Block All Websites, Allow Specific Sites in Windows Server

Block all websites and allow only specific websites in Windows Server with a LAN proxy, test the allowlist, and fix common browser issues fast.
A Windows server behind a glowing blue barrier with a few secure website pathways passing through.

To block all websites and allow only specific websites in Windows Server, configure a loopback proxy in Internet Options and add an exception list for approved domains. You can apply it in about ten minutes, but remember that this is a per-user WinINet setting for compatible browsers and desktop apps, not a substitute for an organization-wide web filter.

Prerequisites

  • A Windows Server 2019, Windows Server 2022, or Windows Server 2025 installation with an interactive desktop session.
  • An RDP session with a local administrator account, or a user account that can change its own Internet Options.
  • The exact domains to allow, including any separate sign-in, update, API, or content-delivery domains that the permitted service needs.
  • A browser that uses the Windows system proxy settings, such as Microsoft Edge, and a second website to use as a blocked test.
  • If you need a Windows environment for this configuration, see VPSLake Windows RDP hosting.

This procedure changes the settings for the Windows user who performs it. Other user profiles on the server keep their own proxy configuration unless an administrator deploys a managed policy.

Step 1: Record the current proxy settings

Saving the current values gives you a quick reference if the server already uses a corporate proxy or automatic configuration script.

Open Windows PowerShell as the user whose browsing you want to restrict and run:

Get-ItemProperty -Path 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Internet Settings' -Name ProxyEnable,ProxyServer,ProxyOverride -ErrorAction SilentlyContinue | Select-Object ProxyEnable,ProxyServer,ProxyOverride

The output may be empty or may show an existing configuration. A new, direct connection commonly looks like this:

ProxyEnable ProxyServer ProxyOverride
----------- ----------- -------------
          0

Do not remove an existing proxy, PAC URL, or bypass list without checking with the person who manages the network. The LAN method replaces that user’s current proxy behavior.

Step 2: Open the LAN proxy settings

Internet Options is the control panel that stores the per-user WinINet proxy values used by many Windows desktop browsers.

Use either route:

  • Press Windows key + R, enter inetcpl.cpl, and select OK.
  • Or open Control Panel → Network and Internet → Internet Options.

Select Connections → LAN settings. Clear Automatically detect settings if you do not want Windows to discover a different automatic configuration, then select Use a proxy server for your LAN.

Step 3: Send non-allowed web requests to the loopback address

The loopback address keeps the proxy endpoint on the server; choosing a local port with no listening service makes a non-exempt request fail instead of reaching the public internet.

In LAN Settings, enter the following values:

  • Address: 127.0.0.1
  • Port: 9
  • Bypass proxy server for local addresses: leave this unchecked.

Port 9 is only a local sink in this procedure; it is not an internet service you need to install. Do not use a port occupied by another local proxy or application, because that service could receive the requests.

Select Advanced. If the dialog displays separate protocol fields, make sure HTTP and Secure both use 127.0.0.1 and port 9, or leave Use the same proxy server for all protocols selected. This matters for HTTPS sites as well as plain HTTP sites.

Microsoft documents these settings as WinINet connection options. Applications that do not read the Windows Internet Options proxy may require their own proxy configuration, so this method is most predictable in a supported desktop browser. See Microsoft’s proxy configuration guidance for the scope and application differences.

Step 4: Add the allowed domains as proxy exceptions

Exceptions bypass the loopback proxy, allowing those destinations to connect directly while other proxy-aware requests still go to 127.0.0.1:9.

In the Exceptions box labeled Do not use proxy server for addresses beginning with, enter domains separated by semicolons. For example:

example.com;*.example.com;docs.example.net;*.docs.example.net

Do not include https://, a path, or a trailing slash. Add both the bare domain and a wildcard form when you need the root domain and its subdomains. If the allowed site uses a separate login or API hostname, add that hostname too.

Select OK in the Advanced window, select OK in LAN Settings, and then OK in Internet Options. Close every affected browser window and reopen it so existing connections and cached proxy decisions do not remain in use.

Step 5: Check that the proxy and exceptions were saved

Reading the current user’s Internet Settings confirms the values before you troubleshoot a browser.

