Microsoft Defender for Endpoint
Endpoint protection

Web Content Filtering

In brief

The documentation now notes up to two hours of policy-enforcement latency, audit-only policies, possible delays during policy or group changes, and risks of blocking the “Uncategorized” category. It also names dashboard cards and updates the SmartScreen link.

What Defender admins need to know

Admins can better plan policy rollouts, use audit-only policies to assess user behavior, and interpret web activity dashboards.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

author: limwainstein ms.reviewer: ericlaw ms.localizationpriority: medium ms.date: 06/16/07/03/2026 ms.collection:

  • m365-security
  • tier2
  • mde-asr ms.custom: admindeeplinkDEFENDER, msecd-doc-authoring-10141016 ms.topic: how-to ms.subservice: asr appliesto:

Configure policies across your device groups to block selected categories. Blocking a category prevents users within specified device groups from accessing URLs associated with the category. For any category that's not blocked, the URLs are automatically audited. Your users can access audited URLs without disruption, and you gather access statistics to help create a more custom policy decision. Your users see a block notification if an element on the page they're viewing is making calls to a blocked resource.

Web content filtering is available in major web browsers, with blocks performed by Windows Defender SmartScreen (Microsoft Edge) and network protection (Chrome, Firefox, Brave, and Opera). Supported browsers include Microsoft Edge, Google Chrome, Mozilla Firefox, Brave, Opera, and Internet Explorer. For the full list of requirements, including subscription, operating system, browser, and protection prerequisites, see the web content filtering prerequisitesprerequisites section later in this article.

Benefits of web content filtering

|Portal access|You must have access to the Microsoft Defender portal.| |Operating system|Your organization's devices must be running one of the following operating systems with the latest antivirus/antimalware updates:
- Windows 11
- Windows 10 Anniversary Update (version 1607) or later
- Windows Server 2019 or later
- For macOS availability, see Network Protection for macOS
- For Linux availability, see Network Protection for Linux| |Browser|Your devices must be running one of the following browsers:
- Microsoft Edge
- Google Chrome
- Mozilla Firefox
- Brave
- Opera
- Internet Explorer| |Related protection|Windows Defender SmartScreenWindows Defender SmartScreen and network protection must be enabled on your organization's devices.|

Web content filtering data storage and privacy

Create a policy

To add a new policy, follow these steps:

  1. In the Microsoft Defender portal at https://security.microsoft.com

    To add a new policy, follow these steps:

    1. In the Microsoft Defender portal at https://security.microsoft.com, go to System> Settings > Endpoints > Rules section > Web content filtering. Or, to go directly to the Web content filtering page, use https://security.microsoft.com/securitysettings/endpoints/web_content_filtering_policy.

    Web activity by category

    ThisThe Web activity by category card lists the parent web content categories with the largest increase or decrease in the number of access attempts. You can explore changes in web activity patterns in your organization from last 30 days, 3 months, or 6 months. Select a category name to view more information.

    In the first 30 days of using web content filtering, your organization might not have enough data to display the Web activity by category card.

    Web content filtering summary card

    ThisThe Web content filtering summary card displays the distribution of blocked access attempts across the different parent web content categories. Select one of the colored bars to view more information about a specific parent web category.

    :::image type="content" source="media/web-content-filtering-summary.png" alt-text="The web content filtering summary card" lightbox="media/web-content-filtering-summary.png":::

    Web activity summary card

    ThisThe Web activity summary card displays the total number of requests for web content across all URLs.

    :::image type="content" source="media/web-activity-summary.png" alt-text="The web activity summary card" lightbox="media/web-activity-summary.png":::