We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft security
  2. Web content filtering
Web content filtering, UAE

You probably already own this. It needs two features switched on and a policy nobody has written.

Web content filtering is part of Defender for Endpoint web protection and reaches devices wherever they are, on the network or away from it. It requires SmartScreen and network protection to be enabled, and most tenants have one of the two.

Book a web filtering reviewSee how it works
Defender for Endpoint web content filtering for UAE organisations
  • 5 categoriesParent groups you can block or audit
  • Auto auditedEvery category you do not block
  • 2 hoursMaximum latency before a policy applies
  • On or off networkEnforcement follows the device
What web content filtering does

Eight things that determine whether it works as intended.

The feature is straightforward to enable and has several documented limitations that decide how much you can rely on it. Knowing them up front is the difference between a control you trust and one that quietly does less than you think.

Category-based control that follows the device

Policies block selected content categories across device groups, and users are prevented from reaching those sites whether they are browsing on-premises or away. That mobility is the main advantage over network-level filtering, which stops applying the moment somebody leaves the office.

Everything you do not block is audited automatically

For any category that is not blocked, the URLs are automatically audited. Users access them without disruption and you gather access statistics. That means visibility is free even before you decide to block anything, which makes an audit-first approach genuinely easy.

Two features have to be on

Windows Defender SmartScreen and network protection must both be enabled on your devices. SmartScreen performs the block in Microsoft Edge and network protection performs it in Chrome, Firefox, Brave and Opera. If either is off, coverage is partial rather than absent, which is harder to notice.

Browser coverage, and the experience difference

Supported browsers are Edge, Chrome, Firefox, Brave, Opera and Internet Explorer. In third-party browsers the block is a system-level message from network protection rather than an in-browser page. Microsoft suggests Edge for a more user-friendly experience, which is a real difference to users.

Most restrictive policy wins

Applying multiple policies to the same device results in the more restrictive policy applying for each category. A policy blocking two categories and another blocking two different ones results in all four being blocked. That is predictable and it surprises people who expected a precedence order.

The Uncategorized category is not what it sounds like

It contains only newly registered domains and parked domains, not everything outside the other categories. Microsoft warns directly that blocking Uncategorized could lead to unexpected and undesired results, and newly registered means registered within the past 30 days.

Allow indicators override everything

A custom allow indicator supersedes the web content filtering policy, which is how you permit one site inside a blocked category. It is also the recommended route for faster manual unblocking, since disputing a category takes up to one business day for review.

Reporting that needs time to become useful

Web activity by category covers the last 30 days, three months or six months. Microsoft notes that in the first 30 days of use your organisation might not have enough data to display that card at all, so the first month is a collection period rather than a reporting one.

Where the coverage genuinely stops

A local proxy application masks the process name, and filtering stops working.

Microsoft documents this alongside three other limitations, and together they define the honest boundary of what this control delivers.

  • Web content filtering is restricted to specific browsers by process name, so it does not work when a local proxy application such as a debugging proxy is in place, because the originating process name is masked. It also does not function in isolated browser sessions.
  • Because full URLs are not available in third-party browsers, blocking access to certain web applications may require a custom block indicator for the application login page. Microsoft cautions that such a block might also stop users reaching other services associated with the same website.
  • Categorisation is a continuous, imperfect process. Microsoft classifies billions of URLs, new sites are added daily and may not be categorised immediately, and a site category may change at any time. For full control over access to a specific site, a custom indicator is the reliable answer rather than the category.
  • Finally, licensing shapes design. On Microsoft 365 Business Premium or Defender for Business you can define only a single web content filtering policy for the environment, which rules out different policies for different device groups and makes the single policy a compromise by construction.
Ask us to scope this against your estate
How we approach it

Four things that make this land without a fight.

Web filtering is the security control most likely to become a workplace argument, because it touches what people do all day. Handling it as a business decision supported by data avoids most of that.

We audit before we block, because it is free

Every category you do not block is audited automatically, and a policy with no categories selected creates an audit-only policy explicitly. A month of that produces evidence, and evidence turns a contested policy decision into a short conversation with numbers in it.

We verify both prerequisites across the whole estate

SmartScreen performs the block in Edge and network protection performs it in Chrome, Firefox, Brave and Opera. Where one is missing on a subset of devices, filtering is partial in a way that reporting does not make obvious. Verification per device group takes an hour and prevents a false sense of coverage.

We keep Uncategorized out of the block list

Microsoft warns that blocking Uncategorized could lead to unexpected and undesired results, and the category contains only newly registered and parked domains rather than everything unclassified. Organisations block it expecting a catch-all and get unpredictable breakage instead.

