Cloud Apps tab

The cloud service includes a database of cloud applications that can be used to allow or block user access to selected applications.

Click the Cloud Apps tab to configure a list of cloud apps to be blocked and a separate list of cloud apps to be allowed by this policy.

Note: Customers who have licensed and use the Protected Cloud Apps feature will see slight differences when using the Cloud Apps tab for policies for which protected cloud apps should be applied. See Using the Cloud Apps tab with Protected Cloud Apps below.

Steps

  1. Enable Always allow access to cloud apps on the Allow Access list to always permit user access to cloud apps that have been added to the Allow Access list. User requests to these applications are allowed regardless how the corresponding category is configured on the Web Categories tab.

    See Filtering action order for details on how the cloud service applies filtering actions.

  2. Select Block all high risk level applications to block access to any cloud app that is considered high risk.

    The number of high risk applications is provided in a link that can be used to open a scrollable list of the qualifying apps. When the list is open, use your browser search feature to locate specific apps.

  3. Click the link to the Cloud Apps block page to navigate to Web > Block & Notification Pages > Page Details and customize the block page created specifically for blocking user access to cloud apps.
  4. In the Block Access and Allow Access list, select specific cloud apps that should always be blocked, regardless of their risk level.
    1. Use the Risk level and Application Family dropdown filters to narrow down the application choices.

      Applications are organized into three risk categories: High risk, Medium risk, and Low risk. Each category displays the total number of applications available. Expand a category to view applications within that risk level.

    2. Select the app or apps you wish to add to the blocked list by marking the check box next to the app name.

      Important: Apps that have already been included in the Allow Access list cannot be selected. They must first be removed from that list.

      When you select an application for blocking, it becomes greyed out (deactivated) in the Allow Access section and vice-versa, ensuring that one application cannot be both blocked and allowed simultaneously.

    3. You can click Show selected to display only the applications you have already marked.
    4. Click Done when you have finished making your selections. Each selected cloud app is added to the blocked or allowed list.
    5. Remove an app from the list by removing the check mark.

    The number of selected apps included in each risk level is provided next to the risk level name. Cloud apps in the list are sorted alphabetically within each risk level.

    If Block all high risk level applications was enabled, the risk level and total is automatically included in the list. The actual apps are not listed. If one of the high risk apps is specifically selected in the Allow Access list, the count is reduced by the number of high risk apps allowed.

    Important: The Block Access list takes precedence over actions assigned on the Web Categories tab. If a blocked cloud app is requested using a URL categorized in a category that is set to allow, access to it is blocked.

    A count of the number of selected apps is provided above the selection pane. The list is limited to 250 selections. When the limit is reached, search results no longer allow selection of additional apps. An app that was previously selected must first be removed from the list.

  5. Configure application exceptions to create temporary overrides for specific users, groups, or time periods.
    1. In the Application Exceptions section, click Add Exception.
    2. On the Edit Application Exception page, configure the following:
      • State: Check the box to enable the exception.
      • Name: Enter a descriptive name for the exception (e.g., "HR Team ChatGPT Access").
      • Description: (Optional) Provide additional details about the exception's purpose.
      • Action: Select either Allow access or Block access from the dropdown.
      • Time period: Choose when the exception applies:
        • During: Select a specific time period (e.g., "Afternoon")
        • Anytime: Exception applies at all times
        • Outside: Exception applies outside the specified time period
        Optionally, check Apply only when user is roaming to limit the exception to roaming users.
      • Expiry: Choose one:
        • Do not expire: Exception remains active indefinitely
        • Expire after: Specify a date (dd-mm-yyyy format) when the exception should automatically expire and be removed


    3. In the Applications section, select which applications this exception applies to:
      • Expand application families (e.g., COLLABORATION, FINANCE, HR) in the Available applications list.
      • Select one or more applications using the shift and/or control keys to make multiple selections.
      • Use the > arrow to move selected applications to the Selected applications column.
      • Use the < arrow to remove applications from the selection.
    4. Click Save to create the exception.

    Example use case: You have blocked ChatGPT (a Generative AI application) for all users. However, the HR team requires access during afternoon hours for recruitment purposes. Create an exception named "HR Team ChatGPT Access" with Action set to "Allow access", Time period set to "During Afternoon", assign it to the HR group, select ChatGPT in the applications list, and set an expiry date if needed. The HR team will be able to access ChatGPT during the specified time period while the block remains in effect for all other users.

    Note: Application exceptions are displayed in the Application Exceptions table showing Name, Applications, Users/Groups, Action, Applies (time period), Expiry date, and State (enabled/disabled toggle). Expired exceptions are automatically removed from the proxy configuration.
  6. Click Save to apply all Cloud Apps configuration changes.
    Important: Block actions assigned on the Web Categories tab take precedence over the Allow Access list. If a permitted cloud app is requested using a URL categorized in a category that is set to block, access to it is blocked.