# Changing the Rules...

Introducing the fastest, safest, and most reliable internet secure web gateway for your company. With dope.swg, internet security checks are performed at your machine, bypassing datacenters which results in **faster**, **safer**, and more **reliable** performance.

The typical use-case is to prevent access to harmful websites and programs by blocking them in a company-defined policy. However, with legacy SWGs this means sending your information to a third-party datacenter *before* you visit a website, creating a degraded internet experience.

When you install dope.swg, there is no waiting — the controls take place on your machine. There are no stopovers datacenters. It’s fully customizable: you decide where users can go with integrated anti-malware, cloud app controls, and user-based policies.

#### No stopovers, no waiting. It’s a first-class direct flight every time.

### What makes dope.swg better than legacy SWGs?

Like taking a flight, using the internet should be a relaxed experience. Wait times, stopovers, and check-ins are all headaches you don’t need. Using dope.security lets you fly direct to your destination — in first-class.

### It’s Faster

<table><thead><tr><th>Legacy SWGs</th><th>dope.swg</th><th data-hidden></th></tr></thead><tbody><tr><td>Slowed down by datacenter congestion, data outages, or proxy-restrictions, meaning a slower experience for users.</td><td>No stopover datacenters, no datacenter outages. Up to 4x faster performance.</td><td></td></tr></tbody></table>

### It’s Secure

<table><thead><tr><th>Legacy SWGs</th><th>dope.swg</th><th data-hidden></th></tr></thead><tbody><tr><td>Data faces serious security risks. Data can be transferred to other countries or jurisdictions without you knowing.</td><td>No data compromise. No security risk.</td><td></td></tr><tr><td>Decrypt your sensitive data in the cloud at a datacenter. Data safety could be compromised.</td><td>SSL decryption takes place on your device.</td><td></td></tr></tbody></table>

### It’s Reliable

| Legacy SWGs                                                       | dope.swg                                                                                   |
| ----------------------------------------------------------------- | ------------------------------------------------------------------------------------------ |
| Must negotiate datacenter queues, outages, and proxy-restrictions | No stopovers. Worldwide internet connectivity on multiple devices, all the time.           |
|                                                                   | Supports HTTP2 for faster connectivity. Streamlined to work flawlessly on Windows and Mac. |
|                                                                   | No support delays or waiting for upgrades. Out-of-the-box support for Apple M1 Silicon.    |

### It’s Simple

| Legacy SWGs                                                                                                                                        | dope.swg                                                                                                                                                                                                            |
| -------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Legacy SWGs use cloud proxies to manage traffic, from multiple customers, which takes time. This can mean poor performance and reliability issues. | Gives you full control of what users can access.                                                                                                                                                                    |
|                                                                                                                                                    | A fully customizable out-of-the-box base policy speeds up your policy creation.                                                                                                                                     |
|                                                                                                                                                    | <p>Single sign-on: easy email authentication for your network using Google or Office 365.<br>Instant SSO reuses your email corporate login. This gives you one-click 2FA and deprovisioning without the hassle.</p> |
|                                                                                                                                                    | On-board analytics mean you can see how your users are accessing the internet.                                                                                                                                      |

## **Are you ready to fly direct?**


# Quick Start Guide

### Ready to fly direct? Let’s get started.

To use dope.swg, you must have a corporate Google or Microsoft O365 email address. That’s it.

Start your trial at <https://fly.dope.security>.


# Create a dope.swg Account

## Create a tenant using Google or O365

After accessing [fly.dope.security](https://fly.dope.security/), select Google or O365, depending on which corporate email you use:

![](/files/lzd3JBchWLbel3YJjycA)

You will authenticate using your corporate email/password and two-factor authentication (if enabled). The dope.console is automatically single sign on without any configuration

{% hint style="warning" %}
Personal Gmail or Outlook does not work. You must use a corporate Microsoft or Google account
{% endhint %}

## Choose Data Residency Region

We offer a variety of regions to store your [transaction records](#user-content-fn-1)[^1] and will only upload the records to the region you choose. Data is automatically deleted (time-to-live) with a maximum of 30 days (typically less).

{% hint style="info" %}
Learn more about our policies through our [Data Processing Agreement](https://dope.security/legal/dpa)
{% endhint %}

![](/files/RBslFnqVtdz52LK9q4Dl)

Customers can choose one of the of the following locations:

<img src="/files/IHZHiRMGGHcqo6yuf9ng" alt="" data-size="line"> USA

<img src="/files/JggR1YqaME5l4dVjXwwK" alt="" data-size="line"> Germany

<img src="/files/FrIzNHEyDvpb6rhyJFum" alt="" data-size="line"> Bahrain

<img src="/files/IKv00tDAKJNbnwcJ5QUV" alt="" data-size="line"> Singapore

<img src="/files/vf2EeJUiPYHYqhKKlNO6" alt="" data-size="line"> Australia

<img src="/files/3pGu4OB25w0C4kil8pbh" alt="" data-size="line"> Brazil

No Storage - With no storage enabled, data will be sent to your SIEM to help satisfy data-residency laws (e.g. KVKK in Turkey).

#### What other data do we store?

We collect customer user information (device name, username/email, user groups, IP addresses) for administrators to configure policy and monitor endpoints. This is stored in an Active-Active multi-region global database to support failover, disaster recovery, and performance.

Unlike other SWG products the dope.endpoint enforces policy and inspects all content with an on-device proxy — including SSL decryption. The output is analytics/reporting data records that include the user, URL, timestamp, size, and policy result. Customer web traffic never transits our cloud, it remains in the safezone of your endpoint.

#### Agree to Our [EULA](https://dope.security/legal/eula)

[^1]: Logs of all websites, internet requests, including URL, User, Device, etc.


# Get Started with the dope.endpoint

## Download dope.endpoint

To install dope.swg, select your OS: [Mac](/dope.endpoint/mac-installer) or [Windows](/dope.endpoint/windows-installer)

<figure><img src="/files/0VKJxUnZiwNdRwSKkRRH" alt=""><figcaption></figcaption></figure>

{% hint style="success" %}
The dope.endpoint supports Windows 10/11 and macOS 13/14/15
{% endhint %}

## Install the dope.endpoint

Install the dope.endpoint to your device with the [Mac](/dope.endpoint/mac-installer) or [Windows](/dope.endpoint/windows-installer) guide as required


# Import User and Group Data

While dope.swg can be used without importing user and group data, admins must import user and group data to fully utilize the product.

## dope.console

![When you open the dope.console, you’ll arrive at the dope.swg overview dashboard.](/files/CbhLKjSWSZRdAxQB6EVI)

## Endpoint Auth & User Import

First, enable endpoint authentication. This forces users to authenticate with their corporate emails and automatically have the correct web security policy applied. By using an integration with Microsoft 365 and Google, it’s a click without any SAML configuration.

![Click to enable endpoint authentication](/files/wkp3DcikNy7h2B0IjoJB)

In other words, if you're using Okta, Ping, or another 3rd-party IDP, you'll automatically redirect to that IDP.

Now, use the link provided to authorize access to the users and groups.

