Policy Exceptions
Navigate to the sidebar menu: Protection > Policies, open a Standard Policy and select the Exceptions tab in the top navigation bar.
Overview
The Exceptions module serves as the final authority in your filtering hierarchy. It allows you to assign specific Allow Lists (Whitelists) or Block Lists (Blacklists) to override the general rules set in the Malware, Content, or Application modules.
- Example: You can block the entire "Social Networks" category in the Content tab but add a specific Exception to allow access to LinkedIn for the HR department.
Interface Overview
The interface is designed to manage the link between your policy and your custom domain lists.
Interface Element | Focus & Description |
|---|---|
Search Bar | Located at the top left. Allows you to quickly find a specific exception group already assigned to this policy. |
+ Assign exception groups | The blue + Assign exception groups button allows you to attach a new list to this policy. |
List View | Once groups are assigned, they will appear in the main area below the search bar (currently empty in the view). |
Understanding Exception Types
Exceptions are managed via "Groups" (lists of domains). Use this table to understand the two main types of overrides you can apply.
Exception Type | Function & Priority |
|---|---|
Allow List (Whitelist) | Domains in this list are always accessible, even if they fall under a blocked category (e.g., Malware or Social Networks). This is primarily used to fix False Positives or grant specific access. |
Block List (Blacklist) | Domains in this list are always blocked, even if the category they belong to is generally allowed. This is used to block specific unwanted sites without restricting the entire category. |
Subdomains and CDNs When adding exceptions, remember that modern websites often load content from multiple sources:
- Subdomains: Ensure you consider whether you need to allow just example.com or also drive.example.com.
- CDNs: Many sites host images and scripts on external domains (e.g., cdn-provider.net). If a Whitelisted site appears "broken" (missing images or styles), check if you need to allow its CDN domains as well.
Configuration & Logic
This page is used solely to link existing groups to the current policy.
- To Assign a Group: Click the + Assign exception groups button. This will open a dedicated selection window.
- To Create/Edit Groups: The actual lists of domains are managed in the global settings.
Managing Groups Clicking the Assign button opens a separate interface for selecting and managing your custom lists: New exception