Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

URL Filtering Policy Best Practices in Zscaler

Zscaler
05/08/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


In this series of short videos, we'll be taking a look at recommendations for the configuration of URL filtering. This is part two, URL filtering policy. Let's start by looking at what the objectives are for good URL filtering policy. These are, first, protecting users and data from security threats, such as malware and data loss, second, limiting the business's exposure to liability by blocking access to inappropriate content, for example, pornography, hate speech, or drugs, third, reducing productivity loss caused by users accessing sites or cloud applications that do not serve a legitimate business purpose. To this end, Zscaler recommends you begin building URL filtering policy by starting from your corporate acceptable use policy. Next, it's recommended that you use the retain parent category option when creating custom URL categories, as this will ensure URLs can be evaluated against their original category, as well as any custom categories they are part of. This will make understanding your URL filtering policy and troubleshooting unwanted behaviors easier. As with other policy engines, it's recommended that you build policy in a top-down model, with the most specific rules at the top, since policy is evaluated in order. Zscaler recommends blocking the legal liability, malicious, and suspicious categories entirely. We also recommend creating a policy to caution users when they access URLs in the miscellaneous category, which is the category to which URLs belong when they have not yet been categorized. Finally note that the default behavior for the URL filtering module is an implicit allow. You should decide whether this is acceptable or whether you want to configure a default block policy and explicitly allow only select categories. Let's take a look at an example URL filtering policy. Here, as rules number 1 and 2, we start with global-specific allow and global-specific block rules. These rules are where you would control access to specific URLs belonging to categories that would otherwise be incorrectly allowed or blocked. Putting these rules at the top allows us to ensure exact matching works to our advantage. Rule number 3 is a global security-oriented block rule, and rule number 4 is a global legal liability block. These block specific categories for all users that are privacy or security risks, and legal liability risks respectively. Rule number 5 blocks the file host, webmail, and peer-to-peer categories for all users. Since URL filtering policy is evaluated after cloud app control policy, you can define allowed applications in these categories as part of your cloud app control policy, and this URL filtering rule will block all other cloud applications in these categories not explicitly allowed this way. Below rule number 5 is where you would place rules that apply only to specific users or locations, whatever those rules might be. Here, we recommend that you create these rules in a disabled state at first while building your policy, then enable all user-specific and location-specific rules at the same time to ensure policy is properly applied. The final rule, numbered 8 here, is the global category-based block rule. This rule is where you will select all URL categories you wish to block for all users. Placing it at the bottom ensures that it is evaluated after any of your specific allow rules. As a reminder, the default behavior for URL filtering is an implicit allow. This means any URL category not explicitly blocked will be allowed for your users. Next, here are a few things to look out for when creating and configuring URL filtering policy. First, when configuring custom URL categories for use in URL filtering policy, we recommend that you use FQDNs and not IP addresses. This helps make sure that destinations are correctly blocked or allowed based on your URL filtering policy when a user tries to access a URL, as users will generally be entering user-friendly FQDNs rather than IP addresses in their browsers. IP-based policy blocks should generally be implemented in Cloud Firewall policy instead. Next, under Advanced Policy Settings, you will find a number of toggles. At minimum, Zscaler recommends enabling the Suspicious New Domains lookup setting. This will allow you to create policy to block the Newly Registered and Observed Domains and Newly Revived Domains categories, which contain domains that are often used as part of phishing or malware distribution campaigns. We also recommend enabling the Enable Embedded Sites categorization setting. The remaining settings should be evaluated on the basis of your organization's security policies. Under Administration, Advanced Settings, it is also recommended that you enable all HTTP tunnel control settings. These settings will help prevent HTTP tunneling, which is a common method of obscuring traffic to avoid detection, by inspecting tunneled traffic and blocking tunneling on non-standard ports. Similarly, it's recommended that you enable the domain fronting protections in this section. Although domain fronting can have legitimate uses, it can also be used to disguise command and control traffic. Before enabling these settings, it's recommended that you review any instances of domain fronting observed in your logs to validate whether or not you need to configure exceptions, and that you continue to monitor logs for some time after enabling this setting. That's it for this video. Thank you for watching.

TL;DR

  • URL filtering policy should address three objectives: protecting against security threats, limiting legal liability from inappropriate content, and reducing productivity loss from non-business sites
  • Build policy top-down starting with specific allow/block rules, then global security and legal blocks, followed by user/location-specific rules, and ending with category-based blocks
  • Enable suspicious new domains lookup to block newly registered and revived domains commonly used in phishing campaigns, and configure HTTP tunnel control settings to prevent traffic obfuscation
  • Use FQDNs instead of IP addresses in custom URL categories and enable retain parent category option to ensure proper policy evaluation and easier troubleshooting

Summary

This technical tutorial demonstrates how to build effective URL filtering policies within Zscaler's Zero Trust Exchange platform. The session covers three core objectives for URL filtering: protecting users and data from security threats like malware, limiting organizational liability by blocking inappropriate content such as pornography and hate speech, and reducing productivity loss from non-business websites. The presenter walks through a recommended policy structure that begins with the corporate acceptable use policy as a foundation, then implements a top-down rule hierarchy starting with specific allow/block rules, followed by global security and legal liability blocks, and concluding with category-based restrictions. Advanced configuration settings are explored, including suspicious new domain lookups, embedded site categorization, HTTP tunnel control, and domain fronting protections. The tutorial emphasizes using FQDNs rather than IP addresses in custom URL categories and enabling the retain parent category option to simplify policy troubleshooting and ensure URLs are evaluated against both original and custom categories.

