Skip to main content

Admin Dashboard

Windows Deployment Troubleshooting

Some web applications stop working while the Blocksi Enterprise web filter is active, because one or more of the domains the application depends on - APIs, CDNs, authentication providers, or WebSocket endpoints - are blocked or inspected by the filter. To restore the application, identify the domains it calls, exclude them from filtering, and deploy the exclusions to the affected devices.

Excluding a web application's domains from filtering requires a three-step process:
  1. Identifying Domains Blocked by the Web Filter

  2. Excluding Domains on a Test Device

  3. Deploying Domain Exclusions

Important

This process requires administrator access to a test device for diagnosis, and to Group Policy Management or Microsoft Intune for deployment.

Before you can exclude a domain, you need to know which domains the web application calls and which of those calls are failing. Do this on one affected device, using the browser the user reports the issue in. Google Chrome and Microsoft Edge both use Chromium DevTools, so the steps are the same in either browser.

To identify the domains a web application uses:
  1. On the affected device, open the web application in Google Chrome or Microsoft Edge and sign in as far as the issue allows.

  2. Press F12 to open DevTools, then click the Network tab.

  3. Select the Preserve log checkbox so requests are not cleared when the page redirects or reloads, then click the Clear network log button to empty the request list.

  4. Right-click the column header row and select Domain to display the domain of each request.

  5. Reproduce the failure. Reload the page and repeat the exact action that breaks, such as signing in, uploading a file, or opening a dashboard widget.

  6. Look for requests shown in red, requests with a status of (failed), (blocked), or (canceled), and requests that stay (pending). These are the requests the web filter is interfering with.

  7. Note the Domain value for each failing request. Record the host exactly as it appears, such as api.example.com, not the full URL.

  8. Repeat for each part of the application reported as broken. Different features often call different subdomains or third-party services.

  9. Compile a single list of the domains to exclude, removing any duplicates.

Tip

The Console tab in DevTools can confirm the diagnosis. CORS errors, failed-to-fetch messages, and connection-reset messages that name a specific host corroborate what the Network tab shows.

The web filter reads its exclusion list from the HKEY_LOCAL_MACHINE\SOFTWARE\BlocksiEnterprise\Excluded registry key. Each excluded domain is its own value under this key, and the value name is the domain itself. The client only checks whether a value with that name exists, so the value data is never read.

Add the domains on a single test device and confirm the application works before deploying to all affected devices. Rolling out an incomplete domain list means repeating the deployment.

Important

The web filter reads its exclusion list at startup, so exclusions do not take effect until the device restarts.

To exclude domains on a test device:
  1. On the test device, run Registry Editor as an administrator.

  2. Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\BlocksiEnterprise\Excluded. If the Excluded key does not exist, right-click BlocksiEnterprise, select New > Key, and name it Excluded.

  3. Right-click in the right-hand pane and select New > String Value.

  4. Enter the domain as the value name, exactly as it appeared in the Domain column, with no protocol and no trailing slash - for example, api.example.com. Leave the value data blank.

  5. Repeat for every domain you identified.

  6. Restart the device.

Note

Value names must be bare host names, such as www.example.com, or literal IPv4 addresses. Wildcards such as *.example.com are not supported. Domains that resolve to the loopback address 127.0.0.1 are skipped and produce no rule.

To verify the exclusions:
  1. After the device restarts, sign in and reopen the web application.

  2. Press F12 to open DevTools, click the Network tab, select the Preserve log checkbox, then click the Clear network log button.

  3. Repeat the action that failed before.

  4. Confirm that the requests to the excluded domains now succeed and that the application works end to end.

Note

If the application still does not work correctly, check the Network tab for additional blocked domains, add them to the registry, restart the device, and test again. Repeat until the application works fully.

Once the domain list is confirmed working on the test device, push the same registry values to every affected device. Use the procedure that matches how the Blocksi Enterprise agent was deployed.

Important

Deploy the exclusions only after confirming the fix on a test device. Rolling out an incomplete domain list means repeating the deployment.

Group Policy pushes the exclusions as a registry preference. The exclusion key is under HKEY_LOCAL_MACHINE, so the Group Policy Object must apply to computer objects rather than users.

To deploy the domain exclusions with Group Policy:
  1. On a domain controller or admin workstation, open the Group Policy Management Console.