Run this in PowerShell under the same Windows account:

Get-ItemProperty -Path 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Internet Settings' -Name ProxyEnable,ProxyServer,ProxyOverride | Select-Object ProxyEnable,ProxyServer,ProxyOverride

For the example above, expect values similar to:

ProxyEnable ProxyServer  ProxyOverride
----------- -----------  -------------
          1 127.0.0.1:9 example.com;*.example.com;docs.example.net;*.docs.example.net

Confirm that no process is listening on the selected sink port. A zero count is the expected result:

@((Get-NetTCPConnection -LocalAddress 127.0.0.1 -LocalPort 9 -State Listen -ErrorAction SilentlyContinue)).Count
0

If the count is greater than zero, return to Internet Options → Connections → LAN settings and choose an unused local port, then update the protocol fields in Advanced to match it.

Verify the website allowlist

Open the browser again and test both sides of the rule:

  1. Browse to an approved domain, such as https://example.com. It should load normally because it is in the bypass list.
  2. Browse to a domain that is not listed. The browser should report that the proxy connection failed or that the page cannot be reached; it should not load the site directly.
  3. Test a subdomain separately. A bare entry such as example.com may not cover every subdomain in the way you intend, so include *.example.com when subdomains are part of the allowlist.

The Microsoft WinINet proxy documentation explains the ProxyEnable, ProxyServer, and ProxyOverride values and why applications can behave differently. The registry check proves that the settings were saved; the browser tests prove how the selected browser applies them.

Troubleshooting

An unlisted website still opens

The browser or application may be ignoring WinINet, using its own proxy setting, or connecting through a VPN or direct tunnel. Test in a newly opened Edge window first, then inspect the application’s own network settings. If users must not bypass the rule, use a managed filtering proxy, Group Policy, or an egress firewall rather than relying on this per-user convenience setting.

An allowed website shows a proxy error

The exception may omit the hostname that actually serves the page, login, API, or static content. Add the required hostnames without URL schemes, include both the root and wildcard forms where appropriate, save the dialog, and fully restart the browser. A site that requires many third-party domains may not be suitable for a small manual exception list.

Every website stopped working, including allowed sites

Check that the Secure proxy field also points to 127.0.0.1 on the selected port and that the allowed entry has no https:// prefix or path. Also check that another local service is not already using the sink port. If the server previously used an organization proxy, restore that approved address instead of leaving a loopback proxy enabled.

The LAN settings are locked or keep changing

A domain Group Policy, management tool, PAC file, or per-machine proxy policy may control the setting. Review Internet Options → Connections → LAN settings, ask the Windows administrator to check the applied policy, and do not repeatedly overwrite a centrally managed configuration. A local change may be reverted at the next policy refresh.

Hardening

  • Apply the setting separately to each user profile that needs the allowlist, or deploy a centrally managed policy when the rule is an administrative requirement.
  • Keep the allowlist short and document why each domain is required; web applications often add new service hostnames over time.
  • Treat this as browser-level access control. It does not block DNS lookups, raw IP connections, non-proxy-aware software, VPNs, or other network protocols.
  • To undo the LAN method, open Internet Options → Connections → LAN settings, clear Use a proxy server for your LAN, remove the exceptions if they are no longer needed, and select OK. Restore the original proxy or automatic configuration from Step 1 if one existed.

FAQ

Does this block websites for every Windows Server user?

No. Internet Options stores the normal WinINet values per user, so each account can have a different proxy and exception list. Use Group Policy or a network filtering device when the rule must cover all users and applications.

Can I allow a full URL instead of a domain?

No. The bypass field matches hostnames and patterns, not complete URLs with schemes, paths, or query strings. Enter the host portion, such as portal.example.com, and add any other hostnames required by that service.

Why do I need to include both example.com and *.example.com?

The root host and its subdomains are separate destinations. Listing both makes the intended scope clear and allows requests such as www.example.com or api.example.com when the browser or application uses them.

Is a loopback proxy a complete security control?

No. It is a practical per-user restriction for compatible browsers, but an application can ignore WinINet or use another route. For enforced web access control, combine centrally managed policy with an authenticated filtering proxy or outbound firewall rules.

Samrat Ghosh
Written by

Samrat Ghosh

Founder & Infrastructure Engineer

Samrat Ghosh is the founder of VPSLake, where he builds and runs the remote desktop and VPS hosting infrastructure the company is built on. He writes hands-on guides about RDP, Windows Server, VPS management and secure remote access - the practical documentation he wishes had…

Previous Article

Allow a Port in Windows Server 2025 Firewall

Write a Comment

Leave a Comment

Your email address will not be published. Required fields are marked *

Subscribe to our Newsletter

Subscribe to our email newsletter to get the latest posts delivered right to your email.
Pure inspiration, zero spam ✨