Policy Configuration — Current Catalog (2026 update)
Authentication Controls — login & identity enforcement.
- Personal Login modes (NEW): Block all · Specific allow/block URL lists · By category (choose which website categories permit personal logins).
- Login Enforcement domains (NEW): auto identity-switch on IdP/login domains (login.microsoftonline.com, accounts.google.com, okta.com, or any added domain); CSV import/export.
- Force AI Login (NEW): require corporate login on Gen-AI sites — all classified Gen-AI domains or an explicit list.
- MFA & transactional MFA, session duration / disconnect, prevent-logout, RPA controls, keylogging protection.
Web Content Filtering — category-based URL allow/block, keyword & iframe filtering, learning mode, browser redirect.
- Per-user time-boxed access (NEW): grant a single user temporary access from an Alert (scope = User) until a chosen revocation date; auto-expires. (Web Filter violations only.)
Data Loss Prevention (DLP) — copy/paste/upload prevention, PII detection, anonymizer, watermarking, screen-capture controls, AI character limits, controlled/forbidden links.
Download Management — file-extension allow/alert rules, download encryption, malware scan, scraping prevention, secure storage, exception URLs.
Browser Extensions Controls — Chrome Web Store rule, allowed-extension list, extension-rating rule.
Browsing Monitoring (Activity Capture) — monitored apps, active-site time, and Shadow-IT capture.
- NEW: Activity screen capture (screenshot or video), AI Interaction Governance (consent / forced AI login), meeting recording, and per-feature domain-exclusion lists.
Phishing Protection — SaaS-impersonation & credential-phishing detection, regex rules, trusted/exception domains.
Advanced Protection — JIT, domain-age, content-script exclusion, weak-password check, safe browsing, iframe-injection control, ADMX, and ad-blocking (NEW).
Device Compliance Enforcement (DPC) — device posture checks: registry-key / file-exists / process-exists / certificate-upload rules (extension-with-agent).
Proxy Access Management — route traffic via a self-hosted or PAC proxy; global/temporary, domain exclusions, SaaS/additional domains, authenticated proxy.
Bookmark Management — push and manage browser bookmarks.
Gateway Control Management (NEWER policy) — privileged remote access via Guacamole and Boundary (RDP/SSH).
- Guacamole & Boundary JIT credential rotation, subnet management, allowed-server / allowed-access-URL lists.
- NEW: JIT AD password rotation interval (reuse one JIT AD password for N days, e.g. 30 = monthly); forward-proxy support; session-recording viewer (see Remote Desktop Gateway).
Product Owner — Policy Exclusion (cross-cutting): POs can exclude any parent policy per company; exclusion disables the policy and its dependent feature flags and is audited in the Change Log. (Full feature-profile companies only.)