  2. Create a new Group Policy Object, such as Blocksi - Webapp Domain Exclusions, or edit the existing Group Policy Object you use for Blocksi client configuration.

  3. Right-click the Group Policy Object, select Edit, then navigate to Computer Configuration > Preferences > Windows Settings > Registry.

  4. Right-click in the right-hand pane and select New > Registry Item. The New Registry Properties window opens.

  5. Configure the following:

    Setting

    Value

    Action

    Update

    Hive

    HKEY_LOCAL_MACHINE

    Key Path

    SOFTWARE\BlocksiEnterprise\Excluded

    Value name

    The domain to exclude

    Value type

    REG_SZ

    Value data

    Leave blank

  6. Click OK, then repeat for every domain you identified.

  7. Link the Group Policy Object to the organizational units containing the target computer accounts.

  8. Open an elevated Command Prompt on a target device and run the following command, or wait for the background refresh cycle:

    gpupdate /force
  9. Restart the device so the web filter picks up the new exclusions.

Tip

To add many domains at once, use the browse button in the New Registry Properties window to connect to the test device's registry and import the existing Excluded values directly, rather than typing each one.

Intune has no built-in policy type for custom registry values outside an imported ADMX template, so the exclusions are deployed with a PowerShell script that runs in the system context.

To deploy the domain exclusions with Intune:
  1. Sign in to the Microsoft Intune Admin Center.

  2. Navigate to Devices > Scripts and remediations, click the Platform scripts tab, then click + Add and select Windows 10 and later.

  3. On the Basics tab, enter a name for the script, such as WebFilter Exclusion script, then click Next.

  4. On the Script settings tab, click the button next to Script location and upload a PowerShell script that creates the Excluded key if it is missing and adds a string value for each domain:

    $regPath = 'HKLM:\SOFTWARE\BlocksiEnterprise\Excluded'
    if (-not (Test-Path $regPath)) {
        New-Item -Path $regPath -Force | Out-Null
    }
    $domains = @('api.example.com', 'cdn.example.com')
    foreach ($d in $domains) {
        New-ItemProperty -Path $regPath -Name $d -Value '' -PropertyType String -Force | Out-Null
    }
  5. Configure the remaining script settings, then click Next:

    • Run this script using the logged on credentials - Select No so the script runs as SYSTEM and can write to HKEY_LOCAL_MACHINE.

    • Enforce script signature check - Select No.

    • Run script in 64 bit PowerShell Host - Select Yes.

  6. On the Assignments tab, add the device group covering the affected devices, then click Next.

  7. On the Review + add tab, review the settings, then click Add.

  8. Monitor the rollout on the script's Device status blade. Once the script has run, restart the affected devices so the web filter picks up the new exclusions.

Note

Replace the domains in the $domains array with the domains you identified on the test device.

If web traffic on a device is not filtered even though Blocksi Enterprise is installed and running, another application on the device may be routing browser traffic in a way that bypasses the filter. Enable proxy scanning first, as it addresses the more common cause.

To enable proxy scanning:
  1. On the affected device, open an elevated Command Prompt and run the following command:

    reg add "HKLM\SOFTWARE\BlocksiEnterprise" /v ProxyScanning /t REG_SZ /d 1 /f
  2. Restart the bsflt service or the device. The setting is read once on first use and cached for the life of the service.

  3. Open C:\ProgramData\BlocksiEnterprise\bsflt.log and confirm that it contains the line proxy scanning: on, followed by one proxy scanning: filtering <browser> -> 127.0.0.1 line per scanned connection.

Note

Proxy scanning applies to chrome.exe, msedge.exe, firefox.exe, brave.exe, opera.exe, and vivaldi.exe. Any value other than 1, including no value at all, leaves those connections unscanned.

If proxy scanning does not resolve the issue and a third-party content scanning product such as iBoss is installed on the device, the iBossMitigation value under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\msfilter3 applies a sublayer ordering workaround at the driver level.

Set iBossMitigation to one of the following REG_DWORD values:
  • 0 - Applies the workaround only when iBoss is detected. This is the default.

  • 1 - Always applies the workaround.

  • 2 - Never applies the workaround.

Note

The iBossMitigationStatus value under the same key is written by the driver and must not be set manually. A value of 1 means the mitigation was applied on the current load, and 0 means it was not.