Getting Started
How To Activate Your USS Account.
USS Dashboard Walk Through.
Web Security Getting Started Guide
Cloud Application Security Rules and Reporting.
Email Security: Quick Start for Microsoft 365.
Analytics
Activity Reports
Charts
Schedules
Data retention periods
Admin Auditing
Account Settings
Settings
Licenses
Notifications
Branding
Cloud App. Security (CASB)
Knowledge Base
Events not arriving for Office 365 Onedrive or Sharepoint
Overview
App Catalog
API Integrations
App Catalog List
Cloud Multi-factor authentication (MFA)
Managing an MFA lock-out
Count how many users are in an AD group
ADFS Login not being intercepted for MFA
Configure FortiGate to use PAP for Challenge-Response
Quick Start
Rules Engine Concepts
Authentication Client (server)
Authentication App (enduser)
MFA - Product Configuration
Third Party Guides
Configuring Windows Logon Protection
Configuring RADIUS Protection
Deploying the Cloud MFA Authentication App
Configuring RD Web Access using IIS Website Protection
Products not supporting RADIUS Challenge-Response
Configuring AD FS Protection
Compliant Email Archive (CEA)
User Guide
CEA User Guide
Viewing and Managing History in CEA
Using the CEA Outlook Add-in
Viewing and Managing Spaces in CEA
Managing Deletion Requests from CEA
Installing the Outlook Add-in for CEA
Legal Hold in CEA
Authorised Delete in CEA
Viewing and Managing CEA results
Google Workspace
Configuring Google Workspace OAuth and Service Account
Integrate Gmail with a CEA
CEA - Data storage explained
Compliant Email Archive Quick Start Guide
Understanding Data Guardians
Email Archive End User Guide
Configuring journaling on Exchange 365
Configuring authentication with O365 via OAuth
Ingest mail via Mailbox Reader with MSGraph
Configuring an Impersonation Account
Folder Replication Configuration
Assigning delegation via OAuth with User Directory
Compliant Email Archive - LDAP Configuration
Configuring journaling for Exchange and Office 365
Configuring a local user account
Re-enabling Outlook Homepage Tab
Ingest mail via Mailbox Reader for Exchange 2013 - 2019
Ingest mail via Mailbox Reader
End User Email Archive Authentication with ADFS
Data Loss Prevention (DLP)
Grammar Regular Expression Engine
Applying a DLP policy in Email Security
Grammar Entity Short Names
DLP Policies
Email Security (EMS)
Email Security Configuration
EMS - Message Rules
Connection Rules
Custom rule Data
Global Quarantine
Personal Quarantine
Spam Deny List
Spam Safe List
Mailboxes
Group Management
EMS - Product Configuration
Configuration Recommendations
How to avoid multiple disclaimers being added when forwarding or replying to emails
Executive Tracking
Nearby Domain Rule
Configuring TLS encryption
LinkScan: on-demand URL protection
Configure outbound DMARC
Configure outbound DKIM
How to Prefix a banner to inbound emails
Executive Tracking with Subject
IP Geolocation Connection Rule
Display Name Detection
How to configure Authenticated Received Chain (ARC) Inbound
How to use the Domain Name Detection rule
Empty Body Detection
How does DMARC work?
Reject oversized emails
MX records and IP addresses
MX records and IP addresses for all regions
MX records and IP addresses for EU customers
MX records and IP addresses for USA customers
MX records and IP addresses for UAE customers
MX records and IP addresses for India customers
Office 365
Post Delivery Email Deletion (Retract)
Configure Office 365 for EMS
Safelisting Email Security IP addresses in Office 365
Configure Inbound mail on Office 365 to reject non-EMS emails.