{% hint style="info" %}
Only Google/Microsoft 365 admins can authorize users and group imports. This link can be copied and sent to them. Google import requires special authorization [detailed here](/dope.console/settings/users/importing-from-google).
{% endhint %}

{% hint style="warning" %}
Azure / Microsoft Entra Security Groups are not currently supported for policy assignment and exceptions in dope.console
{% endhint %}

Once the admin has authenticated with either Google or Microsoft 365, the dope.security console will import your users and groups. Any updates to groups or new users in either Google or Microsoft 365 are synced and reflected in the dope.swg console.

{% hint style="danger" %}
Without importing users and groups into the console, functionality will be limited:

* No Custom Policies
* No Policy Exceptions
* Limited Analytics Functionality
  {% endhint %}

![](/files/dOMlTwfhKssVS18brgrE)

### Acceptable Domains

If your company uses multiple domain names, enter the different domain names that may be used by users.

Logins from other domains will be blocked.

{% hint style="success" %}
Add comma-separated domain names, e.g. for <user@voyager.com>, just put in “voyager.com”.
{% endhint %}

Once you’ve completed adding domains, select ‘Save’ on the bottom right panel to save your changes.

![](/files/u9XYdLJ7oggpdQQ2fJmW)


# Create a dope.swg Web Policy

To edit the Base Policy or create a new policy, visit the Policy page from the top navigation.

![](/files/Xbal8KT4YfdgUKYj142v)

The Base Policy is configurable to suit your company’s needs so you can easily adjust the out-of-the-box settings.

The policy view shows all categories, with subcategories collapsed and hidden at first glance. You can see what restriction level is associated with each category by hovering over the icon.

<img src="/files/GNRyW7knmrs9kN7Zlmi8" alt="" data-size="line"> Allowed

<img src="/files/NrgoyLNTRnbqbdENz3kR" alt="" data-size="line"> Blocked

<img src="/files/bVhJ0OjgFhEILWCpTmY6" alt="" data-size="line"> Warning

![](/files/ZO1C335VjlYXoMJcpPzE)

{% hint style="info" %}
You won’t have the ability to create multiple policies until you have imported users or groups into dope.swg.
{% endhint %}

## DOPE Categories

The Base Policy contains 83 subcategories that are grouped into 30 parent categories.

Each of the 83 categories has a default restriction category of either allow or block. Starting off, each subcategory has the same restriction level as its parent category. This means if you want to allow or block the same type of category, you can just change the restriction level at the parent level.

You can also change the restriction level for each individual subcategory if you wish. As well as “Allow” and “Block,” dope.swg also supports a restriction level of “Warning.”

So, are you ready to proceed? Let’s make some category changes.

### Change a parent category

On selecting a parent category, the right-side panel provides a description of what that category covers.

You can change the restriction level to “Allow,” “Block,” or “Warning” for each parent category.

If you change the restriction level at the parent category level, the subcategories restriction level will be updated to reflect.

![](/files/nXxOpRhgdErAhn94RDvB)

### Change a subcategory

Clicking into a parent category expands to reveal the associated subcategories. On selecting a subcategory, the right-side panel provides a description of what that subcategory covers.

You can then change the restriction level to “Allow,” “Block,” or “Warning” for each subcategory.

The restriction level shown at the parent level reflects the restriction level associated with each subcategory. When any subcategory restriction level is different, the parent level will that the restriction is Mixed <img src="/files/MxGivovQFx2WAiKyYLFb" alt="" data-size="line">

![](/files/OOqNsDXPNwoVZqg6ghWy)

Once you have completed the changes you want to make, you must save your policy. This is done by selecting the save button in the bottom right panel in the console.

![](/files/u9XYdLJ7oggpdQQ2fJmW)

The Base Policy is now updated: dope.swg will automatically apply the updates for all users assigned to the policy.

## Add a Policy Exception

To add an exception to a super category or subcategory select the category and go to the right hand panel. Here select the <img src="/files/1UoNPx9RTTnXOQl1GHBx" alt="" data-size="line"> button.

This will allow you to enter in a user or group from your imported users and groups. Once you start typing in the text box provided the console will provide suggested users and groups from the previously imported data.

![](/files/ln33QPf0DdrpqoHgqqVe)

Once you have selected the user or group for whom you wish to create the exception you can then select the restriction level you wish to apply for this user to the select category. Again this is done by simply clicking on the icon and toggling through the restriction levels.

The final step to complete the creation of the category exception is to save the policy. This is done by selecting the save button in the bottom right panel in the console.

![](/files/u9XYdLJ7oggpdQQ2fJmW)

The Base Policy is now updated, on receipt of the updated policy the dope.endpoint will apply this exception for the configured user or group.

{% hint style="danger" %}
It is not possible to create policy exceptions without importing user and group data.
{% endhint %}


# Mac Installation Process

After selecting to download the mac version of the dope.endpoint a ZIP fie will be downloaded to your device.

The ZIP file will be called **dope\_security*****\_mac\_1.0.XXXX.zip***

Extract the ZIP file, it will contain the following three files:

* **dope\_security\_1.0.XXXX.pkg** — The dope.endpoint installer.
* **dope.security.root.crt** — The dope.security Root CA, required for SSL inspection.
* **agent\_parameters.json** — Tenant-specific data required for the installation process.

{% hint style="warning" %}
All three files must be in the same directory or the installation will FAIL.
{% endhint %}

To install the dope.endpoint, double click on the PKG file from within the ZIP file. This will launch the Installer UI. From here select **Continue**.

<div align="center"><img src="/files/pjfnJB47UUExPEvRIKFf" alt=""></div>

A prompt will appear asking to allow the installation of the dope.endpoint. Provide the required details to proceed.

![](/files/WEmm46G12O0im4ZSRTVN)

For the dope.endpoint to work it needs to install the dope.security Root CA. Provide the required details to proceed.

![](/files/ohQrlDgjqHBIsl9hxCmz)

The system extension prompt is to allow the dope.security application to run. There’s a prompt to open the macOS security and preferences settings.

![](/files/BKMeBGtdc9n2sftvHhKt)

Open the security preferences dialog box, provide the required details and allow the dope.security application to run.

![Click the lock to make changes and select "Allow".](/files/SzWkbJaxo0RGrv4RGWzI)

The final prompt is to allow the dope.security application monitor network activity. Select **Allow** to finalize installation.

![](/files/ycq6tshBv4Ri8IQcHkVt)

Once these steps are complete a dope.security icon <img src="/files/09Vda7z9bqmXOhFm9ZXj" alt="" data-size="line"> can be seen in the macOS menubar. This shows the installation was successful.

For more details on the macOS installation process see [Mac Installer (Old)](/dope.endpoint/mac-installer-old).

{% hint style="info" %}
All of the prompts above will not appear an a device where a MDM profile has been installed. For more details see [Installing using MDM on Mac](/dope.endpoint/installing-using-mdm-on-mac).
{% endhint %}

## Go to Console

<figure><img src="/files/K4cPaqTESUjqB9g1bPGD" alt=""><figcaption></figcaption></figure>

When you’re ready, proceed to the console where you will configure your web security policy for your users.


# Windows Installation Process

After selecting to download the Windows version of the dope.endpoint a ZIP fie will be downloaded to your device.

The ZIP file will be called **dope\_security*****\_windows\_\<build number>.zip**.*

Extract the ZIP file, it will contain the following three files:

* **dope.security\_windows-\<build number>.msi** — The dope.endpoint installer.
* **dope.security.crt** — The dope.security Root CA, required for SSL inspection.
* **agent\_parameters.json** — Tenant specific data required for the installation process.