We set up the exception route before enforcement

Custom allow indicators supersede the web content filtering policy and are the recommended route for fast unblocking, since a category dispute takes up to a business day to review. Having that route staffed before day one is what keeps a legitimate block from becoming an escalation.

How a deployment runs

Four phases across roughly six to eight weeks.

The audit period sets the length. Because unblocked categories are audited automatically, that period costs nothing and produces the data that makes the blocking decision defensible.
  1. 01
    Week 1

    Confirm the prerequisites are genuinely in place

    SmartScreen and network protection both enabled across the estate, the web content filtering toggle on in advanced features, and device groups defined. Partial prerequisite coverage produces partial filtering, which is worse than none because it looks complete.

    • SmartScreen state verified per device group
    • Network protection state verified per device group
    • Web content filtering enabled in advanced features
    • Device groups defined for policy scoping
  2. 02
    Weeks 2 to 5

    Audit first, deliberately

    A policy with no categories selected creates an audit-only policy, and every unblocked category is audited anyway. Four weeks of that produces real usage data, and Microsoft notes the by-category card may not have enough data to display in the first 30 days.

    • Audit-only policy deployed
    • Usage data collected across a full month
    • Category activity reviewed with the business
    • Candidate blocks identified from evidence
  3. 03
    Week 6

    Decide blocks with the business, not for it

    Legal liability categories are usually uncontroversial. Leisure and high bandwidth are policy decisions that belong with HR and leadership rather than with IT, and the audit data is what makes that conversation short.

    • Block list agreed with named business owners
    • Uncategorized decision recorded, with the warning understood
    • Allow indicator process defined for exceptions
    • Dispute route documented for miscategorisation
  4. 04
    Weeks 7 to 8

    Enforce and set expectations

    Policies applied with up to two hours of latency before enforcement, users told what to expect including the difference between the Edge experience and the system message in other browsers, and a route for requesting an exception.

    • Block policies applied per device group
    • User communication issued covering both block experiences
    • Exception request route live with an owner
    • Reporting reviewed and handed over
Where this applies

Six situations where category filtering earns its place.

The strongest case is an organisation with mobile devices and an existing Defender licence, which describes a large share of UAE businesses.

A business whose staff work away from the office

Network appliance filtering stops applying the moment a laptop leaves the building, which for hybrid working is most of the week. Endpoint filtering follows the device, and Microsoft states users are prevented from accessing blocked categories whether browsing on-premises or away.

A regulated firm managing legal liability exposure

The legal liability parent category covers criminal activity, hacking, illegal drugs, illegal software and weapons, and blocking it is rarely controversial internally. It is the category most likely to appear in a policy document and least likely to already be enforced.

A school or university with duty of care obligations

Education estates have both a policy requirement and a safeguarding one, and devices frequently go home. Adult content and self-harm related categories are the driver, and the audit-first approach gives the evidence base for a decision that has to be defensible to parents.

An operator managing bandwidth at remote sites

The high bandwidth parent category covers streaming media, downloads, image sharing and peer to peer. At sites with constrained links, blocking or auditing that category has an operational benefit that is easier to justify than a purely policy-driven block.

An organisation trying to stop proxy and tunnel use

Remote proxy sites are categorised as Illegal Software specifically because they can route traffic to any destination, including unwanted or malicious content. Organisations that want to stop staff bypassing controls frequently do not realise this is already handled by a category.

A company that wants visibility before any policy

Because unblocked categories are audited automatically, you can gain full visibility of web activity by category without blocking anything at all. For organisations not ready to make blocking decisions, that is a genuinely useful position to occupy for a while.

Three positions

How UAE organisations control web access.

The middle column is the traditional answer and it has one structural flaw: it stops applying the moment a laptop leaves the office, which is most of the time for many roles.
Applies away from the office
Endpoint web content filteringYes
Network appliance filteringNo
No filteringNot applicable
Category coverage
Endpoint web content filteringFive parent categories
Network appliance filteringVendor dependent
No filteringNone
Unblocked activity visible
Endpoint web content filteringAutomatically audited
Network appliance filteringUsually logged
No filteringNo
Per device group policy
Endpoint web content filteringYes, unless Business plans
Network appliance filteringBy network segment
No filteringNot applicable
Additional hardware
Endpoint web content filteringNone
Network appliance filteringRequired
No filteringNone
Works with a local proxy tool
Endpoint web content filteringNo
Network appliance filteringYes
No filteringNot applicable
Single site exceptions
Endpoint web content filteringAllow indicators
Network appliance filteringVendor dependent
No filteringNot applicable
Block experience quality
Endpoint web content filteringBest in Edge
Network appliance filteringConsistent
No filteringNot applicable
Data residency controlled
Endpoint web content filteringBy Defender data handling region
Network appliance filteringOn premises
No filteringNot applicable
Likely already licensed
Endpoint web content filteringOften yes
Network appliance filteringSeparate purchase
No filteringNot applicable
Feature
Endpoint web content filtering
Network appliance filtering
No filtering
Applies away from the office
YesNoNot applicable
Category coverage
Five parent categoriesVendor dependentNone
Unblocked activity visible
Automatically auditedUsually loggedNo
Per device group policy
Yes, unless Business plansBy network segmentNot applicable
Additional hardware
NoneRequiredNone
Works with a local proxy tool
NoYesNot applicable
Single site exceptions
Allow indicatorsVendor dependentNot applicable
Block experience quality
Best in EdgeConsistentNot applicable
Data residency controlled
By Defender data handling regionOn premisesNot applicable
Likely already licensed
Often yesSeparate purchaseNot applicable
The category structure

