Windows Deployment Troubleshooting
Some web applications stop working while the Blocksi Enterprise web filter is active, because one or more of the domains the application depends on - APIs, CDNs, authentication providers, or WebSocket endpoints - are blocked or inspected by the filter. To restore the application, identify the domains it calls, exclude them from filtering, and deploy the exclusions to the affected devices.
Important
This process requires administrator access to a test device for diagnosis, and to Group Policy Management or Microsoft Intune for deployment.
Before you can exclude a domain, you need to know which domains the web application calls and which of those calls are failing. Do this on one affected device, using the browser the user reports the issue in. Google Chrome and Microsoft Edge both use Chromium DevTools, so the steps are the same in either browser.
On the affected device, open the web application in Google Chrome or Microsoft Edge and sign in as far as the issue allows.
Press F12 to open DevTools, then click the Network tab.
Select the Preserve log checkbox so requests are not cleared when the page redirects or reloads, then click the Clear network log button to empty the request list.
Right-click the column header row and select Domain to display the domain of each request.
Reproduce the failure. Reload the page and repeat the exact action that breaks, such as signing in, uploading a file, or opening a dashboard widget.
Look for requests shown in red, requests with a status of (failed), (blocked), or (canceled), and requests that stay (pending). These are the requests the web filter is interfering with.
Note the Domain value for each failing request. Record the host exactly as it appears, such as
api.example.com, not the full URL.Repeat for each part of the application reported as broken. Different features often call different subdomains or third-party services.
Compile a single list of the domains to exclude, removing any duplicates.
Tip
The Console tab in DevTools can confirm the diagnosis. CORS errors, failed-to-fetch messages, and connection-reset messages that name a specific host corroborate what the Network tab shows.
The web filter reads its exclusion list from the HKEY_LOCAL_MACHINE\SOFTWARE\BlocksiEnterprise\Excluded registry key. Each excluded domain is its own value under this key, and the value name is the domain itself. The client only checks whether a value with that name exists, so the value data is never read.
Add the domains on a single test device and confirm the application works before deploying to all affected devices. Rolling out an incomplete domain list means repeating the deployment.
Important
The web filter reads its exclusion list at startup, so exclusions do not take effect until the device restarts.
On the test device, run Registry Editor as an administrator.
Navigate to
HKEY_LOCAL_MACHINE\SOFTWARE\BlocksiEnterprise\Excluded. If the Excluded key does not exist, right-click BlocksiEnterprise, select New > Key, and name itExcluded.Right-click in the right-hand pane and select New > String Value.
Enter the domain as the value name, exactly as it appeared in the Domain column, with no protocol and no trailing slash - for example,
api.example.com. Leave the value data blank.Repeat for every domain you identified.
Restart the device.
Note
Value names must be bare host names, such as www.example.com, or literal IPv4 addresses. Wildcards such as *.example.com are not supported. Domains that resolve to the loopback address 127.0.0.1 are skipped and produce no rule.
After the device restarts, sign in and reopen the web application.
Press F12 to open DevTools, click the Network tab, select the Preserve log checkbox, then click the Clear network log button.
Repeat the action that failed before.
Confirm that the requests to the excluded domains now succeed and that the application works end to end.
Note
If the application still does not work correctly, check the Network tab for additional blocked domains, add them to the registry, restart the device, and test again. Repeat until the application works fully.
Once the domain list is confirmed working on the test device, push the same registry values to every affected device. Use the procedure that matches how the Blocksi Enterprise agent was deployed.
Important
Deploy the exclusions only after confirming the fix on a test device. Rolling out an incomplete domain list means repeating the deployment.
Group Policy pushes the exclusions as a registry preference. The exclusion key is under HKEY_LOCAL_MACHINE, so the Group Policy Object must apply to computer objects rather than users.
On a domain controller or admin workstation, open the Group Policy Management Console.
