service.
- Follows the redirect chainResolves every hop to the final destination, defeating URL-rewriting abuse and chained trusted domains.
- Computer vision and OCRDetects official emblems, logos and credential-harvesting layouts on domains that have no business displaying them.
- Language analysisIdentifies social-engineering phrasing and fake security or government notices, including AI-generated copy.
- Classification-awareRecognises when a form is requesting data types mapped to regulated datasets, and raises enforcement accordingly.
- Blocks data entryStops the submission itself, not just navigation to the page.
Raises enforcement severity for privileged identities and for identities previously flagged by Access Assurance.
- Inspects the rendered pageAnalyses what the user actually sees, not the URL. Catches replicas that are visually identical to the real service.
- Follows the redirect chainResolves every hop to the final destination, defeating URL-rewriting abuse and chained trusted domains.
- Computer vision and OCRDetects official emblems, logos and credential-harvesting layouts on domains that have no business displaying them.
- Language analysisIdentifies social-engineering phrasing and fake security or government notices, including AI-generated copy.
- Classification-awareRecognises when a form is requesting data types mapped to regulated datasets, and raises enforcement accordingly.
- Blocks data entryStops the submission itself, not just navigation to the page.
Prevents access to consumer AI services from managed browsers, working with the AI Processing Guard.
- Inspects the rendered pageAnalyses what the user actually sees, not the URL. Catches replicas that are visually identical to the real service.
- Follows the redirect chainResolves every hop to the final destination, defeating URL-rewriting abuse and chained trusted domains.
- Computer vision and OCRDetects official emblems, logos and credential-harvesting layouts on domains that have no business displaying them.
- Language analysisIdentifies social-engineering phrasing and fake security or government notices, including AI-generated copy.
- Classification-awareRecognises when a form is requesting data types mapped to regulated datasets, and raises enforcement accordingly.
- Blocks data entryStops the submission itself, not just navigation to the page.
On the block page
When a site is blocked the user sees a clear explanation of the risk rather than a generic network error, and the security team gets a safe preview of the blocked content. Users cannot bypass protection without authorisation — which matters, because the population most likely to try are the ones already being targeted.