Managing DNS in Office 365
Example Rules
Digest generation and Quarantines
Blocking emails from hacked Gmail accounts
Stop specific users from receiving Word documents
Detect credit card numbers in an email
Disable spam filtering for specific mailboxes
CoreService filter classifications
Configure GMail using Google Workspace for EMS
Configure outbound email for Exchange 2007/2010
Configure outbound email for Exchange 2016
Bulk Email & Fair Usage
Queue retention and retry times
Personal Safe Lists and Personal Deny Lists
Reject message due to message “550 5.1.8 sender denied”
Email Sandbox - Supported file types
[Marketing Medium] or [High Medium] prefixed to the subject of mails
DMARC Failure Reporting
What happens when my Email Security license is suspended or deleted?
Example Spam Digest or Quarantine Report
How to onboard users into the End User Portal
Cisco Fixup Protocol
Adding images to email disclaimers
Reject Top Level Domains
Adding an alias to a primary mailbox
Temporary Server Error
Unable to Relay error on outbound email
Notify Recipient/Sender Actions
Reject Disabled user accounts (mailboxes)
DLP Dictionaries
Activate the Quarantine Portal for Spam Digest users
DMARC Abuse Report received even though it passes DMARC
Unable to forward emails from Microsoft 365 accounts
How to use Custom Rule Data (formerly Dictionaries)
HTML attachments
How to block double extension filenames
Manage Mailboxes using the API
Email Security: Best Practice Guide
How to work with System Locked rules
How to detect simplified Chinese character sets
Placeholders for inserting message data into actions
Creating Custom Digests
Advanced Email Sandbox - Overview
Redirect emails to a different address
Configuring MTA-STS and TLS-RPT (Inbound)
Outlook Plugin
Outlook Add-in V2
Installing the Outlook add-in for Email Security
Outlook add-in is not the newest version
Upgrade Outlook Add-in for reporting spam and phishing email
Securemail (add-on)
SecureMail concepts explained
Configuring SecureMail
Using the SecureMail dashboard
Email Security Troubleshooting
Reporting spam or false positives
Insufficient system resources message on inbound email delivery
Outbound Delivery error: 550 Unable to relay
No Valid MX Record NDR message
Why do I see No SMTP transport in Email activity?
Email Security Common Problems
Identifying Spoofed Emails
DMARC Fail: Alignment reporting
Email Security: Quick Start
Email Security: Quick Start for Google Workspace
EMS - Default Rules
General
What's new ?
Understanding Product Usage
Service IP addresses and ports
End of Life
Supported Browsers
Legal
Introduction
Privacy Policy
Master Services Agreement (MSA)
Standard Contractual Clauses (SCCs)
Website Usage and Cookie Policies
Log Streaming
Log Streaming Overview
Log Streaming to Microsoft Sentinel
Log Streaming record format
Log Streaming to Rapid7 InsightIDR
Log Streaming to Amazon S3
Log Streaming to Google Cloud Storage
Log Streaming for Splunk Enterprise or Cloud
Log Streaming to Sumo Logic
Product Settings
Administrators
Single Sign On
Active Directory
AD Connect software
Roles (RBAC)
Keyword Lists
Devices & Groups
Active Directory Synchronisation Explained
Active Directory Object Synchronisation
Account Password and MFA
Role Builder
Granting access to synchronise Entra ID shared mailboxes
Add the Exchange Online API permission to an existing AAD connection
Verify that Azure AD permissions are granted for Shared Mailbox sync
Google Workspace synchronisation
Posture Management
Posture Management Overview
Posture Management Dashboard (Homepage)
Connectors
Posture Management Scanning
Posture Management Activity and AI Remediation
Alerts
Controls Management
AWS Onboarding Guide
Google Cloud Platform Onboarding Guide
Microsoft 365 Onboarding Guide
Microsoft Azure Onboarding Guide
Salesforce Onboarding Guide
Configuring Microsoft Teams alerts
Upgrade Notice
Security Awareness Training (SAT)
SAT - User Guide
Safelisting
Google Workspace - SAT Safelisting
How to allow download of images within emails
M365 - SAT Safelisting
Reports
How is the Risk Score calculated?
How do I Access the SAT Portal as a New User via Email?
How do I reset my SAT password?
Web Security (WS)
Web Security Configuration
Filter Rules
Feature Control Rules
Browser Categories
Custom URLs
Bypass Categories
Deployment Section.
