This article describes how to configure Web Content Filtering (WCF) for Microsoft Edge.
IntroductionMicrosoft Edge is already one of the most secure browsers with features like phishing protection, typosquatting, and more to protect users when they're browsing online. Adding to these security features, Microsoft Edge is introducing Web Content Filtering (WCF) for EDU and SMB organizations to help them keep students and employees safe online. Using this feature, you can choose categories of websites that users aren't allowed to access while using Microsoft Edge.
You can set up web content filtering for your organization via the Microsoft Edge management service using the following steps.
Note
This experience is currently in preview.
PrerequisitesBefore you can set up WCF you must meet the following prerequisites.
Note
Make sure you update to the latest version of Edge on all the managed devices where you want to run (WCF).
Setup stepsThis section describes and illustrates the steps for your organization:
To enable WCF for a configuration policy:
From the Microsoft 365 admin center, navigate to Settings -> Microsoft Edge -> Configuration policies.
If you donât yet have a configuration policy in the Edge management service assigned to your target. Microsoft Entra group, create one by following these steps: Create a configuration policy.
Navigate to your desired configuration policy by clicking on it.
From the configuration policy, navigate to Customization Settings -> Web content filtering.
On the Web content filtering controls page, you find all the settings to manage WCF for your organization. Under Blocked categories, check all the categories that you want to block and then select Save changes.
Important
Users with configured security settings may still be at risk on other browsers. To mitigate this risk, enabling web content filtering through the Edge management service also blocks user access to other browsers. When WCF is enabled, a new configuration policy is created in Intune. Any modifications you make to this new policy in Intune or in a configuration policy with identical groups in the Microsoft Edge management service may lead to unexpected behaviors.
Manage exceptions via allow and block listsWith the necessary categories blocked, use the allow and blocklist capabilities to manage any exceptions.
If you want to allow a particular URL that is part of a blocked category, then you can add the URL to the list of Allowed Sites by following steps:
Tip
Instead of adding the URLs manually, you can import them in bulk using a .csv or .json file with the Import option. You could also bulk export the list if you want to reuse it for a different group/policy.
Similarly, if you want to block a particular URL or list of URLs, you can repeat the previous steps in the Blocked sites section.
Note
In addition to specific URLs you can use URL patterns with supported wildcard characters. Refer to this page for more information.
Important
URLs added to the Allowed sites list takes precedence over the Blocked sites list and Blocked categories. You can read more about this here.
Enable diagnostic data (optional)Web Content Filtering (WCF) on Microsoft Edge is in preview and our aim is to make it as safe and seamless as possible. To help improve the feature and diagnose any issues that might arise during the preview, we recommend that you enable Optional data for the devices on which you're enabling WCF. Microsoft values your privacy, and we won't collect or use any personal identifiable information.
Now that the policy has WCF, Allowlist & Blocklist, and Diagnostic data settings configured you can assign this policy to a group.
On the policy page, select Assignment and then select Assignment.
Click Select Group.
You can check whether the policy was applied to a user's Edge browser by navigating to edge://settings/privacy. Under Privacy, search, and services > Security you should see the Web content filtering setting is enabled.
When a user tries to access a site that is blocked by WCF, they'll see a screen like the one in the next screenshot.
Note
It can take up to 90 minutes for policies set via the Edge management service be applied to user devices.
Managing User Access RequestsIf a user encounters a blocked site which they need to access for a legitimate business reason, or that they believe shouldn't be blocked, they may request access. These requests can then be granted or denied by an administrator from the Edge management service.
Note
Requests are currently enabled for cloud-based configuration profiles.
Support for Intune-based configuration profiles is coming soon.
URLs allowed via requests will automatically add the domain name to the allow list.
Requesting Access (User Steps)To change a block or allow setting from a resolved request, remove the site from the appropriate block or allow list.
ReportingYou can analyze the web activity trends in your organization by searching the audit log on Microsoft Purview. The following fields are associated with the Web Content Filtering records that are sent to Microsoft Purview.
Workload: MicrosoftEdge
Record Type: WebContentFiltering
Activities: Allowed URL Navigation in Microsoft Edge, Blocked URL Navigation in Microsoft Edge
You can use the above to run a search job on the Audit solution of Microsoft Purview.
You can view more details of each URL navigation in the search result by clicking on it or by exporting the results of any search query.
See alsoRetroSearch is an open source project built by @garambo | Open a GitHub Issue
Search and Browse the WWW like it's 1997 | Search results from DuckDuckGo
HTML:
3.2
| Encoding:
UTF-8
| Version:
0.7.4