Windows Website Access Guide

How to Allow Only Work-Related Websites on Windows

Keep approved business portals, webmail, CRM, support, and cloud services available while unrelated browsing remains blocked on office, front-desk, and shared Windows PCs.

  • Start with a default block and add approved work websites
  • Keep required Windows programs and services online
  • Password protect policy changes and review blocked attempts
GiliSoft WebLock approved website list
Approved sites stay availableGiliSoft WebLock

Can a Windows PC Be Limited to Work Websites Only?

Yes. Use an allowlist instead of trying to name every distracting website.Block general internet access, add the domains and Windows applications required for work, protect the settings, then review blocked events for any verified dependency you missed.

This model fits reception desks, service counters, warehouses, classrooms, training rooms, shared workstations, and company PCs assigned to a narrow job. It is more predictable than chasing social, streaming, gaming, shopping, and newly created websites one at a time.

Modern business sites often rely on separate sign-in domains, APIs, content delivery networks, document storage, and helper applications. Build the allowlist around the complete work task, not only the address visible in the browser bar.

Compare Ways to Allow Only Approved Websites

MethodBest fitCoverageAdministration
GiliSoft WebLockOffice, front-desk, kiosk, study, and shared Windows PCsWebsites, programs, services, IPs, temporary access, and logsLocal Windows tool with password-protected settings
Microsoft Edge policiesManaged Edge profiles and devicesURLs opened in Microsoft EdgeGroup Policy, registry, or device management
Chrome Enterprise policiesManaged Chrome browsersURLs opened in managed ChromeGoogle Admin console or managed policy files
Microsoft DefenderDefender for Endpoint environmentsCategories, custom URL/IP indicators, and reportingCentral portal and device groups
Secure web gatewayIdentity and network-wide policyDomains, full URLs, categories, users, and trafficGateway clients, routing, certificates, and central rules
Recommended for a straightforward Windows rollout: use GiliSoft WebLock when individual or shared PCs need a defined set of business websites and applications without building a browser-management or secure-gateway environment.

Prepare the Work Website Allowlist First

Business websitesCRM, ERP, webmail, ticketing, supplier portals, banking, and support.
Supporting domainsSingle sign-on, APIs, CDNs, storage, maps, payment, and embedded services.
Windows applicationsEmail, remote support, communication, synchronization, and line-of-business tools.
  1. List each task the PC must perform and the websites used for that task.
  2. Sign out and in again so authentication and redirect domains are included.
  3. Open files, submit forms, and test embedded content and approved downloads.
  4. Record desktop applications and services that require internet access.
  5. Apply the rule to one test PC before using it on additional computers.
Do not approve a broad parent domain just to fix one missing page. Review the blocked event and add the narrowest verified website, program, service, or IP exception.

Allow Work Websites with GiliSoft WebLock

WebLock combines a restrictive internet policy with separate lists for approved websites, Windows programs, services, and IP addresses. An administrator password protects changes, Temporary Unlock handles supervised maintenance, and the log shows what the policy intercepted.

1. Choose the default internet policy

GiliSoft WebLock main internet policy screen

Choose a restrictive default policy before adding the access required for work.

  1. Open WebLock and enter the administration password.
  2. Select the policy that blocks general internet access.
  3. Keep WebLock active while building and testing approved lists.

2. Add approved business websites

Adding approved work websites in GiliSoft WebLock

Add the company, cloud, support, and sign-in domains required by the assigned job.

  1. Open Allowed Websites.
  2. Add each required domain and save the list.
  3. Complete the normal sign-in and work sequence on an approved site.
  4. Try an unrelated site to confirm the default block remains active.

3. Keep trusted business applications online

Approved Windows programs in WebLock

Allow the executable used by an approved desktop application.

Approved Windows services in WebLock

Add a service only when a verified business application requires it.

A website allowlist does not automatically cover every desktop application. Add the executable and any confirmed service or IP dependency, then test the exact online feature employees use.

4. Protect settings and review blocked events

WebLock administration password settings

Require authorization before the allowlist or policy can be changed.

WebLock blocked internet access logs

Identify missing dependencies without opening unrestricted access.

Use Edge or Chrome Policies for Browser-Only Control

Microsoft Edge URLAllowlist and URLBlocklist

Microsoft documents a configuration in which * is placed in URLBlocklist and approved destinations are entered in URLAllowlist. The allowed list takes precedence over the blocked list. Policies can be delivered through Group Policy, registry settings, or supported device-management systems.

Google Chrome URLBlocklist and URLAllowlist

Google documents the same default-block model for managed Chrome. Chrome Enterprise supports administration through the Google Admin console and managed policy files. Google also notes that URL lists are basic browser management; stronger filtering may require a content-filtering proxy or extension.

Browser policies are not whole-PC internet control. Desktop applications, alternate browsers, background services, and non-web protocols may require endpoint or gateway controls.

Use Endpoint or Gateway Filtering for Larger Environments

Microsoft Defender for Endpoint

Microsoft Defender web protection combines web threat protection, category-based filtering, and custom URL/IP indicators. Policies can target device groups and provide centralized reporting for organizations already operating Defender for Endpoint.

Secure web gateways

A secure web gateway can evaluate domains, full URLs, content categories, identities, device posture, and network traffic. Cloudflare documents DNS policies for whole domains, HTTP policies for complete URL paths, and network policies for non-HTTP traffic. This provides broader control but requires gateway enrollment, routing, policy administration, and certificate planning for inspected HTTPS traffic.

For larger or specialized WebLock deployments, GiliSoft can discuss customization and deployment requirements directly.

Roll Out Work-Only Browsing Without Breaking Business Apps

  • Test on a representative Windows PC first
  • Include sign-in, API, storage, and CDN dependencies
  • Verify browsers and desktop applications
  • Protect changes with an administrator password
  • Document who can approve a new website
  • Review blocked events before adding exceptions
  • Retest after cloud or sign-in changes
  • Keep a temporary maintenance procedure

Employees should know why access is restricted, how to request a legitimate site, and who reviews the request. A short approval path prevents policy from interrupting real work.

Frequently Asked Questions

Can I allow one website while blocking everything else?

Yes. Choose a restrictive default policy in WebLock and add the approved domain. Add any verified sign-in, API, program, service, or IP dependency needed for the site to work.

Why is an approved website only partly working?

The page may load resources from other domains or use a separate identity provider. Reproduce the failed action, review the blocked log, and add only the dependency that belongs to the approved task.

Can employees change the website list?

Protect WebLock settings with an administration password and keep it with the person responsible for policy changes.

How do I provide temporary unrestricted access?

Use Temporary Unlock for authorized maintenance. The saved policy can resume after the selected condition instead of being deleted and rebuilt.

Official References

Keep Work Websites Available and Block the Rest

Use GiliSoft WebLock to approve websites and Windows applications, protect policy changes, and review blocked attempts from one Windows tool.