{% hint style="warning" %}
All three files must be in the same directory or the installation will FAIL.
{% endhint %}

To install the dope.endpoint double click on the MSI file within the ZIP file. This will launch the following Installer UI.

![](/files/2hg6ifHSk2Byy0whiV6R)

Before installation can start the dope.security End User License Agreement (EULA) needs to be accepted. Once this has been accepted select the install option to start the installation process.

MS Windows will also prompt to accept installing the dope.endpoint on the Windows machine. On selection of **Yes** the installation process will continue.

![](/files/RE8jjszWmzUdNElp77iY)

Once it is complete the following dialog will be displayed.

![](/files/PR46lW0H5Uf30bqICUto)

Simply select **Finish** to complete the installation.

Once the installation is complete a dope.security icon <img src="/files/09Vda7z9bqmXOhFm9ZXj" alt="" data-size="line"> can be seen in the Windows systems tray icon. This indicates the installation was successful.

## Go to Console

<figure><img src="/files/K4cPaqTESUjqB9g1bPGD" alt=""><figcaption></figcaption></figure>

When you’re ready, proceed to the console where you will configure your web security policy for your users.


# Mitre ATT\&CK and Nist CSF

SWG and CASBs are well-known tools that organizations use to align & prevent techniques in multiple frameworks in their security strategy.

The dope difference is to give you better architecture — Fly Direct and LLM-based DLP — making it easier to operate and better control coverage!

As a guide, here's what we align to:

***

### **MITRE ATT\&CK Alignment**

dope.security's capabilities align with the following **tactics and techniques**:

**Tactic: Initial Access**

* **Drive-by Compromise (T1189)** *(SWG)*\
  URL filtering blocks access to malicious or compromised websites, preventing malware infections.

**Tactic: Execution**

* **Malicious File Execution** *(SWG)*\
  SSL inspection prevents the download of malicious files hidden in encrypted traffic.

**Tactic: Persistence**

* **Boot or Logon Autostart Execution (T1547)** *(SWG)*\
  Cloud app control minimizes risks from persistent tools using cloud-based channels.

**Tactic: Command and Control (C2)**

* **Encrypted Channel (T1573)** *(SWG)*\
  SSL inspection detects and blocks encrypted malicious C2 communications by identifying unusual patterns or indicators.

**Tactic: Exfiltration**

* **Exfiltration Over Web Service (T1567)** *(SWG)*\
  Cloud app control and URL filtering block unauthorized file-sharing platforms, preventing data exfiltration.
* **Exfiltration Over Web Service: SaaS (T1567.002)** *(CASB Neural)*\
  Detects and remediates public or external sharing of sensitive documents in SaaS platforms like Office 365 and Google Workspace.

**Tactic: Discovery&#x20;*****(CASB Neural)***

* **Cloud Service Discovery (T1526)**\
  Identifies and maps exposed sensitive documents in SaaS platforms.

**Tactic: Collection&#x20;*****(CASB Neural)***

* **Data from Cloud Storage Object (T1530)**\
  Scans SaaS environments for sensitive files that may be improperly shared.

***

### **NIST Cybersecurity Framework Alignment**

dope.security aligns with several **functions and subcategories** of NIST CSF:

**Function: Identify**

* **Asset Management (ID.AM-1, ID.AM-2)** *(SWG)*\
  Maintains visibility over cloud app usage and destinations.
* **Risk Assessment (ID.RA-1, ID.RA-2)** *(CASB Neural)*\
  Identifies improperly shared sensitive documents, prioritizing risk mitigation.

**Function: Protect**

* **Access Control (PR.AC-4, PR.AC-5)** *(SWG)*\
  Enforces least privilege by restricting access to unauthorized apps and services.
* **Data Security (PR.DS-1, PR.DS-5, PR.DS-6)** *(SWG & CASB Neural)*\
  Secures data in transit via SSL inspection and mitigates risks of data leakage by remediating exposed SaaS files.
* **Protective Technology (PR.PT-1, PR.PT-2)** *(SWG)*\
  Integrates with protective systems to ensure real-time analysis and blocking of harmful traffic.

**Function: Detect**

* **Anomalies and Events (DE.AE-2)** *(CASB Neural)*\
  Detects unexpected public or external sharing of sensitive data.
* **Security Continuous Monitoring (DE.CM-7, DE.CM-8)** *(SWG)*\
  Monitors traffic to detect malicious activity or unusual patterns.

**Function: Respond**

* **Mitigation (RS.MI-1, RS.MI-2)** *(CASB Neural)*\
  One-click remediation of sensitive data exposure ensures rapid containment.
* **Response Planning (RS.RP-1)** *(SWG)*\
  Enforces immediate response to malicious activity.

**Function: Recover**

* **Improvements (RC.IM-1)** *(SWG & CASB Neural)*\
  Provides insights for continuous improvement of security policies and data protection strategies.

***

In summary:

* **SWG (URL Filtering, SSL Inspection, Cloud App Control, etc):** Protects against malicious access, data exfiltration, and encrypted threats while ensuring compliance with organizational policies
* **CASB Neural:** Enhances SaaS data security by identifying and remediating improperly shared sensitive files, aligning with data protection and risk mitigation requirements


# Analytics

### When you’re flying first class, you want to be able to enjoy all the good things that come with that privilege. dope.swg has added analytics on Policy, Productivity, and Shadow IT that set it apart from coach class. Why miss out?

{% hint style="info" %}
To enjoy all these benefits and make the most of your dope.swg experience, you need to have imported your users/groups into the console.
{% endhint %}

Have you already imported all your organization’s users?

If you haven’t imported users/groups into the console, you’ll see this at the bottom of the overview dashboard...

![](/files/uVv62Sq0681x7Prm9LxZ)

…with no information on Productivity or Shadow IT. This means you will have limited access to analytics data unless users/groups are imported into the console.

You can continue without importing users or groups but you will have limited access to analytics data. To make the most of dope.swg, ensure you import your organization’s users and groups.


# Overview dashboard

### When you’re flying first class, you want to know you’re safe and secure on your journey so you can relax. dope.swg has you covered, with a simple and easy dashboard so you can keep on top of all your company’s security and analytics in one place. No fuss, no problem.

When you open the dope.swg portal, you’ll arrive at the dope.swg dashboard.

![](/files/5soG3XQBChdguF2kvQzH)

The dashboard gives you a comprehensive overview of how dope.swg is working across your organization, so you can see any security issues or threats which exist.

The world map shows the geographic location of each dope endpoint across your organization, each location represented with a colored dot.

<img src="/files/uFxzndcOJqCypOEbnj4S" alt="" data-size="line"> Green dot = Active (No policy violations in this area)

<img src="/files/86aIbmOVbt1p94ENmYHc" alt="" data-size="line"> Yellow dot = Above average violations in this area (\*see note)

<img src="/files/AdVWYVuTjjXSkCGHySvZ" alt="" data-size="line"> Red dot = Error (Endpoint in geolocation is in Error or Fail Open State)

**The dots will vary in size:**

* The smallest dot displays where 1 to 5 endpoints are running in this location.
* The middle-sized dot displays where 5 to 15 endpoints are running in this location.
* The large dot displays where more than 15 endpoints are running in this location.

