# Download & Upload Restriction Last Updated On: 24 Jul 2026 4 minutes read Block or condition file downloads and uploads through the browser to keep transfers to trusted sources. ## Why file activity needs restricting Malicious sites push harmful downloads; uncontrolled uploads leak data the other way. ### The risk of unrestricted file activity Restricting file activities such as downloads and uploads from untrusted websites is essential to safeguarding computers and sensitive data. Malicious websites often host harmful files — viruses, malware, ransomware — that can compromise systems, steal confidential information, or cause operational disruptions. Uncontrolled uploads can equally lead to accidental or intentional data leakage. These incidents can result in data loss, financial fraud, compliance violations, and other serious consequences. Enforcing file activity restrictions significantly reduces the risk of cyberattacks and data exfiltration. ## Restricting browser file activities Block downloads and uploads outright, or condition them on domain, size, type, or time. ### Create a File Activity Restriction policy 1. Go to **Browsers → Policies → File Activity Restriction**. 2. Click **Create Policy**. 3. Go to the respective section to restrict downloads or uploads. 4. Click **Yes** against **Block Downloads** or **Block Uploads** to block all downloads or uploads respectively. ![Download Restriction settings screen.](https://www.manageengine.com/products/desktop-central/help/images/browser-download-restriction.png) *Configuring download restriction.* ![Upload Restriction settings screen.](https://www.manageengine.com/products/desktop-central/help/images/browser-upload-restriction.png) *Configuring upload restriction.* ### Restricting based on specific conditions Instead of blocking everything, downloads and uploads can be restricted based on conditions — a transfer is blocked if any or all of the specified conditions are met. - **Web Domains/URLs** — the tab URL or the download URL. - **Web Groups** — any web groups already created. - **File Size** — specified in bytes (e.g. 4KB = 4000 bytes). - **File Types** — specified as file extensions (e.g. .pdf, .exe). - **Time Limit** — specified in 24-hour format (e.g. 10:00:00). Specific items can be excluded from the restriction by listing them in the **Exclusion List**. ### Customizing the block page The block page shown to users can use the default message or a customized message and logo, with an option to let users contact the administrator directly from that page. ![Block page appearance customization screen.](https://www.manageengine.com/products/desktop-central/help/images/block-page-appearance.png) *Customizing the block page.* [Deploy](https://www.manageengine.com/desktop-management-msp/help/browser-security/policy-deployment.html) the policy with the computers or groups it should apply to. **Note** The file activity restriction policy isn't supported in Incognito mode or Guest mode. Incognito mode can be disabled under **Policies → Browser Customization → Security Restriction → Disable Incognito Policy**, and Guest mode under **Policies → Browser Customization → User Account Settings → Allow users to use guest mode**. ## Related - [Browser Security Overview](https://www.manageengine.com/desktop-management-msp/help/browser-security/browser-overview.html) - [Policy Deployment](https://www.manageengine.com/desktop-management-msp/help/browser-security/policy-deployment.html)