Agent Configuration Profiles
Unblock Requests
Web Security: Product Configuration
Prevent Law features for UK organisations
USS Agents
USS Agent for Windows
Deploying the USS Agent for Windows
Deploying via Wizard
Deploying via Startup/Shutdown script
Deploying the Windows agent via a custom MSI
Deployment via GPO
Deploying via Microsoft Intune
Command-line parameters for the USS Agent for Windows.
Installing the USS Agent for Windows SSL certificate in Firefox.
Deploying the USS agent for Windows via Microsoft SCCM
Changelog - Windows Agent
Configuration options for the Windows agent type
Download Microsoft Windows agent
Requirements for the USS Agent for Windows
Processes used by USS Agent for Windows
USS Agent for MacOS
Deploying the USS Agent for Mac OS X
Install - Deploying the USS Agent for Mac OS X via Wizard.
Command-line parameters For the USS Agent for Mac OS X
Deploying the USS Agent for Mac OS X via JAMF
Requirements for the USS Mac OS X agent
Changelog - MacOS Agent
Download macOS Agent
Configuration options for the Mac OS X USS agent.
USS Agent for Chromebook
Deploying the USS Agent for ChromeBook
Deploying Chromebook agent via Google Admin console
Requirements
Changelog - Chromebook Agent
Download Chromebook agent
Configuration options for the USS Chromebook agent.
USS Gateway
Deploying the USS Gateway
USS Gateway - Requirements
Installation of the USS Gateway
Installing the USS Gateway on Microsoft Hyper-V
Deploying Web Browser proxy settings for the USS Gateway.
Migrating the SSL intercept certificate to a new gateway
Preparing the USS Gateway for use with a load balancer
Client Deployment options for explicit proxying to the USS Gateway.
Configuring USS Gateway to work with LoadBalancer.org software load balancer
Third Party Load Balancer Guides
Change the default listening port for the USS Gateway proxy
Installing an SSL Certificate on iOS 13 onwards.
USS Gateway Configuration
Authentication & Identification
Network
USS Gateway Time & NTP Settings
USS Gateway System Settings
USS Gateway Advanced configuration
Configuration options for the USS Gateway agent.
USS Gatewat Charts
Download Gateway Virtual Machine
Changelog - USS Gateway.
Web Security Troubleshooting
USS Mac OS X Agent Troubleshooting
USS Mac OS X Agent Log File Storage
Collecting debug information - USS Agent for Mac OS X
Processes used by the USS Agent for Mac OS X
USS Agent for Mac OS X Tray icon status codes.
Microsoft Teams Bypass Exception list on mac OS
Safari 17 Proxy Exceptions limit on a USS Mac OS X Agent.
USS Windows Agent Troubleshooting
How to disable Device Guard or Credential Guard
USS Window Agent Tray icon status codes
Temporary files generated by the endpoint agent software
USS Windows Agent Log File Storage
Incompatibility with nmap based products such as Wireshark
Collecting debug information - USS Agent for Windows
Using USS Windows Agent Web Security with Sophos
Windows agent - force download of anti-malware database
Change the default USS Windows agent configuration poll time.
USS Gateway Troubleshooting
Regular Gateway server maintenance
Accessing the USS Gateway Command Line
Resetting the Ubuntu Password To Log Into Gateway Command Line
Captive Portal on Samsung Devices
"The Requested Content Was Blocked" Error Message on a USS Gateway
Resizing a Partition in ESX Server Virtual Machine
Interception of iOS and Android apps (SSL Pinning)
Using an intermediate CA signed by Windows DC root CA
Updating the USS Gateway
Upgrading the USS Gateway from 20.04 LTS to 22.04 LTS.
Importing an SSL Certificate into the USS Gateway
Collecting debug information - USS Gateway
Adding a Static Route on a USS Gateway.
Chromebook Allowlist USS Gateway Proxy
Disable QUIC in Chrome Browser
Take a Packet Capture From the USS Gateway Command Line.
