4

Gateway Policies

SL-11

What the browser inspects and how it enforces. Reliance on user awareness or static blocklists is insufficient where attackers use deception and impersonation — which is why every policy here inspects the page rather than the address.

DischargesS.8(4)R.6S.16
Policies
4
Enabled
4
Blocks (30 days)
564
Bypassable
1

All require approval

Configured policies

Block deceptive and impersonating sitesAll managed browsers

Inspects the rendered page rather than the URL alone, follows every redirect, and applies computer vision and language analysis to detect impersonation.

186
30-day blocks
  • Inspects the rendered page
    Analyses what the user actually sees, not the URL. Catches replicas that are visually identical to the real service.
  • Follows the redirect chain
    Resolves every hop to the final destination, defeating URL-rewriting abuse and chained trusted domains.
  • Computer vision and OCR
    Detects official emblems, logos and credential-harvesting layouts on domains that have no business displaying them.
  • Language analysis
    Identifies social-engineering phrasing and fake security or government notices, including AI-generated copy.
  • Classification-aware
    Recognises when a form is requesting data types mapped to regulated datasets, and raises enforcement accordingly.
  • Blocks data entry
    Stops the submission itself, not just navigation to the page.
Prevent personal data entry into untrusted sitesAll managed browsers

Uses Discovery classification to recognise regulated data types. Blocks submission when a user is about to enter classified personal data into an untrusted or newly seen site.

44
30-day blocks
  • Inspects the rendered page
    Analyses what the user actually sees, not the URL. Catches replicas that are visually identical to the real service.
  • Follows the redirect chain
    Resolves every hop to the final destination, defeating URL-rewriting abuse and chained trusted domains.
  • Computer vision and OCR
    Detects official emblems, logos and credential-harvesting layouts on domains that have no business displaying them.
  • Language analysis
    Identifies social-engineering phrasing and fake security or government notices, including AI-generated copy.
  • Classification-aware
    Recognises when a form is requesting data types mapped to regulated datasets, and raises enforcement accordingly.
  • Blocks data entry
    Stops the submission itself, not just navigation to the page.
Elevated protection for privileged usersPrivileged and previously compromised identities

Raises enforcement severity for privileged identities and for identities previously flagged by Access Assurance.

22
30-day blocks
  • Inspects the rendered page
    Analyses what the user actually sees, not the URL. Catches replicas that are visually identical to the real service.
  • Follows the redirect chain
    Resolves every hop to the final destination, defeating URL-rewriting abuse and chained trusted domains.
  • Computer vision and OCR
    Detects official emblems, logos and credential-harvesting layouts on domains that have no business displaying them.
  • Language analysis
    Identifies social-engineering phrasing and fake security or government notices, including AI-generated copy.
  • Classification-aware
    Recognises when a form is requesting data types mapped to regulated datasets, and raises enforcement accordingly.
  • Blocks data entry
    Stops the submission itself, not just navigation to the page.
Block unsanctioned AI servicesAll managed browsersBypass with approval

Prevents access to consumer AI services from managed browsers, working with the AI Processing Guard.

312
30-day blocks
  • Inspects the rendered page
    Analyses what the user actually sees, not the URL. Catches replicas that are visually identical to the real service.
  • Follows the redirect chain
    Resolves every hop to the final destination, defeating URL-rewriting abuse and chained trusted domains.
  • Computer vision and OCR
    Detects official emblems, logos and credential-harvesting layouts on domains that have no business displaying them.
  • Language analysis
    Identifies social-engineering phrasing and fake security or government notices, including AI-generated copy.
  • Classification-aware
    Recognises when a form is requesting data types mapped to regulated datasets, and raises enforcement accordingly.
  • Blocks data entry
    Stops the submission itself, not just navigation to the page.

On the block page

When a site is blocked the user sees a clear explanation of the risk rather than a generic network error, and the security team gets a safe preview of the blocked content. Users cannot bypass protection without authorisation — which matters, because the population most likely to try are the ones already being targeted.