# Web Filtering Last Updated On: 24 Jul 2026 6 minutes read Block malicious and non-work-related sites, and control access by category, site, or time window. ## About Web Filtering A network-level control for what employees can reach in the browser. ### What it does **Web filtering** manages user access to enterprise-approved websites based on pre-determined security policies. It can enforce internet usage policies, block malicious sites, or restrict non-work-related content, and is typically implemented at the network level to improve productivity and security. ## Benefits of Web Filtering A single control point for security, compliance, and productivity. ### What it protects against Web filtering protects networks from threats, helps ensure compliance with regulations like HIPAA and GDPR, improves employee focus by blocking non-work-related sites during work hours, optimizes network performance, mitigates legal risks, and safeguards sensitive data by blocking unauthorized file-sharing sites. Endpoint Central MSP's web filter helps prevent malware, improves productivity, and ensures security — letting IT admins control downloads, set browsing times, block harmful sites, manage policies centrally, and protect remote workers. ## Implementing Web Filtering Turn on the built-in threat protections, then layer time- and category-based access rules on top. ### Create a policy and enable threat protections 1. Go to **Browsers → Policies → Web Filter**. 2. Click **Create Policy** and name the policy. 3. Enable **Block Malicious Websites** to block access to malware sites. 4. Enable **SSL certificate protection** to ensure SSL certificate encryption. 5. Enable **Restrict over-riding SSL certificate errors** to stop users from ignoring or bypassing invalid/untrusted SSL certificate warnings. 6. Enable **Block third party websites that inject code** to stop pages from loading external content that could inject malicious code. 7. Enable **Block websites with excessive ads** to prevent access to sites with an excessive amount of advertising. ![Web Filter toggles for malicious sites, SSL protection, and ad-heavy sites.](https://www.manageengine.com/products/desktop-central/help/images/web-filter-1.png) Enabling the core web filter protections. ### Filtering by category, site, and time window **URL Filter** controls website access based on specific time intervals. Allow or block access using AI-classified categories — Education, News, Entertainment, and so on — or by specifying individual websites or [website groups](https://www.manageengine.com/desktop-management-msp/help/browser-security/create-web-groups.html#website-groups). Access time windows are specified in HH:MM:SS format. **Override Category Restriction** lets a blocked domain within a category be overridden; every such request is [recorded under Web Activity](https://www.manageengine.com/desktop-management-msp/help/browser-security/enterprise-browser-visibility.html#category-approval-for-url-filter) in the Insights tab. While configuring website groups, specific sites can also be excluded from filtering with **Define exclusion list for URL filter**. **Note:** The Web Category feature is currently in closed beta — reach out to [msp-endpointcentral-support@manageengine.com](mailto:msp-endpointcentral-support@manageengine.com) for access. See [web category based filtering](https://www.manageengine.com/desktop-management-msp/help/browser-security/web-category.html) for more. ![URL Filter settings for category, site, and time-based access.](https://www.manageengine.com/products/desktop-central/help/images/web-filter-2.png) Configuring URL Filter access rules. ### Customizing the block page and deploying The message and logo shown on blocked pages can be customized, or the page can redirect elsewhere entirely. **Allow users to contact admin from a blocked page** lets end users send mail to the administrator directly from that page. ![Block page customization settings.](https://www.manageengine.com/products/desktop-central/help/images/web-filter-3.png) Customizing the block page. 1. Click **Save & Publish** to save the policy. 2. [Deploy](https://www.manageengine.com/desktop-management-msp/help/browser-security/policy-deployment.html) the policy with the computers or groups where web-application access should be restricted. **Note:** The web filter policy isn't supported in Incognito mode or Guest mode. Incognito mode can be disabled under **Policies → Browser Customization → Security Restriction → Disable Incognito Policy**, and Guest mode under **Policies → Browser Customization → User Account Settings → Allow users to use guest mode**. ## Related - [Creating Website Groups](https://www.manageengine.com/desktop-management-msp/help/browser-security/create-web-groups.html) - [Web Category Based Filtering](https://www.manageengine.com/desktop-management-msp/help/browser-security/web-category.html) - [Enterprise Browser Visibility & Insights](https://www.manageengine.com/desktop-management-msp/help/browser-security/enterprise-browser-visibility.html) - [Policy Deployment](https://www.manageengine.com/desktop-management-msp/help/browser-security/policy-deployment.html) - [Browser Security FAQ](https://www.manageengine.com/desktop-management-msp/help/browser-security/browser-faq.html#restrictfaq)