Five parent categories and what each is genuinely for.

Most organisations block on legal liability grounds and audit the rest. The Uncategorized row is the one to read carefully before enabling anything.
Parent categoryTypical intent
Legal liabilityThe clearest block case, covering criminal activity, hacking, illegal drugs and weapons
Adult contentCommonly blocked on workplace policy grounds
High bandwidthStreaming, downloads and peer to peer, frequently audited rather than blocked
LeisureSocial, chat, games and web mail, usually a policy decision rather than a security one
UncategorizedOnly newly registered and parked domains, and blocking it may cause undesired results
Remote proxy sitesCategorised as Illegal Software, because they can route traffic anywhere
Newly registered domainsRegistered within the past 30 days and not yet moved to another category
Anything not blockedAutomatically audited, so visibility comes at no cost
A specific site inside a blocked categoryPermit with a custom allow indicator, which supersedes the policy
A miscategorised domainDispute in the portal, reviewed within one business day
How an engagement runs

Five steps, and the audit month does most of the work.

Configuration is quick. The value is in arriving at the blocking decision with data, and in setting expectations before enforcement rather than after.
  1. 1

    Verify prerequisites and enable the feature

    SmartScreen and network protection confirmed enabled across every device group, not assumed, since one performs Edge blocks and the other performs blocks in Chrome, Firefox, Brave and Opera. Then the web content filtering toggle in advanced features.

  2. 2

    Deploy an audit-only policy and wait

    A policy with no categories selected creates an audit-only policy, and unblocked categories are audited regardless. A month of data, noting that in the first 30 days the by-category report card may not have enough data to display.

  3. 3

    Take the data to the business

    Legal liability categories are usually an easy decision. Leisure and high bandwidth are workplace policy questions that belong with HR and leadership, and a conversation with actual usage numbers is much shorter than one without.

  4. 4

    Apply blocks and communicate both experiences

    Policies applied with up to two hours of latency before enforcement, and users told what a block looks like. In Edge it is an in-browser page. In other supported browsers it is a system-level message from network protection, which people find more confusing.

  5. 5

    Operate the exception and dispute routes

    Custom allow indicators for sites that must be reachable inside a blocked category, since they supersede the policy, and the portal dispute route for genuine miscategorisation, reviewed within one business day. Both need an owner before enforcement begins.

Straight answers

What organisations ask about web content filtering.

Quite possibly. It is included with Defender for Endpoint Plan 1 and Plan 2, Defender for Business, Microsoft 365 Business Premium, Microsoft 365 E3 and E5, Windows Enterprise E5 and the education equivalents. Many organisations own it and have never enabled it.

Windows Defender SmartScreen and network protection must both be enabled on your devices. SmartScreen performs the block in Microsoft Edge and network protection performs it in Chrome, Firefox, Brave and Opera. If one is missing on some devices, coverage is partial in a way that is easy to miss.

Yes, and that is the main advantage over appliance-based filtering. Users are prevented from accessing websites in blocked categories whether they are browsing on-premises or away, because enforcement happens on the endpoint rather than at a network boundary.

Yes, and it costs nothing. For any category that is not blocked the URLs are automatically audited, and you can also deploy a policy with no categories selected to create an explicitly audit-only policy. It is the right way to start.

Generally no. Microsoft warns directly that blocking it could lead to unexpected and undesired results, and it is not a catch-all: it contains only newly registered domains, meaning registered within the past 30 days, and parked domains, not every site outside the other categories.

The more restrictive policy applies for each category. Microsoft gives the example of one policy blocking two categories and another blocking two different ones, with the result that all four are blocked. There is no precedence order to reason about, which is simpler than it sounds.