You can zoom in to an area on the map or click on a dot to find out more information about what’s going on at each location.

#### When the user clicks on any colored dot, they will be shown the following details:

* Total number of devices using the system
* Total volume of data transferred (Uploaded+Downloaded)
* Total number of transactions
* Total policy violations
* All endpoints in Error
* All endpoints in Fallback

*The information will appear like below on clicking on the dot.*

![](/files/Sintg4Y3cWGKbSomjkKQ)

## Analytics Summary

Sitting comfortably? Alright. At the bottom of the dope.swg analytics overview dashboard, you’ll see this information for the last seven days.

![](/files/8gMjrhsxOzRqgiNVMScX)

So let’s take a closer look at the details here...

**Policy Violations**\
At the bottom left of your dope.swg homepage dashboard, you can see real-time information on the total number of policy violations within your organization over the last seven days. This is updated every 10 seconds.

**Violation Detail (Top Blocked Category)**\
This displays the dope category that has generated the most blocks in your organization over the last seven days.

**Productivity (Category Most Viewed)**\
This displays the most viewed dope category across your organization over the last seven days.

**Shadow IT (Most used cloud app)**\
This displays the most used cloud app across your organization over the last seven days.

Each of these sections is clickable — that click will bring you to the associated analytics view.

## Search

Searching the overview dashboard will bring you to the Detail view filtered to show the violation data that matches your search.

When you place your cursor in the search bar in the overview dashboard, you will see some suggestions for the other analytics views that exist i.e. Overview, Policy, Productivity, Shadow IT, Detail.

![Search Suggestions](/files/bP8s51uEiKHZUHB4ng4k)

### **Search for User, Group or Location**

When you start entering text into the search bar, dope.swg will suggest users, groups or locations that match the text you are entering. You can then search policy violation for a specific user, group or location.

![](/files/bvXQlNnaaJh5i576nEVT)

You do not have to select a valid user, group, or location to search the detail view from the overview dashboard. You can simply enter text and the console will search for policy violations for users, groups, or locations starting with the text you have entered.

On selecting enter you will be brought to the Detail view which will be filtered with policy violations that match your search. [Detail View](/dope.console/analytics/detail-view)

{% hint style="info" %}
*You need to have imported users and groups’ data into the console to search for groups or locations.*
{% endhint %}


# Policy View

### By clicking on “Policy” from the dropdown, you’ll get to the Policy view with a live overview of the policy violation numbers across all your organization’s endpoints.

![](/files/zUEf85Jd0FZdyQf0fOHQ)

The Policy view shows you details of what policy violations, malware blocks, and cloud app blocks have occurred in the last 7 days across your organization.

The policy violations will be listed as either “Block” or “Warning” — depending on how you have configured your dope.swg policy

## Policy Violations

![The dope.swg analytics view for policy](/files/Wa29PO6EcgRLkgnUoPTN)

On the left of this view you will see the following data for the last seven days:

* The number of **Policy** Blocks — with the total number of web transactions across your organization for comparison.
* The number of **Malware** Blocks — with the total number of files across your organization scanned for comparison.
* The number of **Cloud Application Control (CAC)** Blocks — with the total number of CAC transactions across your organization for comparison.

{% hint style="info" %}
*Clicking on any of these totals will bring you to a Detail view filtered to violations for the selected policy type.*
{% endhint %}

The Analytics view features a graph showing the trend for blocks across your organization for the 3 policy areas for the last 7 days. Each trendline is signified by a different color.

![](/files/FoDg1c30Hv8OHXKtO17o)

Below the graph you can see more details on the reason for the policy blocks across the last seven days:

* For **Policy** you can see up to the top seven blocked categories.
* On **Malware** you can see the up to the top seven malware types that were blocked.
* For **CAC** you can see the top CAC Apps that were blocked.

## Top Blocks

You need to know when your users are violating their policy so you can keep your organization’s users safe. *Safety first, right?*

dope.swg lets you monitor which users, groups, and locations are responsible for the highest number of policy violations. You can then decide the appropriate action to take.

dope.swg uses a tree map graphic to show admins who is responsible for the top blocks in your organization. A tree map graphic visualizes the data in blocks — this makes it easier for you to spot trends or patterns.

![A tree map of graphic visualizes the data in blocks — this makes it easier for you to spot trends or patterns of policy breaches.](/files/nJjfXRfIN5qwRepKzwIi)

*S*electing any of the sections in the tree map will open the detail view.

### Refine your search

By default this graphic shows violations for all policy types and includes user, groups, and locations. You can select a specific policy type using Policy, Malware, or CAC filter buttons or a combination of policy types.

<div align="center"><img src="/files/KwwhWMC7nT3Sn8YaFEsi" alt="You can select a specific policy type using Policy, Malware, or CAC filter buttons or a combination of policy types"></div>

You can also filter to select by users, groups, or locations by using the check boxes to see users, groups or locations or a combination of these.

![](/files/CRPpJgXXm6EFp5yAluA0)

Selecting any of the sections in the tree map will open the Detail view filtered to either the selected user, group, or location.

## **Search**

Searching the Policy view will bring you to the Detail view filtered to show the violation data that matches your search.

### **Search for User, Group or Location**

When you start entering text into the search bar, dope.swg will suggest users, groups or locations that match the text you are entering. You can then search policy violation for a specific user, group or location.

![](/files/bvXQlNnaaJh5i576nEVT)

You do not have to select a valid user, group, or location to search the detail view from the policy view. You can simply enter text and the console will search for policy violations for users, groups, or locations starting with the text you have entered.

On selecting enter you will be brought to the Detail view which will be filtered with policy violations that match your search. [Detail View](/dope.console/analytics/detail-view)

{% hint style="info" %}
*You need to have imported users and groups' data into the console to search for groups or locations.*
{% endhint %}


# Productivity

### Everyone benefits when individuals are making the best use of their time. It benefits the individual and it benefits the organization. dope.swg lets you see how your organization is using the web.

The Productivity function on dope.swg lets you see what your users are accessing on the web, giving you a better idea of how productive they are being with their time.

By clicking on “Productivity” from the dropdown, you’ll get to the Productivity view, where you can get a better understanding of how your users are accessing the internet from their corporate devices.

![](/files/0M9L59YUrOIV3JtC92if)

{% hint style="warning" %}
If you have not imported users and groups, the productivity page will open blank.
{% endhint %}

## Top 5 Categories

When you arrive to the Productivity view, you will see a circular graph.

The outer ring of the graph is divided into 5 colors: the colors signify the top 4 category viewed across your organization over the past 7 days *and* the total data and web transactions for all other viewed categories.

![Top Categories View](/files/7bSIyYHDwnC9ldCJS1od)

* Each color in **the outer ring** shows the amount of data transferred in bytes.
* **The inner ring** of the graph shows the number of transactions for each top 4 category *and* a total for all other transactions.
* **The middle** of the graph shows the total amount of data transferred across the entire organization over the last 7 days.

Clicking on one of the top four categories will open a new graph — see **Category Domains** below.

### Category Domains

You can click on one of the top four viewed categories. This will open a new circular graph showing the top domains associated with this category.

The circular graphic takes the same format as the top categories graphic. There are the top 4 domains for the category, each showing both the data transferred and the total number of transactions.

The fifth domain in the graph shows the accumulated data for all other domains within the category.

