Windows Internet Access Guide

How to Restrict Internet Access on Windows

Block all internet traffic, restrict selected websites and services, or keep only approved business applications online on a Windows PC.

  • Choose full restriction or targeted blocking
  • Preserve approved websites, programs, services, and IPs
  • Password protect changes and review blocked attempts
GiliSoft WebLock internet access control settings
Internet rules for this Windows PCGiliSoft WebLock

What Is the Best Way to Restrict Internet Access on Windows?

Match the restriction to the real task.Use GiliSoft WebLock when one Windows PC needs an administrator-controlled internet policy, Windows Defender Firewall when one executable must be blocked, browser policy when managed Edge or Chrome browsing is the only concern, and a secure web gateway when many users and devices need central control.

"Restrict internet access" can mean several different things: take a shared PC completely offline, block a distracting website, prevent one application from connecting, or allow only a short list of business resources. Starting with the narrowest rule that solves the problem reduces accidental disruption.

Choose the Level of Internet Restriction

Restrict the whole PCDisable general internet activity, then preserve only the websites and applications the computer must use.
Restrict selected accessKeep ordinary connectivity available while blocking named websites, programs, services, or destinations.
Restrict one applicationCreate an outbound firewall rule when only one executable should be prevented from connecting.
Do not disconnect the network adapter if approved online work must continue. A policy with explicit exceptions is easier to operate than repeatedly disabling and enabling Wi-Fi or Ethernet.

Compare Windows Internet Restriction Methods

MethodBest forWhat it controlsImportant detail
GiliSoft WebLockShared, work, study, kiosk, and front-desk Windows PCsDefault internet policy, websites, programs, services, IPs, temporary access, and logsOne local interface with password-protected administration
Windows Defender FirewallBlocking one program or serviceOutbound traffic by executable, port, protocol, address, and profileWindows allows outbound traffic by default unless a blocking rule matches
Edge or Chrome policyManaged browsersURL blocklists and allowlist exceptionsDoes not automatically govern other browsers or desktop application traffic
Secure web gatewayLarger organizations and remote usersDNS, network, HTTP, identity, device, and application policiesRequires central deployment, routing, and ongoing administration
Practical choice for a Windows workstation: WebLock combines broad restrictions with narrow exceptions, so the PC can remain useful without leaving unrestricted internet access open.

Restrict Internet Access with GiliSoft WebLock

1. Select the default internet policy

Choose the main internet restriction policy in GiliSoft WebLock

Choose Block Everything for a tightly controlled PC, or block selected websites and services when normal business access should continue.

  1. Open WebLock and enter the administration password.
  2. Choose Block Everything, block selected websites and services, or harmful-content filtering.
  3. Apply the policy on a test PC before using it on a production workstation.
  4. Test one permitted destination and one destination that should be blocked.

2. Preserve approved websites and applications

Approved website list in GiliSoft WebLock

Keep company portals, cloud services, support pages, and other approved destinations available.

Approved program list in GiliSoft WebLock

Allow the actual executable used by an approved Windows application.

Under a restrictive policy, add the resources the PC genuinely needs. If an allowed application still cannot connect, check whether it relies on a helper executable, service, or additional destination.

3. Allow required services and IP addresses

Allowed network services in GiliSoft WebLock

Preserve a verified service without opening general internet access.

Allowed IP addresses in GiliSoft WebLock

Permit a known destination IP when the application requires it.

4. Protect settings, use temporary access, and review logs

Temporary Unlock options in GiliSoft WebLock

Pause restrictions until restart, for a selected period, until idle, or until the screen saver starts.

Blocked internet access log in GiliSoft WebLock

Review the event time, process, action, and details before approving a new exception.

Set the WebLock administration password before another user receives the PC. Use Temporary Unlock for approved maintenance instead of deleting the saved policy.

Block Internet Access for One Program with Windows Firewall

Microsoft documents outbound program and service rules in Windows Firewall with Advanced Security. This is useful when one executable must not send network traffic and the rest of the PC should remain online.

  1. Open Windows Defender Firewall with Advanced Security.
  2. Select Outbound Rules, then choose New Rule.
  3. Choose a custom or program rule and select the executable path.
  4. Select Block the connection, choose the applicable network profiles, name the rule, and finish.
  5. Launch the program and verify its online functions are blocked while other approved applications still connect.
Use the correct executable path. Some applications update into a new folder or use helper processes. Recheck the rule after application updates and do not assume a browser-only test proves that every background connection is blocked.

Restrict Websites in Managed Edge or Chrome

Microsoft Edge and Google Chrome support URL blocklists and allowlist exceptions through managed policy. Both vendors document a restrictive pattern in which all URLs are blocked and approved destinations are added as exceptions.

This approach is appropriate when the browser is managed and web navigation is the only requirement. It does not replace endpoint or gateway controls for another browser, desktop software, background services, or non-HTTP traffic.

Apply Internet Restrictions Without Breaking Approved Work

  • List every website and application the PC needs
  • Include sign-in, update, and support dependencies
  • Test one representative Windows PC first
  • Protect policy settings with an admin password
  • Verify both approved and blocked activity
  • Review logs before broadening an exception
  • Use Temporary Unlock for maintenance
  • Record who owns and reviews the policy

For company computers, explain what is restricted, who can authorize a change, and how a user reports a blocked business dependency. Large deployments can be discussed with GiliSoft for customized implementation requirements.

Frequently Asked Questions

Can WebLock disable all internet access but allow one program?

Yes. Start with a restrictive default policy, add the approved executable, then allow only the services, websites, or IP destinations that application requires.

Can I restrict websites without blocking the whole internet?

Yes. Choose selected website and service restrictions so approved browsing and Windows applications remain available.

How do I temporarily restore access?

Use WebLock Temporary Unlock. Restrictions can resume after restart, after a selected duration, when the PC becomes idle, or when the screen saver starts.

Can users change the internet rules?

WebLock settings can be protected with an administration password so ordinary users cannot casually alter the policy.

Is Windows Firewall enough for company-wide internet control?

Firewall rules are useful for specific programs, ports, and destinations. Centralized user, device, URL, and traffic policies usually require managed browser, endpoint, or secure web gateway administration.

Official References

Control Internet Access on This Windows PC

Use GiliSoft WebLock to apply the right default policy, preserve approved access, protect changes, and review blocked events.