In this article
Admins use this article to review and manage end-user requests to access blocked sites from the Unblock Requests page.
When an end user submits a request from the block page, the request displays in the Active Requests grid. To access the Unblock Requests page, navigate to Policies and select Unblock Requests. Admins review each request and approve, deny, or ignore it.
The page has two tabs:
- Active Requests: Pending requests
- Request History: Resolved requests
Active Requests
The Active Requests tab displays all pending unblock requests. The following columns are visible by default:
- Domain
- Organization
- Site
- Policy
- Category
- Time of Attempt
- Logged on User
- Request Reason
- Actions
The Active Requests grid loads with Time of Attempt sorted ascending by default. Select any column header except Category or Request Reason to re-sort.
✍️ Hover over any domain to reveal a copy icon.
Approve, Deny, or Deny & Ignore a request
Each pending request in the Active Requests grid has three decision options available in the Actions column.
Approve
To approve a request:
- Select Approve in the Actions column for the request
- Under Add domain to, select one of the following:
- Policies: Select one or more policies from the drop-down menu to add the domain to those policies' Allow Lists. The policy that generated the block is labeled Current Policy and sorted to the top of the list
- Universal Allow List: Add the domain to the Universal Allow List, affecting all sites and users
- Optionally, select Include CNAMEs to also allow the CNAME chain for the domain alongside the requested domain
- Optionally, enter a note in the Internal Notes field
Internal Notes are saved to the Request History grid and the Allow List entry and are not visible to the requester. - Select Approve Request
✍️ If the domain is already on the relevant Allow List when Approve is selected, the drawer displays an "Already on the Allow List" message instead of the approval options. Select Resolve Request to close the request without adding a duplicate entry, or Cancel to leave the request pending.
✍️ Policies that already have the domain on their Allow List display an Already allowed indicator in the policy drop-down menu.
Deny
To deny a request:
- Select Deny in the Actions column for the request
- Optionally, enter a message in the Response to requester field
This message is included in the denial email sent to the requester. - Optionally, enter a note in the Internal Notes field
Internal Notes are saved to the Request History grid and are not visible to the requester. - Select Deny
The request is denied and the requester is notified.
Deny & Ignore
To deny a request without notifying the requester:
- Select Deny & Ignore in the Actions column for the request
Request statuses
A request displays one of the following statuses: Pending, Allowed, Denied, Ignored, Resolved — Already Allowed, and Expired (requests not actioned within the auto-expiry window).
Notifications
Admin notifications
When a new request is submitted, a red dot badge displays on Policies in the left navigation and the pending request count updates next to Unblock Requests.
Admins with grid access for the organization also receive an email notification with the requester name, Domain, Category, and a direct link to the request.
Requester notifications
When an admin approves or denies a request, the requester receives an email with the decision and the admin's response message if one was provided.
Deny & Ignore decisions do not send a notification to the requester.
Request History
The Request History tab displays all resolved requests. The following columns are included in addition to the Active Requests columns:
- Actioned by
- Resolved Date
- Internal Notes
- Decision
The Request History grid loads with Resolved Date sorted descending by default.
No row-level actions are available in the Request History grid. Resolved requests are read-only.
Search and filter
Both tabs include a search field and column-level filters.
Search: The search field filters the grid by free text across the following fields: Domain, Organization, Site, Policy, Category, Logged on User, Email, Request Reason. Request History also includes Actioned by.
Column filters: Select the filter icon on any column header to filter by that column. Available filter operators per column:
| Column | Filter options |
|---|---|
| Time of Attempt / Resolved Date | Date range |
| Category | Is / Is not |
| Domain, Organization, Site, Policy, Logged on User, Email, Request Reason | Contains / Does not contain |
| Actioned by (Request History only) | Is / Is not, Contains / Does not contain |
Row-level actions
Each row in both tabs includes a ⋯ actions menu with the following options:
Report Miscategorization
The Report Miscategorization option opens the Domain Report tool with the domain pre-populated. Reporting a miscategorization does not change the request status. A back link returns to the Unblock Requests page with the current tab, sort, filters, and search preserved.
View Policy
The View Policy option opens the policy associated with the request. If no policy is associated, the option is disabled.
Investigate Mode
The Investigate Mode option opens a modal displaying DNS query activity anchored to the request's domain and timestamp. Select a time window of ±5s, ±10s, or ±15s to scope the activity. The row matching the anchor domain and timestamp is highlighted and tagged Investigating. Select View Full Log to open the full DNS Query Log scoped to the request context.
✍️ Investigate Mode uses DNS Query Log data, which is retained for 9 days. For requests older than 9 days, Investigate Mode is disabled in the ⋯ menu. Hovering over the disabled option displays: "Investigate Mode uses DNS Query Log data, which is kept for 9 days. This request is past 9 days."
Customize the grid view
On either tab, use the grid toolbar to customize, export, and refresh data.
Columns
Under Preferences, select Columns to open a checklist of available columns to display. Search the list to find a specific column, or use Show/Hide All to show or hide all columns at once.
Select the three-dot icon (⋮) on any column header to pin, sort, or hide that column.
The following columns are available but hidden by default on both tabs:
- Deployment
- Deployment Type
✍️ Deployment and Deployment Type reflect a snapshot of the values at the time the request was made. If the device is reassigned to a different deployment after the request, the columns continue to display the original values.
Density
Under Preferences, select Density to choose how rows display: Compact (most dense), Standard, or Comfortable (least dense).
Export
Export is available on both tabs. Select Export to download the current view as a CSV file.
Save View
Under Preferences, select Save View to save a customized column layout and reuse it across sessions. Select Use Default to reset the layout. Save View does not save filters, only column layout.
Refresh
Select Refresh to re-fetch requests from the server and surface any new submissions since the page was loaded. Refresh preserves the current tab, sort, filters, search term, and page size.
Read-only access
Users with a read-only role can view the Unblock Requests page and both tabs but cannot take any action on a request. The Approve, Deny, and Deny & Ignore options are visible but disabled for read-only users.
MSP organization filtering
MSP admins managing multiple organizations can filter the Unblock Requests page to a specific organization directly from the page header.
The header displays All Organizations and a Managing N Organizations control displaying the total number of organizations the admin manages. Select Managing N Organizations to open the Organization Drill Down panel. Search for an organization by name or select one from the list to filter both the Active Requests and Request History tabs to that organization. Select Cancel or close the panel to dismiss it without changing the current filter.
Comments
0 comments
Please sign in to leave a comment.