![](/files/lw4Scu7TwmZYavPqNfTK)

The middle of the graph shows the percentage of the total data transferred that the selected category is responsible for.

## Top 10 Categories

The productivity view also provides a list of the top 10 categories viewed over the last 7 days across the organization. It shows the percentage of the total amount of data transferred that the selected category is responsible for.

![](/files/qB7R52nrNulVY6kNvGKT)

All the categories in this list are clickable and will bring you to the domain view for the selected category.

## Screen Time

The screen time view lets you see how long users are spending on the top categories, and what time of day they view each category.

You can see the average daily time users are active on their endpoints across the entire organization. Taking this information on board can help your organization become more productive.

![](/files/ZLMLp9nFJFsg2YlOVLpW)

By default screen times show for the last week but it is possible to view the screen time for just the previous day by selecting the “Day” option at the top of the graph. This will show you when the categories were viewed in the last 24 hours and the average for this period.

## Search

By default the productivity view shows details on the viewing history of everyone in your organization. However it is possible to search the view for a user, a group, or a location.

### **Search for Users**

When you start entering text into the search bar, dope.swg will suggest users , groups or locations that match the text you are entering.

![](/files/bvXQlNnaaJh5i576nEVT)

When you have made a selection, the Productivity view will show the top categories viewed for the selected user. It is also possible to download all of the searched for users web transactions to a CSV file using the download button at the top of the view.

The screen time graphic and the top categories graphic will update to show the information for the selected user, group, or location.

{% hint style="info" %}
Searching for a group or a location in the productivity view will bring you to the Details View where you will see all the violations for the searched group or location
{% endhint %}


# Shadow IT

### Nobody likes turbulence. So when you’re flying first class, you want to to keep it to a minimum. Knowing your organization’s cloud app use ensures everybody has a smooth, safe experience as they work

## Application View

By clicking on ”Shadow IT” from the dropdown, you are directed to the application view showing the top 20 used cloud apps based on data transferred over the last 7 days across your organization.

![](/files/UitilK11xlqaTcgCJcQn)

{% hint style="warning" %}
If you have not imported users and groups, the Shadow IT page will open blank.
{% endhint %}

The apps are ordered with the app with the least number of users at the top and the app with the most users at the bottom.

![](/files/Uvj5cmgKDs05IDLjlvCS)

Why does dope.swg show least first? Because it’s likely these are the ones you are most interested in to find out why they need to be used.

You can see usage across each of the last 7 days by hovering over the day in the graphic.

## Search

### Application View

By default, the Shadow IT view shows details on the viewing history of everyone in your organization. However you can also search the view for a user, a group, or a location.

#### **Search for Users**

When you start entering text into the search bar, dope.swg will suggest users, groups or locations that match the text you are entering.

![](/files/bvXQlNnaaJh5i576nEVT)

On selecting a user the Shadow IT application view will show the top cloud apps used by that user, group, or location, over the last seven days. It is also possible to download all of the searched for users Shadow IT transactions to a CSV file using the download button at the top of the view.

###

{% hint style="info" %}
Searching for a group or a location in the Shadow IT view will bring you to the Details View where you will see all the violations for the searched group or location
{% endhint %}


# Detail View

### When you're flying first class, sometimes it’s the little details that enhance your experience. When it comes to web security, Detail View in dope.swg analytics gives you that added piece of mind.

Clicking on “Detail” from the dropdown brings you to the Detail view where you can view details on any policy violations over the last seven days.

![](/files/PtHxrUgU2afpoCEcTXHk)

By default the detail view will open showing the violation details for everyone, with the most recent violation first on the list.

![](/files/7A3SQQQy8ikcoOz5QGIV)

The details view includes the following details associated with each web transaction:

* **Domain:** The domain that the category match was made against.
* **URL/Path:** The complete URL that that was attempted to be accessed.
* **Process Name:** The process from where the connection attempt was made.
* **Location:** The location of the dope.endpoint.
* **Destination IP:** The destination IP for the requested URL.
* **Category:** The categories associated with the domain.
* **User:** The email address of the user. Logged in user where no user/group import has been done.
* **Size:** The total size of the data transferred within the connection.
* **Type:** What type of policy was applied to the transaction (Policy/Malware/CAC/DLP)
* **Block Detail:** Contains either the dope category, malware type, or the cloud application that resulted in the block.
* **Verdict:** Will be one of the following — “Allow,” “Block,” “Warning,” "Monitor," or “Bypass.”
* **Time:** The time of the web transaction.
* **Fallback Mode:** Was the dope.endpoint in fallback mode at the time of the web transaction.
* **Cache Miss:** Indicates whether the domain was found in the dope.endpoint cache.
* **File Name:** The file name that was blocked from being downloaded due to a malware violation.
* **File Hash:** The file hash of the file that was blocked from being downloaded due to a malware violation.
* **Dopamine:** A summary of the file contents or AI prompt input where sensitive data was detected; available for DLP violation types.
* **Detections:** The category of sensitive data identified — IP, PII, PCI, PHI, or Other.

## Search

By default, the Detail view shows every policy violation in the last seven days.

dope.swg also lets you search for a user, a group, or a location.

### **Search for User, Group or Location**

When you start entering text into the search bar, dope.swg will suggest users, groups or locations that match the text you are entering. You can then search policy violation for a specific user, group or location.

![](/files/bvXQlNnaaJh5i576nEVT)

You do not have to select a valid user, group, or location to search the detail view. You can simply enter text and the console will search for policy violations for users, groups, or locations starting with the text you have entered.

On selecting enter the Detail view which will be filtered with policy violations that match your search.

{% hint style="info" %}
*You need to have imported users and groups' data into the console to search for groups or locations.*
{% endhint %}


# dope.swg Policy

## Creating a Policy

### dope.swg comes preconfigured with a base policy to safely control your organization’s web traffic e.g. Adult Material will be blocked, Business-Related will be allowed.

When you install dope.swg, you’ve immediately upgraded your organization to a world leader in security policy.

Sometimes, not everybody’s needs are the same. With dope.swg you can easily tailor a policy to suit your users’ needs, simply by editing the base policy.


# Editing the Base Policy

### The first time you select the policy view on dope.swg, you’ll see the Base policy.

![Base Policy](/files/cXBK2dYoITFuDLNevYul)

{% hint style="info" %}
You will not have the ability to create multiple policies unless you have imported users and groups into the product.
{% endhint %}

The policy view shows all the dope.swg parent categories, with subcategories collapsed. You can see what restriction level is associated with each parent category.

## DOPE Categories

The Base Policy contains 83 subcategories that are grouped into 30 parent categories.

Each of the 83 categories has a default restriction category of either allow or block. Starting off, each subcategory has the same restriction level as its parent category. This means if you want to allow or block the same type of category, you can just change the restriction level at the parent level.

You can also change the restriction level for each individual subcategory if you wish. As well as “Allow” and “Block,” dope.swg also supports a restriction level of “Warning.”

So, are you ready to proceed? Let’s make some category changes.

### Change a parent category

On selecting a parent category, the right-side panel provides a description of what that category covers.

You can change the restriction level to “Allow,” “Block,” or “Warning” for each super category.

If you change the restriction level at the parent category level, the subcategories restriction level will be updated to reflect.