A custom allow indicator, which supersedes the web content filtering policy. It is also the recommended route for fast unblocking, since disputing a category in the portal is reviewed within one business day and the indicator takes effect without waiting for that.

It depends on the browser. In Microsoft Edge the experience is an in-browser block page. In third-party supported browsers the block comes from network protection as a system-level message, which users find less clear. Microsoft suggests Edge for a more user-friendly experience.

There might be up to two hours of latency between creating a policy and it being enforced on the device. Worth knowing during testing, because a policy that appears not to work may simply not have arrived yet.

Yes, and they are documented. It is restricted to specific browsers by process name, so it does not work where a local proxy application masks the originating process name, and it does not function in isolated browser sessions. Those are hard boundaries rather than configuration issues.

Because full URLs are not available in third-party browsers, so blocking a particular web application may require a custom block indicator for its login page. Microsoft cautions that such a block might also prevent access to other services associated with the same website.

Dispute it in the portal, under web protection reports and the domains tab, where you can suggest a category. The review takes up to one business day. If you need it working sooner, create a custom allow indicator, which is the documented advice for faster manual unblocking.

In the region selected in your Defender for Endpoint data handling settings. Microsoft states the data will not leave the data centre in that region and will not be shared with any third parties, including its own data providers. That answers the usual first question from a compliance team.

For policy design, yes. On Microsoft 365 Business Premium or Defender for Business you can define only a single web content filtering policy for the environment, which means no per-device-group differentiation and a single policy that has to suit everybody.

We scope by estate size and whether the prerequisites are already in place. The free first step: check whether SmartScreen and network protection are enabled across your devices. If they are, you can be in audit mode this week at no additional cost.

Not necessarily. Web content filtering is part of the web protection capabilities in both Microsoft Defender for Endpoint and Microsoft Defender for Business, and the subscription list includes Microsoft 365 Business Premium alongside the enterprise plans. Many smaller organisations already hold an entitlement.

In Defender for Endpoint, yes, using device groups defined in role-based access control settings. In Microsoft 365 Business Premium or Defender for Business, no. There you can define only a single web content filtering policy for the environment, applied to all users.

Yes, through the web activity by category card, which lists the parent categories with the largest increase or decrease in access attempts and lets you explore changes over the last 30 days, three months or six months. That trend view is frequently more useful to a business than a point in time count.

Statistical data about web content categories, website domains and device groups, with the ability to filter by time range, customise columns and open a flyout for any row. The domains tab is also where a miscategorised site is disputed, which keeps the workflow in one place.
Before you block anything

Fifteen checks worth completing first.

The first group determines whether the control will work at all. The rest determine whether it will be accepted by the people it applies to.

Prerequisites

  • Is SmartScreen enabled everywhere?
    It performs the Edge block.
  • Is network protection enabled everywhere?
    It performs the block elsewhere.
  • Is the feature toggle on?
    In advanced features.
  • Which browsers do people actually use?
    Six are supported.
  • Do we have Business Premium or Defender for Business?
    Only one policy is allowed.

Design

  • Have we run audit only first?
    It costs nothing.
  • Do we have 30 days of data?
    Reports need it.
  • Who owns the blocking decision?
    Not IT alone.
  • Are we blocking Uncategorized?
    Microsoft warns against it.
  • Do multiple policies overlap?
    Most restrictive wins.

Operation

  • Who approves allow indicators?
    They supersede the policy.
  • Who disputes a miscategorised site?
    One business day to review.
  • Do users know what a block looks like?
    It differs by browser.
  • Are any local proxy tools in use?
    They break filtering.
  • Is anyone reading the reports?
    Monthly is enough.
Related reading

The pages around this one.

Defender for Endpoint

The product web protection belongs to.

Learn more

Attack surface reduction rules

The adjacent endpoint hardening controls.

Learn more

Global Secure Access

The identity-centric approach to network access.

Learn more
Next step

Check whether SmartScreen and network protection are enabled across your devices.

If they are, you can turn on web content filtering and be collecting category data by the end of the week, without blocking anything and without buying anything.

Book a web filtering reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Defender for Endpoint

Business, Plan 1 or Plan 2, and what each actually gives you

Learn more

Attack Surface Reduction Rules

Eighteen rules, audit first, then warn, then block

Learn more

Entra Global Secure Access

Internet Access, Private Access and tenant restrictions

Learn more

Endpoint Security

Defender for Endpoint and Intune managed

Learn more

App Control for Business

Only the code you permitted actually runs

Learn more

Security Baselines

Why deploying one does not make you CIS compliant

Learn more

Microsoft Defender

Advanced endpoint and email threat protection

Learn more

Microsoft Security Dubai

Entra, Defender, Purview, Sentinel, and what you already own

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy