{"id":807,"date":"2026-10-11T03:00:00","date_gmt":"2026-10-11T03:00:00","guid":{"rendered":"https:\/\/vpslake.com\/blog\/?p=807"},"modified":"2026-10-11T03:00:00","modified_gmt":"2026-10-11T03:00:00","slug":"block-websites-allow-specific-sites-windows-server","status":"publish","type":"post","link":"https:\/\/vpslake.com\/blog\/2026\/10\/11\/block-websites-allow-specific-sites-windows-server\/","title":{"rendered":"Block All Websites, Allow Specific Sites in Windows Server"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">To block all websites and allow only specific websites in Windows Server, configure a loopback proxy in Internet Options and add an exception list for approved domains. You can apply it in about ten minutes, but remember that this is a per-user WinINet setting for compatible browsers and desktop apps, not a substitute for an organization-wide web filter.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Prerequisites<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>A Windows Server 2019, Windows Server 2022, or Windows Server 2025 installation with an interactive desktop session.<\/li>\n\n\n<li>An RDP session with a local administrator account, or a user account that can change its own Internet Options.<\/li>\n\n\n<li>The exact domains to allow, including any separate sign-in, update, API, or content-delivery domains that the permitted service needs.<\/li>\n\n\n<li>A browser that uses the Windows system proxy settings, such as Microsoft Edge, and a second website to use as a blocked test.<\/li>\n\n\n<li>If you need a Windows environment for this configuration, see <a href=\"https:\/\/vpslake.com\/buy-windows-rdp\">VPSLake Windows RDP hosting<\/a>.<\/li>\n\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This procedure changes the settings for the Windows user who performs it. Other user profiles on the server keep their own proxy configuration unless an administrator deploys a managed policy.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Step 1: Record the current proxy settings<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Saving the current values gives you a quick reference if the server already uses a corporate proxy or automatic configuration script.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Open <strong>Windows PowerShell<\/strong> as the user whose browsing you want to restrict and run:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Get-ItemProperty -Path 'HKCU:\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings' -Name ProxyEnable,ProxyServer,ProxyOverride -ErrorAction SilentlyContinue | Select-Object ProxyEnable,ProxyServer,ProxyOverride<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The output may be empty or may show an existing configuration. A new, direct connection commonly looks like this:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ProxyEnable ProxyServer ProxyOverride\n----------- ----------- -------------\n          0<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Do not remove an existing proxy, PAC URL, or bypass list without checking with the person who manages the network. The LAN method replaces that user\u2019s current proxy behavior.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Step 2: Open the LAN proxy settings<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Internet Options is the control panel that stores the per-user WinINet proxy values used by many Windows desktop browsers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Use either route:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>Press <code>Windows key + R<\/code>, enter <code>inetcpl.cpl<\/code>, and select <strong>OK<\/strong>.<\/li>\n\n\n<li>Or open <strong>Control Panel \u2192 Network and Internet \u2192 Internet Options<\/strong>.<\/li>\n\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Select <strong>Connections \u2192 LAN settings<\/strong>. Clear <strong>Automatically detect settings<\/strong> if you do not want Windows to discover a different automatic configuration, then select <strong>Use a proxy server for your LAN<\/strong>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Step 3: Send non-allowed web requests to the loopback address<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The loopback address keeps the proxy endpoint on the server; choosing a local port with no listening service makes a non-exempt request fail instead of reaching the public internet.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In <strong>LAN Settings<\/strong>, enter the following values:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li><strong>Address:<\/strong> <code>127.0.0.1<\/code><\/li>\n\n\n<li><strong>Port:<\/strong> <code>9<\/code><\/li>\n\n\n<li><strong>Bypass proxy server for local addresses:<\/strong> leave this unchecked.<\/li>\n\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Port <code>9<\/code> is only a local sink in this procedure; it is not an internet service you need to install. Do not use a port occupied by another local proxy or application, because that service could receive the requests.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Select <strong>Advanced<\/strong>. If the dialog displays separate protocol fields, make sure <strong>HTTP<\/strong> and <strong>Secure<\/strong> both use <code>127.0.0.1<\/code> and port <code>9<\/code>, or leave <strong>Use the same proxy server for all protocols<\/strong> selected. This matters for HTTPS sites as well as plain HTTP sites.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft documents these settings as WinINet connection options. Applications that do not read the Windows Internet Options proxy may require their own proxy configuration, so this method is most predictable in a supported desktop browser. See Microsoft\u2019s <a href=\"https:\/\/learn.microsoft.com\/en-us\/troubleshoot\/windows-server\/networking\/configure-proxy-server-settings\" target=\"_blank\" rel=\"noopener\">proxy configuration guidance<\/a> for the scope and application differences.