![](/files/KD2L7uD6jR5PLjLSNbWH)

### Change a subcategory

Clicking into a parent category expands to reveal the associated subcategories. On selecting a subcategory, the right-side panel provides a description of what that subcategory covers.

You can then change the restriction level to “Allow,” “Block,” or “Warning” for each subcategory.

The restriction level shown at the parent level reflects the restriction level associated with each subcategory. When any subcategory restriction level is different, the parent level will that the restriction is Mixed <img src="/files/MxGivovQFx2WAiKyYLFb" alt="" data-size="line">

![](/files/MUGuT7MZcU1m7PlZZPNW)

Once you have completed the changes you want to make, you must save your policy. This is done by selecting the save button in the bottom right panel in the console.

![](/files/u9XYdLJ7oggpdQQ2fJmW)

The Base Policy is now updated: dope.swg will automatically apply the updates for all users assigned to the policy.


# Adding Policy Exceptions

To add an exception to a parent category or subcategory select the category and go to the right hand panel. Here select the + button.

{% hint style="warning" %}
To add Policy exceptions, you need to have previously imported all users and group data.
{% endhint %}

This will allow you to enter in a user or group from your imported users and groups. Once you start typing in the text box provided the console will provide suggested users and groups from the previously imported data.

![](/files/9sdzsCoxBpdQKaGxGRSe)

Once you have selected the user or group for whom you wish to create the exception you can then select the restriction level you wish to apply for this user to the select category. Again this is done by simply clicking on the icon and toggling through the restriction levels.

The final step to complete the creation of the category exception is to save the policy. This is done by selecting the save button in the bottom right panel in the console.

![](/files/u9XYdLJ7oggpdQQ2fJmW)

The Base Policy is now updated, on receipt of the updated policy the dope.endpoint will apply this exception for the configured user or group.

![“Has Exception” on parent category](/files/K7JqOU7UZ0vuV0nWHkac)


# Assigning a Block Page

### Do you want to set a block page or security risk page if your users try to access certain categories?

You can assign a block page or security risk page, to any DOPE or Custom Category, with restriction level of “Block.”

This can be done at either parent or subcategory level by selecting the dropdown in the right panel of the console. If you assign a block page at the parent category level, all subcategories are assigned the same block page.

![](/files/9yMqAgPalRKBZoeeHFRg)

The drop down shows a list of all the default and custom block and security risk pages. If the Default Block page has been assigned to a category, this is what is displayed to the user if they try to access this category.

![](/files/7FEXvVMgxprSzcd73qFu)

You can also customize a block page to brand it to your own organization.

<figure><img src="/files/sJvlieaXAaXDLe4sEeTz" alt=""><figcaption><p>Custom block page example</p></figcaption></figure>

For information on default and custom pages go to [Block Pages](/dope.console/settings/block-pages).

The same rules apply for categories with a restriction level of “Warning” — the drop down will only show you the default or custom warning pages.


# Creating Custom Categories

### dope.swg has a list of groups detailing more than 80 web categories to keep your organization safe on the internet. It’s first class all the way. But it's easy to create your own categories.

If want to create your own categories for specific domains and/or URLs in your organization, dope.swg has you covered.

{% hint style="info" %}
If you add a custom category, it will take precedent over existing Base Categories
{% endhint %}

To create a custom category simply start typing the name in the text field provided then hit enter. Then add any exceptions or URL filtering which will be covered by your new custom category.

![dope.swg will validate each URL that is added to the custom category list.](/files/m7s2DTyfPBmiNBvO7NxU)

{% hint style="info" %}
To delete a URL that has been added to the list then hover over the far right of the field and select the trash can icon.
{% endhint %}

”Wild cards” (\*) can be used. Using wild cards lets you increase the number of domains impacted by a restriction level. For example, [www.google.com](http://www.google.com), would mean drive.google.com would not be included in your category, *but* using a wild card like \*.google.com would mean Google Drive and Google calendar would also be impacted by the custom category restriction level.

Select a restriction level for the custom category ⁠— “Allow,” “Block,” “Warning,” or “Ignore.”

Ignore is required for custom categories as you may want to ignore it for certain policies within your organization.

Lastly, add your exceptions.

## Importing Custom Categories

Once a new custom category is created you can import URLs that were previously created into the list from a CSV or text file.

Once a custom category is created the URLs can be import by simply dragging and dropping the file into the area in the right hand panel.

![](/files/Znrjgfbl2gQuhn99bf5H)

It is also possible to import a file by selecting the <img src="/files/1UoNPx9RTTnXOQl1GHBx" alt="" data-size="line"> icon. This will open a file chooser where a CSV or text file can be selected.

{% hint style="info" %}
**File Format**

The text file must have one url on each line. A CSV file must have one column with each row having one url.
{% endhint %}

### Editing your domains/URLs

To edit the domain/URL that was previously entered simply click on the text field and it will be possible to make any edits required.

To delete a domain/URL, select the delete button <img src="/files/Dn75BVgHfmKjAr6F4Y4P" alt="" data-size="line"> on the same line as the domain/URL. Save the deletion.

![](/files/Vw4Jc15iQAiiaD2o6Fk3)

{% hint style="info" %}
The list of URLs in the custom category is sorted alphabetically.
{% endhint %}

When you add a custom category in the base policy, that new category will be assigned across your organization. Save your new custom category.

![](/files/u9XYdLJ7oggpdQQ2fJmW)

Once the custom category is saved, it will be displayed within the custom category section of the dope.swg policy.

{% hint style="info" %}
When a custom category is added to any policy it will be shared globally across all policies. The new custom category is added to the other policies with a restriction level of “Ignore.”
{% endhint %}

## Deleting a Custom Category

You can delete a custom category whenever you want by selecting the category and then selecting the delete button <img src="/files/k1XLHjYw4Fr0W6XO3TCK" alt="" data-size="line"> in the bottom right corner. You will then need to confirm the deletion by selecting delete from the top of the right-side panel.

![](/files/LBKlIaLGP8DVfesJ6Z1z)

Finally, you need to save the deletion by selecting the save button in the bottom right panel of the console.

![](/files/u9XYdLJ7oggpdQQ2fJmW)

##


# Dopamine DLP

Dopamine DLP is our endpoint-native data loss prevention solution, built directly into the Fly Direct SWG. LLMs monitor and block sensitive uploads by understanding file context — no manual regex or pattern matching required. The result: real signals, fewer false positives, and enforcement that happens on-device with no stopovers.

### DLP Configuration

DLP is configured on a per-policy basis. To enable DLP inspection for a policy, navigate to the **DLP tab** within the policy and toggle **DLP Inspection** to ON from the right-hand panel.

<figure><img src="/files/6vYHuuTiiXc7nukRxrMq" alt=""><figcaption></figcaption></figure>

### Configuration Modes

The Dope endpoint can be configured to either **Monitor** or **Block** when sensitive data in detected in an uploaded file or an AI Prompt.