Check for the presence of a system proxy user
USS Gateway failing to install
ERR_CERT_HAS_EXPIRED_ Digicert certificate expiry 2023
How to add a Static Route to the USS Gateway
CVE-2020-15778
YouTube Safe or Restricted mode enforced by DNS on a USS Gateway.
Troubleshooting Web Security Filter Rules.
Bypassing Office 365
Unclassified / Uncategorised Site Processing
Censornet Web Filtering Policy and Approach for Education
List of domains to bypass apps for SSL Interception on the USS Gateway.
Blocking Embedded Games in Google Search
Enable Enhanced Unpacking Engine
MIME Categories and Types
How to submit a URL reclassification request
What happens when my Web Security license is suspended or deleted?
SSL/TLS Strict Mode blocked ciphers
Export Agents using curl script
Custom URL parsing and overlapping patterns
Web Security Common Problems
Allow partial websites/specific YouTube videos
Gateway failing to join the domain - the address handle that was given to the transport was invalid
Gateway proxy authentication pop-up login dialog
Bypasses not applying
USS Gateway IP changes unexpectedly
Global Web Filtering Coverage
Web Categories List
Fair Usage Policy for Web & CASB (Inline)
All Categories > Product Settings
15 articles
Administrators are users that are created within the Unified Security Service system itself and are unrelated to any users belonging to an Active Directory connection. Your Cloud USS account must hav…
Updated 2 months ago
The USS dashboard can use Office 365 (Azure Active Directory) as a source for authenticating administrator users, meaning anyone with an approved Microsoft account can can single sign on in to the da…
Updated 1 month ago by admin
The Active Directory section allows you to configure synchronisation of one or more Active Directory domains with the USS cloud account. The advantage of this is that you can use Active Directory att…
Updated 2 years ago
AD Connect is a service, that can be installed on a Windows server in your local network in order to synchronize selected AD objects (users, groups and OUs) to the CensorNet USS Cloud Service. If you…
Updated 10 months ago
The following administrator user Roles are supported: Super User - full access to all dashboard capabilities. Agent Installer - restricted user capable of installing endpoint agents, AD Connect agent…
Updated 3 weeks ago
Keyword Lists are user-created collections of keywords patterns, which can be used to identify URLs and App Content as part of the Keyword Category Match in Filter Rules. Typically, Keyword Lists are…
Updated 4 years ago
The Devices & Groups section allows you to map MAC addresses and IP addresses to device names and also group them together. This allows you to easily reference devices or groups of devices in USS pro…
Updated 11 months ago
General. Active Directory connections are shared across all licensed products. Think carefully about whether you need multiple Active Directory connections as doing so could lead to duplicate objects…
Updated 2 years ago by admin
The following table describes the Active Directory object types and their synchronisation status when using the AD Connect client or service. Object AD Connect (on-premise) with Exchange Server 2010…
Updated 3 years ago by admin
To change your administrator password or configure a second authenticator factor, log in to the dashboard and click the key icon in the top right corner: Change your account password. Click the Passw…
The Role Builder allows you to define custom access to the dashboard using ACL-style permissions and share the defined roles with other accounts. This advanced section allows fine grained control to…
IMPORTANT: Due to a recent Microsoft Azure update, some customers may not be able to assign the role in step 4 below via the Azure portal. Please see the Command Line steps at the end of the article…
This article applies if you have an existing Azure Active Directory connection in Settings -> Active Directory and you wish to be able to identify shared mailboxes. By default, shared mailboxes synch…
Updated 4 years ago by admin
This article relates to Granting access to synchronise Azure AD shared mailboxes and describes how to confirm the necessary Exchange.ManageAsApp is granted. Open the Microsoft Entra admin center at M…
Updated 3 months ago by admin
This article explains how to set up and configure Google Workspace user and group synchronisation. Google Workspace can be used with the Email Security and Cloud MFA modules. Log in to Google Workspa…
Updated 4 months ago by admin
Powered by HelpDocs (opens in a new tab)