Security Policy

Two things that are not about which sites people reach: which accounts they may sign into, and what may leave in the body of a request.

Set policy1 min readApplies to the Fowlguard console

Identity restriction

A domain check alone does not stop somebody signing into a personal account on a service you use for work. These settings push that check down to the provider, which is the only place that can tell one account from another on the same domain.

Microsoft Entra tenant ID and cross-tenant access policy GUID name your Microsoft tenant. A personal Microsoft account belongs to no tenant and would otherwise slip past a domain check.

Google Workspace domains, one per line, is what blocks consumer Gmail. Any domain not named here fails Google's own check, so there is no separate switch for it.

ChatGPT workspace IDs and Claude organization IDs, one per line, do the same for those services: the account must belong to a workspace or organization you have named.

Data-loss prevention

Inspects the body of a request for content you have said must not leave.

Act from tier and minimum confidence decide how sure a match must be before the action applies. Raising confidence means fewer false positives and more that slips through; lowering it means the reverse. There is no setting that avoids both.

Never inspect these hosts, one per line, sits on top of a built-in list of financial, healthcare and government destinations that is always skipped and cannot be narrowed. That built-in list is not a preference: inspecting the body of a request to a bank or a health portal is unlawful in several jurisdictions.

Something missing or unclear? Write to hello@fowlguard.com and we will add it.