**Monitor Mode** — On detection of sensitive data:

* The end user receives a notification that sensitive data was found and that the admin team has been informed
* A violation is logged in the Analytics section ([See more details here](/dope.console/analytics/detail-view))
* The upload is allowed to proceed

<figure><img src="/files/6UQXoIa8divohmnnz3mr" alt=""><figcaption></figcaption></figure>

**Block Mode** — On detection of sensitive data:

* The end user receives a notification that sensitive data was found and that the admin team has been informed
* A violation is logged in the Analytics section ([See more details here](/dope.console/analytics/detail-view))
* The upload is blocked

<figure><img src="/files/0Uf0nSRFjmBqOHYKcQMJ" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Block Mode is available exclusively to customers with a Dopamine DLP license. If you're running a POC and want to test this feature, contact <sales@dope.security>.
{% endhint %}

#### DLP Policy Exceptions

It is possible to create configuration mode exceptions for specific users or groups.

Admins can create configuration mode exceptions for specific users or groups, allowing them to operate under a different mode than the rest of the policy. For example, if a policy is set to **Block**, you could create an exception for the "Marketing" group to set their mode to **Monitor** — or disable DLP inspection entirely for that group.

<figure><img src="/files/cKxaOfVpGfEidbTBUipi" alt=""><figcaption></figcaption></figure>

### DLP URL Bypass

The DLP tab includes a **DLP URL Bypass** list for trusted destinations that do not need Dopamine DLP upload or prompt inspection.

<figure><img src="/files/llcL6ElsLsKyrNLvxO6f" alt="DLP URL Bypass table in the DLP policy tab"><figcaption><p>DLP URL Bypass table in the DLP policy tab</p></figcaption></figure>

When traffic matches an entry in this list, the endpoint skips DLP inspection for that request. The upload or prompt is allowed to continue, and no DLP violation is created for the bypassed request.

{% hint style="info" %}
A DLP URL bypass only applies to Dopamine DLP inspection. It does not bypass SSL inspection, add the destination to the SWG URL Bypass List, or change web category or Cloud Application Control decisions.
{% endhint %}

To add an entry:

* In the **DLP URL Bypass** table, click **Click to assign a new URL.**
* Enter a domain, URL with path, IPv4 address, or IPv6 address. Wildcard domains such as `*.example.com` are supported.
* Add an optional note explaining why the bypass is needed.
* Submit the row. The table records the entry, note, admin who updated it, and update time.

A domain entry applies to that destination and its paths. To bypass only part of a site, include the path in the entry. For example, `example.com/upload` bypasses DLP inspection for `example.com/upload` and child paths, but not for unrelated paths on `example.com`.

Custom policies can inherit the Base Policy DLP URL Bypass list or use their own customized list. To remove an entry, select it and delete it from the right-hand panel.

### Detections

When intercepting uploaded files or AI prompts, our LLMs scan for the following categories of sensitive data:

* Intellectual Property (**IP**)
* Payment Card Industry (**PCI**)
* Protected Health Information (**PHI**)
* Personally Identifiable Information (**PII**)

### Supported Applications

We're continuously adding new applications, including the latest AI tools. Currently supported applications include:

* **Google Drive** — When CAC is enabled, allowed domains are not inspected; all personal accounts are inspected
* **OneDrive** — When CAC is enabled, allowed domains are not inspected; all personal accounts are inspected
* **Box**
* **Dropbox**
* **ChatGPT** — Both prompt and file upload inspection supported
* **Claude AI** (Excludes Co-Worker until next release) - Both prompt and file upload inspection supported
* **Gemini**
* **WeTransfer**

{% hint style="info" %}
Don't see an application you need? Reach out to <sales@dope.security>.
{% endhint %}


# URL Bypass List

### There are some websites that may break when proxied that you still want people within your organization to be able to use. Just let dope.swg know which ones. The domain bypass list allows you to ensure these websites will still work for your users.

## Default URL Bypass List

At dope.security we always put customer experience first. That’s why we have created a list of URLs that we know will break when proxied. The URLs in our default bypass list will automatically be bypassed in all of your policies. You can review the list by selecting the default tab in the URL Bypass section.

<figure><img src="/files/tdAhKpTOXGB9HXYvC7Es" alt=""><figcaption><p>Default URL Bypass List</p></figcaption></figure>

If there is any URL in the list that you do not want to include in the bypass list then select the dropdown from the traffic column and select “Do Not Bypass.”

<figure><img src="/files/FzeeILG0626B79fRxxdB" alt=""><figcaption><p>Do Not Bypass</p></figcaption></figure>

{% hint style="info" %}
dope.security will continue to add to the default bypass list when we find common URLs that need to be bypassed.
{% endhint %}

## Custom Bypass List

There maybe other URLs that you discover that you want to bypass. These can be added to your own custom bypass list.

To add a URL Bypass, select the custom tab and start typing in the “Assign a new domain...” field or select the Add URL Bypass button <img src="/files/gUHOKmjnqqAd3R1tEgEi" alt="" data-size="line"> on the right hand panel. Enter the URL you need to bypass and select enter or hit the tab button on your keyboard.

<figure><img src="/files/LzUQBrhFSc1XdwWNtKSf" alt=""><figcaption><p>Add URL to the Custom Bypass List</p></figcaption></figure>

The final step to complete the addition of the domain bypass is to save the policy.

![Save Button](/files/u9XYdLJ7oggpdQQ2fJmW)

## URL Bypass Rules

As this list skips SSL decryption, any subdomain is ignored.

Wild cards (\*) can be used. Using wild cards lets you increase the number of domains impacted by a restriction level.

For example “[www.google.com”](http://www.google.com”) would mean “drive.google.com” would not be bypassed, *but* using a wild card \*.google.com would mean Google Drive and Google Calendar would both be bypassed.

The dope.console helps with wildcards — if “www” is not placed before the domain, then (\*) will automatically be added.

{% hint style="info" %}
Any duplicate URLs in the bypass list will just be ignored. You cannot edit the bypass domains list. You need to delete and add them again.
{% endhint %}

Each policy has its own domain bypass list. The base policy bypass list will be inherited by any other policy created. You can simply add new specific domains required to any new policy created.

### Delete URL

Change your mind? You can remove any domain or URL from this list whenever you want. Simply select the domain or URL you want to delete and from the right hand panel select the Delete option

![](/files/hWNuM8SpyRbpnKnIglGy)

After you have deleted the domain or URL the policy will need to be saved. This is done by selecting the save button in the bottom right panel in the console.

![](/files/u9XYdLJ7oggpdQQ2fJmW)


# Application Bypass List

### The Application Bypass List is a list of apps that the dope.swg will not apply policy to. These are normally applications that break when proxied. To do this, you just need to tell dope.swg which ones you want to allow.

## Default Application Bypass List

At dope.security we always put customer experience first. That’s why we have created a list of applications that we know will break when proxied. The applications in our default bypass list will automatically be bypassed in all of your policies. You can review the list by selecting the default tab in the Application Bypass section.

<figure><img src="/files/8WptvRwN4SNCnbr4XBSw" alt=""><figcaption><p>Default Application Bypass List</p></figcaption></figure>

If there is any application in the list that you do not want to include in the bypass list then select the dropdown from the traffic column and select “Do Not Bypass.”

<figure><img src="/files/XAZQOKqDSdjHJfLWdyCX" alt=""><figcaption><p>Do Not Bypass</p></figcaption></figure>

## Add a URL to the Custom Bypass List

There maybe other URLs that you discover that you want to bypass. These can be added to your own custom bypass list.

To add a App Bypass, select the custom tab and start typing in the “Assign a new application...” field or select the Add App Bypass button <img src="/files/SNdxbRacuuFzT7fai5dF" alt="" data-size="line"> on the right hand panel. Now simply enter the Application that you need to bypass and select enter or tab.

