In this article
The Unblock Requests page displays end-user requests to access blocked sites. Admins review each request and approve, deny, or ignore it. To access the page, navigate to Policies and select Unblock Requests.
This article describes how admins review and manage end-user requests to access blocked sites.
The page has two tabs:
- Active Requests: Pending requests
- Request History: Resolved requests
Active Requests
The Active Requests tab displays all pending unblock requests. The following columns are visible by default:
- Domain
- Organization
- Site
- Policy
- Category
- Blocked By
- Time of Attempt
- Logged on User
- Request Reason
- Actions
The Active Requests grid loads with Time of Attempt sorted ascending by default. Select any column header except Category or Request Reason to re-sort.
Hover over any domain to reveal Copy domain.
Approve or deny a request
Each pending request in the Active Requests grid has two options in the Actions column: Approve Request (the checkmark) and Deny Request (the circle with a slash). Denying a request offers a further choice of whether to notify the requester.
Approve
To approve a request:
- In the Active Requests grid, locate the request.
-
In the Actions column, select Approve Request (the checkmark).
The Approve Request drawer opens and displays the following request details: Domain, Category, Blocked By, Policy, Requester, and Message.
- Under Add domain to, select one of the following:
- Policies: Select one or more policies from the dropdown to add the domain to those policies' Allow Lists. The policy that generated the block is labeled Current Policy and sorted to the top of the list. Policies that already have the domain on their Allow List display an Already allowed indicator.
- Universal Allow List: Add the domain to the Universal Allow List, affecting all sites and users.
- Optional: Select Include CNAMEs to also allow the CNAME chain for the domain alongside the requested domain.
- Optional: Enter a note in the Internal Notes field.
Internal Notes are saved to the Request History grid and the Allow List entry and are not visible to the requester. -
Select Approve Request.
The request is approved and the domain is added to the selected Allow List.
Note: If the domain is already on the relevant Allow List when Approve Request is selected, the drawer displays an Already allowed message that includes the domain, the date it was added, and the policy it was added to, with "No new entry is needed." Select Resolve Request to close the request without adding a duplicate entry, or Cancel to leave the request pending.
Deny
Denying a request offers two options. Deny Request notifies the requester. Deny Request & Ignore denies the request without notifying them.
To deny a request and notify the requester:
- In the Active Requests grid, locate the request.
- In the Actions column, select Deny Request (the circle with a slash).
- Select Deny Request.
- Optional: Enter a message in the Response to requester field.
This message is included in the denial email. - Optional: Enter a note in the Internal Notes field.
Internal Notes are saved to the Request History grid and are not visible to the requester. -
Select Deny Request.
The request is denied and the requester is notified.
To deny a request without notifying the requester:
- In the Active Requests grid, locate the request.
- In the Actions column, select Deny Request (the circle with a slash).
-
Select Deny Request & Ignore.
The request is denied and no email is sent.
Request statuses
A request displays one of the following statuses: Pending, Allowed, Denied, Ignored, Resolved — Already Allowed, and Expired (requests not actioned within 30 days).
Notifications
Admin notifications
When a new request is submitted, a red dot badge displays on Policies in the left navigation and the pending request count updates next to Unblock Requests.
Admins with grid access for the organization also receive an email notification with the requester name, Domain, Category, and a direct link to the Unblock Requests page.
Note: The email subject line includes the organization name. The link in the email directs to the MSP-level Unblock Requests page for requests from a global block page, or to the organization-level Unblock Requests page for requests from an organization or sub-organization block page.
Requester notifications
When an admin approves or denies a request, the requester receives an email with the decision and the admin's response message if one was provided.
Deny Request & Ignore decisions do not send a notification to the requester.
Request History
The Request History tab displays all resolved requests. In addition to the Active Requests columns, the following columns are included by default:
- Actioned by
- Resolved Date
- Internal Notes
- Decision
The grid loads with Resolved Date sorted descending by default. The only available row-level action is View Policy, which opens the policy associated with the request. If no policy is associated, the option is disabled.
Search and filter
Both tabs include a search field and column-level filters.
The search field filters the grid by free text across Domain, Organization, Site, Policy, Category, Logged on User, Email, and Request Reason. Request History also includes Actioned by.
Select the filter icon on any column header to filter that column. The following table lists the filter operators available per column.
| Column | Filter options |
|---|---|
| Time of Attempt / Resolved Date | Date range |
| Category | Is / Is not |
| Domain, Organization, Site, Policy, Logged on User, Email, Request Reason | Contains / Does not contain |
| Actioned by (Request History only) | Is / Is not, Contains / Does not contain |
Row-level actions
In the Active Requests grid, select More actions (the three dots) to access Report Miscategorization, View Policy, and Investigate Mode. In the Request History grid, select More actions to access View Policy.
Report Miscategorization
The Report Miscategorization option opens the Domain Report tool with the domain pre-populated. Reporting a miscategorization does not change the request status. A back link returns to the Unblock Requests page with the current tab, sort, filters, and search preserved.
View Policy
The View Policy option opens the policy associated with the request. If no policy is associated, the option is disabled.
Investigate Mode
The Investigate Mode option opens a modal displaying DNS query activity anchored to the request's domain and timestamp. Select a time window of ±5s, ±10s, or ±15s to scope the activity. The row matching the anchor domain and timestamp is highlighted and tagged Investigating. Select View Full Log to open the full DNS Query Log scoped to the request context.
Note: Investigate Mode uses DNS Query Log data, which is retained for 9 days. For requests older than 9 days, Investigate Mode is disabled in the More actions menu. Hovering over the disabled option displays: "Investigate Mode uses DNS Query Log data, which is kept for 9 days. This request is past 9 days."
Customize the grid view
On either tab, use the grid toolbar to customize, export, and refresh data.
Columns
Under Preferences, select Columns to open a checklist of available columns to display. Search the list to find a specific column, or use Show/Hide All to show or hide all columns at once.
Select Menu (the three dots) on any column header to pin, sort, or hide that column.
The following columns are available but hidden by default on both tabs:
- Deployment
- Deployment Type
Note: Deployment and Deployment Type reflect a snapshot of the values at the time the request was made. If the device is reassigned to a different deployment after the request, the columns continue to display the original values.
Density
Under Preferences, select Density to choose how rows display: Compact (most dense), Standard, or Comfortable (least dense).
Export
Export is available on both tabs. Select Export to download the current view as a CSV file.
Save View
Under Preferences, select Save View to save a customized column layout and reuse it across sessions. Select Use Default to reset the layout. Save View does not save filters, only column layout.
Refresh
Select Refresh to re-fetch requests from the server and surface any new submissions since the page was loaded. Refresh preserves the current tab, sort, filters, search term, and page size.
Read-only access
Users with a read-only role can view the Unblock Requests page and both tabs but cannot take any action on a request. The Approve Request, Deny Request, and Deny Request & Ignore options are visible but disabled for read-only users.
MSP organization filtering
MSP admins managing multiple organizations can filter the Unblock Requests page to a specific organization directly from the page header.
The header displays All Organizations and a Managing N Organizations control displaying the total number of organizations the admin manages. Select Managing N Organizations to open the Organization Drill Down panel. Search for an organization by name or select one from the list to filter both the Active Requests and Request History tabs to that organization. Select Cancel or close the panel to dismiss it without changing the current filter.
Comments
0 comments
Please sign in to leave a comment.