Create a new Group Policy Object, such as
Blocksi - Webapp Domain Exclusions, or edit the existing Group Policy Object you use for Blocksi client configuration.Right-click the Group Policy Object, select Edit, then navigate to Computer Configuration > Preferences > Windows Settings > Registry.
Right-click in the right-hand pane and select New > Registry Item. The New Registry Properties window opens.
Configure the following:
Setting
Value
Action
Update
Hive
HKEY_LOCAL_MACHINE
Key Path
SOFTWARE\BlocksiEnterprise\ExcludedValue name
The domain to exclude
Value type
REG_SZ
Value data
Leave blank
Click OK, then repeat for every domain you identified.
Link the Group Policy Object to the organizational units containing the target computer accounts.
Open an elevated Command Prompt on a target device and run the following command, or wait for the background refresh cycle:
gpupdate /force
Restart the device so the web filter picks up the new exclusions.
Tip
To add many domains at once, use the browse button in the New Registry Properties window to connect to the test device's registry and import the existing Excluded values directly, rather than typing each one.
Intune has no built-in policy type for custom registry values outside an imported ADMX template, so the exclusions are deployed with a PowerShell script that runs in the system context.
Sign in to the Microsoft Intune Admin Center.
Navigate to Devices > Scripts and remediations, click the Platform scripts tab, then click + Add and select Windows 10 and later.
On the Basics tab, enter a name for the script, such as
WebFilter Exclusion script, then click Next.On the Script settings tab, click the button next to Script location and upload a PowerShell script that creates the Excluded key if it is missing and adds a string value for each domain:
$regPath = 'HKLM:\SOFTWARE\BlocksiEnterprise\Excluded' if (-not (Test-Path $regPath)) { New-Item -Path $regPath -Force | Out-Null } $domains = @('api.example.com', 'cdn.example.com') foreach ($d in $domains) { New-ItemProperty -Path $regPath -Name $d -Value '' -PropertyType String -Force | Out-Null }Configure the remaining script settings, then click Next:
Run this script using the logged on credentials - Select No so the script runs as SYSTEM and can write to
HKEY_LOCAL_MACHINE.Enforce script signature check - Select No.
Run script in 64 bit PowerShell Host - Select Yes.
On the Assignments tab, add the device group covering the affected devices, then click Next.
On the Review + add tab, review the settings, then click Add.
Monitor the rollout on the script's Device status blade. Once the script has run, restart the affected devices so the web filter picks up the new exclusions.
Note
Replace the domains in the $domains array with the domains you identified on the test device.
If web traffic on a device is not filtered even though Blocksi Enterprise is installed and running, another application on the device may be routing browser traffic in a way that bypasses the filter. Enable proxy scanning first, as it addresses the more common cause.
On the affected device, open an elevated Command Prompt and run the following command:
reg add "HKLM\SOFTWARE\BlocksiEnterprise" /v ProxyScanning /t REG_SZ /d 1 /f
Restart the bsflt service or the device. The setting is read once on first use and cached for the life of the service.
Open
C:\ProgramData\BlocksiEnterprise\bsflt.logand confirm that it contains the lineproxy scanning: on, followed by oneproxy scanning: filtering <browser> -> 127.0.0.1line per scanned connection.
Note
Proxy scanning applies to chrome.exe, msedge.exe, firefox.exe, brave.exe, opera.exe, and vivaldi.exe. Any value other than 1, including no value at all, leaves those connections unscanned.
If proxy scanning does not resolve the issue and a third-party content scanning product such as iBoss is installed on the device, the iBossMitigation value under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\msfilter3 applies a sublayer ordering workaround at the driver level.
0- Applies the workaround only when iBoss is detected. This is the default.1- Always applies the workaround.2- Never applies the workaround.
Note
The iBossMitigationStatus value under the same key is written by the driver and must not be set manually. A value of 1 means the mitigation was applied on the current load, and 0 means it was not.