Domain Blocking
Configure which domains are blocked by the Browser Guard.
Overview
The Browser Guard blocks access to domains known for data exfiltration. Domains are managed via the policy's browser guard configuration.
Default Blocked Domains
BlueSentinel ships with 35+ pre-configured blocked domains:
Cloud Storage:
- drive.google.com
- dropbox.com
- onedrive.live.com
- mega.nz
- wetransfer.com
- box.com
Code Sharing:
- pastebin.com
- hastebin.com
- gist.github.com (file uploads)
AI Tools:
- chat.openai.com (ChatGPT)
- claude.ai
- bard.google.com
Messaging:
- web.whatsapp.com
- web.telegram.org
- discord.com
- slack.com (file uploads)
Social Media:
- facebook.com (file sharing)
- twitter.com
- linkedin.com
Adding Custom Domains
- Navigate to Policies → select your policy
- Edit the Browser Guard section
- Add domains to the Blocked Domains list
- Save — changes push to agents on next heartbeat
Domain Matching
Domains are matched by suffix. Blocking dropbox.com also blocks:
www.dropbox.comdl.dropbox.comcontent.dropbox.com
Per-User Exceptions
If specific users need access to a blocked domain:
- Navigate to Exceptions
- Create a whitelist exception for the Browser Guard
- Add the allowed domains
- Set an optional time window (e.g., allow for 24 hours)