Chapters

0:00 - Introduction
0:14 - URL Filtering Objectives
1:56 - Example Policy Structure
3:45 - Advanced Settings Configuration
5:43 - Conclusion

Key Quotes

0:45 "Zscaler recommends you begin building URL filtering policy by starting from your corporate acceptable use policy."
1:22 "Zscaler recommends blocking the legal liability, malicious, and suspicious categories entirely."
4:32 "This will allow you to create policy to block the Newly Registered and Observed Domains and Newly Revived Domains categories, which contain domains that are often used as part of phishing or malware distribution campaigns."

Categories:
  • » Cybersecurity » Zero Trust
  • » Webinar Library » Zscaler
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Cloud Security
  • SASE
  • SSE
  • Best Practices
  • Technical Deep Dive
  • How-To
  • URL filtering policy
  • Zero Trust security
  • Web security controls
  • Category-based filtering
  • Cloud security policy
  • Threat protection
  • Domain fronting prevention
  • HTTP tunnel control
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: URL Filtering Policy Best Practices in Zscaler

              Upcoming Webinar Calendar

              • 06/23/2026
                01:00 PM
                06/23/2026
                The AI-Powered VMware Alternative
                https://www.truthinit.com/index.php/channel/2009/the-ai-powered-vmware-alternative/
              • 06/24/2026
                11:00 AM
                06/24/2026
                Accelerating Through AI: A Dynamic Webinar Series
                https://www.truthinit.com/index.php/channel/2012/accelerating-through-ai-a-dynamic-webinar-series/
              • 06/25/2026
                01:00 PM
                06/25/2026
                Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier
                https://www.truthinit.com/index.php/channel/1998/generative-ai-security-preventing-ai-from-becoming-a-data-breach-multiplier/
              • 06/30/2026
                01:00 PM
                06/30/2026
                Mastering Active Directory Certificate Services for Long-Term Success
                https://www.truthinit.com/index.php/channel/2018/mastering-active-directory-certificate-services-for-long-term-success/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Integrating Security in AI: Automated Red Teaming Strategies for Private Models
                https://www.truthinit.com/index.php/channel/1969/integrating-security-in-ai-automated-red-teaming-strategies-for-private-models/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Schutz von KI in Anwendungen, Agenten und APIs.
                https://www.truthinit.com/index.php/channel/2008/schutz-von-ki-in-anwendungen-agenten-und-apis/
              • 07/01/2026
                01:00 PM
                07/01/2026
                Preventing Your AI from Turning Against You: Essential Strategies
                https://www.truthinit.com/index.php/channel/2021/preventing-your-ai-from-turning-against-you-essential-strategies/
              • 07/02/2026
                10:00 AM
                07/02/2026
                When the cloud goes dark: Resilience lessons from hybrid threats
                https://www.truthinit.com/index.php/channel/2011/resilience-insights-from-hybrid-threats-when-the-cloud-faces-challenges/
              • 07/07/2026
                01:00 PM
                07/07/2026
                A Comprehensive Demonstration of DLP Solutions and Strategies
                https://www.truthinit.com/index.php/channel/2030/a-comprehensive-demonstration-of-dlp-solutions-and-strategies/
              • 07/09/2026
                01:00 PM
                07/09/2026
                The HUMAN Experience: Empowering Trust Through Action and Engagement
                https://www.truthinit.com/index.php/channel/2026/the-human-experience-empowering-trust-through-action-and-engagement/
              • 07/14/2026
                01:00 PM
                07/14/2026
                Crafting a Championship-Quality Security Team for Unmatched Defense
                https://www.truthinit.com/index.php/channel/2025/crafting-a-championship-quality-security-team-for-unmatched-defense/
              • 07/21/2026
                04:00 AM
                07/21/2026
                Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
              • 07/21/2026
                01:00 PM
                07/21/2026
                HUMAN Dialogue: Insights from Attackers Revealed at the FIFA World Cup
                https://www.truthinit.com/index.php/channel/2029/human-dialogue-insights-from-attackers-revealed-at-the-fifa-world-cup/
              • 07/22/2026
                06:30 AM
                07/22/2026
                Understanding the Dynamics of Data Privacy and Protection Regulations
                https://www.truthinit.com/index.php/channel/2000/understanding-the-dynamics-of-data-privacy-and-protection-regulations/
              • 07/28/2026
                01:00 PM
                07/28/2026
                Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
              • 07/29/2026
                04:00 AM
                07/29/2026
                Real-Time Strategies for Safeguarding Against Prompt Injections
                https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
              • 09/30/2026
                04:00 AM
                09/30/2026
                AI Command Center: Optimizing Visibility and Control in Your Operations
                https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/

              Upcoming Events

              • Jun
                23

                The AI-Powered VMware Alternative

                06/23/202601:00 PM ET
                • Jun
                  24

                  Accelerating Through AI: A Dynamic Webinar Series

                  06/24/202611:00 AM ET
                  • Jun
                    25

                    Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier

                    06/25/202601:00 PM ET
                    • Jun
                      30

                      Mastering Active Directory Certificate Services for Long-Term Success

                      06/30/202601:00 PM ET
                      • Jul
                        01

                        Schutz von KI in Anwendungen, Agenten und APIs.

                        07/01/202604:00 AM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version