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Step 4: Add the allowed domains as proxy exceptions<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Exceptions bypass the loopback proxy, allowing those destinations to connect directly while other proxy-aware requests still go to <code>127.0.0.1:9<\/code>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In the <strong>Exceptions<\/strong> box labeled <strong>Do not use proxy server for addresses beginning with<\/strong>, enter domains separated by semicolons. For example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>example.com;*.example.com;docs.example.net;*.docs.example.net<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Do not include <code>https:\/\/<\/code>, a path, or a trailing slash. Add both the bare domain and a wildcard form when you need the root domain and its subdomains. If the allowed site uses a separate login or API hostname, add that hostname too.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Select <strong>OK<\/strong> in the Advanced window, select <strong>OK<\/strong> in LAN Settings, and then <strong>OK<\/strong> in Internet Options. Close every affected browser window and reopen it so existing connections and cached proxy decisions do not remain in use.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Step 5: Check that the proxy and exceptions were saved<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Reading the current user\u2019s Internet Settings confirms the values before you troubleshoot a browser.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Run this in PowerShell under the same Windows account:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Get-ItemProperty -Path 'HKCU:\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings' -Name ProxyEnable,ProxyServer,ProxyOverride | Select-Object ProxyEnable,ProxyServer,ProxyOverride<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">For the example above, expect values similar to:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ProxyEnable ProxyServer  ProxyOverride\n----------- -----------  -------------\n          1 127.0.0.1:9 example.com;*.example.com;docs.example.net;*.docs.example.net<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Confirm that no process is listening on the selected sink port. A zero count is the expected result:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>@((Get-NetTCPConnection -LocalAddress 127.0.0.1 -LocalPort 9 -State Listen -ErrorAction SilentlyContinue)).Count<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>0<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">If the count is greater than zero, return to <strong>Internet Options \u2192 Connections \u2192 LAN settings<\/strong> and choose an unused local port, then update the protocol fields in <strong>Advanced<\/strong> to match it.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Verify the website allowlist<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Open the browser again and test both sides of the rule:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n\n<li>Browse to an approved domain, such as <code>https:\/\/example.com<\/code>. It should load normally because it is in the bypass list.<\/li>\n\n\n<li>Browse to a domain that is not listed. The browser should report that the proxy connection failed or that the page cannot be reached; it should not load the site directly.<\/li>\n\n\n<li>Test a subdomain separately. A bare entry such as <code>example.com<\/code> may not cover every subdomain in the way you intend, so include <code>*.example.com<\/code> when subdomains are part of the allowlist.<\/li>\n\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">The Microsoft <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/wininet\/enabling-internet-functionality\" target=\"_blank\" rel=\"noopener\">WinINet proxy documentation<\/a> explains the <code>ProxyEnable<\/code>, <code>ProxyServer<\/code>, and <code>ProxyOverride<\/code> values and why applications can behave differently. The registry check proves that the settings were saved; the browser tests prove how the selected browser applies them.<\/p>\n\n\n\n<aside class=\"vl-element vl-cta-banner\" aria-label=\"Need a Windows VPS?\">\n\t<div class=\"vl-cta-banner__content\">\n\t\t<p class=\"vl-cta-banner__eyebrow\">Windows Server hosting<\/p>\n\t\t<h3 class=\"vl-cta-banner__title\">Need a Windows VPS?<\/h3>\n\t\t<p class=\"vl-cta-banner__text\">Run a Windows Server desktop with administrator access for controlled browsing and network configuration.<\/p>\n\t<\/div>\n\t<a class=\"vl-cta-banner__button\" href=\"\/buy-windows-rdp\" aria-label=\"View Windows VPS\">View Windows VPS<\/a>\n<\/aside>\n\n\n\n<h2 class=\"wp-block-heading\">Troubleshooting<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">An unlisted website still opens<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The browser or application may be ignoring WinINet, using its own proxy setting, or connecting through a VPN or direct tunnel. Test in a newly opened Edge window first, then inspect the application\u2019s own network settings. If users must not bypass the rule, use a managed filtering proxy, Group Policy, or an egress firewall rather than relying on this per-user convenience setting.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">An allowed website shows a proxy error<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The exception may omit the hostname that actually serves the page, login, API, or static content. Add the required hostnames without URL schemes, include both the root and wildcard forms where appropriate, save the dialog, and fully restart the browser. A site that requires many third-party domains may not be suitable for a small manual exception list.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Every website stopped working, including allowed sites<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Check that the <strong>Secure<\/strong> proxy field also points to <code>127.0.0.1<\/code> on the selected port and that the allowed entry has no <code>https:\/\/<\/code> prefix or path. Also check that another local service is not already using the sink port. If the server previously used an organization proxy, restore that approved address instead of leaving a loopback proxy enabled.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The LAN settings are locked or keep changing<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A domain Group Policy, management tool, PAC file, or per-machine proxy policy may control the setting. Review <strong>Internet Options \u2192 Connections \u2192 LAN settings<\/strong>, ask the Windows administrator to check the applied policy, and do not repeatedly overwrite a centrally managed configuration. A local change may be reverted at the next policy refresh.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Hardening<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>Apply the setting separately to each user profile that needs the allowlist, or deploy a centrally managed policy when the rule is an administrative requirement.<\/li>\n\n\n<li>Keep the allowlist short and document why each domain is required; web applications often add new service hostnames over time.<\/li>\n\n\n<li>Treat this as browser-level access control. It does not block DNS lookups, raw IP connections, non-proxy-aware software, VPNs, or other network protocols.<\/li>\n\n\n<li>To undo the LAN method, open <strong>Internet Options \u2192 Connections \u2192 LAN settings<\/strong>, clear <strong>Use a proxy server for your LAN<\/strong>, remove the exceptions if they are no longer needed, and select <strong>OK<\/strong>. Restore the original proxy or automatic configuration from Step 1 if one existed.<\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">FAQ<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Does this block websites for every Windows Server user?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">No. Internet Options stores the normal WinINet values per user, so each account can have a different proxy and exception list. Use Group Policy or a network filtering device when the rule must cover all users and applications.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Can I allow a full URL instead of a domain?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">No. The bypass field matches hostnames and patterns, not complete URLs with schemes, paths, or query strings. Enter the host portion, such as <code>portal.example.com<\/code>, and add any other hostnames required by that service.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Why do I need to include both <code>example.com<\/code> and <code>*.example.com<\/code>?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The root host and its subdomains are separate destinations. Listing both makes the intended scope clear and allows requests such as <code>www.example.com<\/code> or <code>api.example.com<\/code> when the browser or application uses them.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Is a loopback proxy a complete security control?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">No. It is a practical per-user restriction for compatible browsers, but an application can ignore WinINet or use another route. For enforced web access control, combine centrally managed policy with an authenticated filtering proxy or outbound firewall rules.<\/p>\n\n\n\n<script type=\"application\/ld+json\">{\"@context\": \"https:\/\/schema.org\", \"@type\": \"FAQPage\", \"mainEntity\": [{\"@type\": \"Question\", \"name\": \"Does this block websites for every Windows Server user?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"No. Internet Options stores the normal WinINet values per user, so each account can have a different proxy and exception list. Use Group Policy or a network filtering device when the rule must cover all users and applications.\"}}, {\"@type\": \"Question\", \"name\": \"Can I allow a full URL instead of a domain?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"No. The bypass field matches hostnames and patterns, not complete URLs with schemes, paths, or query strings. Enter the host portion, such as `portal.example.com`, and add any other hostnames required by that service.\"}}, {\"@type\": \"Question\", \"name\": \"Why do I need to include both `example.com` and `*.example.com`?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"The root host and its subdomains are separate destinations. Listing both makes the intended scope clear and allows requests such as `www.example.com` or `api.example.com` when the browser or application uses them.\"}}, {\"@type\": \"Question\", \"name\": \"Is a loopback proxy a complete security control?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"No. It is a practical per-user restriction for compatible browsers, but an application can ignore WinINet or use another route. For enforced web access control, combine centrally managed policy with an authenticated filtering proxy or outbound firewall rules.\"}}]}<\/script>\n\n","protected":false},"excerpt":{"rendered":"Block all websites and allow only specific websites in Windows Server with a LAN proxy, test the allowlist, and fix common browser issues fast.","protected":false},"author":1,"featured_media":808,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"csco_singular_sidebar":"","csco_page_header_type":"","csco_page_load_nextpost":"","footnotes":""},"categories":[5,11],"tags":[45,43,44,42],"class_list":["post-807","post","type-post","status-publish","format-standard","has-post-thumbnail","category-guides","category-windows-server","tag-internet-options","tag-proxy","tag-website-blocking","tag-windows-server","cs-entry"],"_links":{"self":[{"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/posts\/807","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/comments?post=807"}],"version-history":[{"count":1,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/posts\/807\/revisions"}],"predecessor-version":[{"id":3039,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/posts\/807\/revisions\/3039"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/media\/808"}],"wp:attachment":[{"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/media?parent=807"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/categories?post=807"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/tags?post=807"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}