<figure><img src="/files/oKgQl4F6OaU47Yq5ivqM" alt=""><figcaption><p>Add Application to the Custom Bypass List</p></figcaption></figure>

The final step to complete the addition of the application is to save the policy.

![Save Button](/files/u9XYdLJ7oggpdQQ2fJmW)

{% hint style="info" %}
If you enter `.exe` or `.msi` as an extension the console will automatically assign this to be a windows process. All other processes will be assigned to macOS.
{% endhint %}

{% hint style="info" %}
By adding an application name to the list it will bypass all applications with this name. You can add the path to a specific application that you want to bypass e.g. `usr/bin/example_app`.
{% endhint %}

Each policy can have its own list of allowed applications. The Base Policy bypass list is the default for any other policy created but dope.swg lets you change this and add acceptable apps to suit your requirements.

{% hint style="info" %}
You cannot use wild cards on the Application Bypass List.
{% endhint %}

You can see in the policy view which apps are macOS and which are windows.

### Delete Application

You can delete any application from this list whenever you want. Simply select the application you want to delete and from the right hand panel select the Delete option.

![](/files/PWB0OU2NfkHx2IfkHzsr)

After you have deleted the application the policy will need to be saved.

![](/files/u9XYdLJ7oggpdQQ2fJmW)


# Default Bypass List

For easier deployment of the dope.endpoint, dope.security have created default application and URL bypass lists to bypass traffic we know will impact your users if we apply policy to it.

<table><thead><tr><th>Product</th><th>Company</th><th>Windows Process(es)</th><th width="160.81640625">macOS Process(es)</th><th>Domain(s) / Wildcards</th></tr></thead><tbody><tr><td>Adobe Acrobat Reader</td><td>Adobe</td><td>CRWindowsClientService.exe; AdobeCollabSync.exe; AcroCEF.exe</td><td>RdrCEF Helper.app</td><td>*.acrobat.com; *.echosign.com; *.echocdn.com; *.bam.nr-data.net; *.newrelic.com</td></tr><tr><td>Adobe Updates</td><td>Adobe</td><td></td><td></td><td>*.adobe.com</td></tr><tr><td>Amazon Web Services (AWS)</td><td>Amazon</td><td></td><td></td><td>*.amazonaws.com; *.aws.amazon.com</td></tr><tr><td>AnyConnect (Cisco)</td><td>Cisco Systems</td><td>Vpnui.exe; Vpnclient.exe</td><td>Vpnui; Vpnclient; Vpnagentd; /opt/cisco/anyconnect/bin/vpnagentd; /opt/cisco/hostscan/bin64/ciscod; Cisco AnyConnect Secure Mobility Client.app; acumbrellaagent</td><td></td></tr><tr><td>AnyDesk</td><td>AnyDesk Software GmbH</td><td>AnyDesk.exe</td><td>AnyDesk</td><td>*.anydesk.com</td></tr><tr><td>Apple iMessage</td><td>Apple</td><td></td><td></td><td>*.icloud.com</td></tr><tr><td>Apple iTunes / App Store / Updates</td><td>Apple</td><td></td><td></td><td>*.apple.com; *.mzstatic.com; *.akadns.net; *.apple-cloudkit.com; updates.cdn-apple.com</td></tr><tr><td>Apple Configurator</td><td>Apple</td><td></td><td>Apple Configurator</td><td></td></tr><tr><td>Apple Mail App</td><td>Apple</td><td></td><td></td><td>*.me.com</td></tr><tr><td>Azure VPN Client</td><td>Microsoft</td><td>AzVpnAppx.exe</td><td>Azure VPN Client</td><td></td></tr><tr><td>Avira VPN</td><td>Avira (Gen Digital)</td><td>Avira.Spotlight.UI.Application.exe; Avira.Spotlight.Systray.Application.exe; Avira.Spotlight.Service.exe; Avira.OptimizerHost.exe; Avira.VpnService.exe; phantomvpn.exe</td><td></td><td>*.msftncsi.com</td></tr><tr><td>Bitdefender</td><td>Bitdefender</td><td>EPIntegrationService.exe</td><td></td><td></td></tr><tr><td>Bitly</td><td>Bitly</td><td></td><td></td><td>bit.ly</td></tr><tr><td>Burp Suite (Community)</td><td>PortSwigger</td><td></td><td>Burp Suite Community Edition.app</td><td></td></tr><tr><td>Cloudflare DNS</td><td>Cloudflare</td><td></td><td></td><td>cloudflare-dns.com</td></tr><tr><td>Code42 (CrashPlan)</td><td>Code42 Software</td><td>Code42Service.exe</td><td>Code42Service.app</td><td></td></tr><tr><td>CrowdStrike Falcon Agent</td><td>CrowdStrike</td><td></td><td>com.crowdstrike.falcon.Agent.systemextension</td><td></td></tr><tr><td>Cuttly (Cutt.ly)</td><td>Cuttly</td><td></td><td></td><td>cutt.ly</td></tr><tr><td>Dameware</td><td>SolarWinds (N‑able)</td><td>BASEClient.exe</td><td></td><td></td></tr><tr><td>DBeaver</td><td>DBeaver Corp.</td><td>dbeaver.exe</td><td>DBeaver.app</td><td></td></tr><tr><td>Docker Desktop</td><td>Docker, Inc.</td><td>docker.exe; docker desktop.exe</td><td>Docker Desktop; docker</td><td></td></tr><tr><td>Dropbox</td><td>Dropbox, Inc.</td><td>Dropbox.exe; DropboxUpdate.exe</td><td>Dropbox; DropboxMacUpdate.app</td><td></td></tr><tr><td>Evernote</td><td>Evernote</td><td></td><td></td><td>*.announce.evernote.com; *.cd1.evernote.com; *.evernote-a.akamaihd.net; www.evernote.com</td></tr><tr><td>Firefox (telemetry)</td><td>Mozilla</td><td></td><td></td><td>*.telemetry.mozilla.org</td></tr><tr><td>Fortinet Client VPN</td><td>Fortinet</td><td>FortiClientConsole.exe</td><td></td><td></td></tr><tr><td>GlobalProtect</td><td>Palo Alto Networks</td><td>pangpa.exe</td><td>GlobalProtect</td><td></td></tr><tr><td>Google Cloud Platform (IAP)</td><td>Google</td><td></td><td></td><td>*.tunnel.cloudproxy.app</td></tr><tr><td>Google – Shared Services / Drive</td><td>Google</td><td>GoogleDriveFS.exe</td><td>Google Drive</td><td>*.connectivitycheck.gstatic.com; *.dl-ssl.google.com; *.dl.google.com; *.m.google.com; *.safebrowsing-cache.google.com; *.safebrowsing.google.com; *.tools.google.com; *.pack.google.com</td></tr><tr><td>Google Hangouts (legacy)</td><td>Google</td><td></td><td></td><td>*.accounts.google.com; *.apis.google.com; *.googleapis.com; *.appspot.com; *.googleusercontent.com; *.video.google.com</td></tr><tr><td>Grammarly</td><td>Grammarly</td><td></td><td></td><td>*.grammarly.com</td></tr><tr><td>JetBrains Toolbox</td><td>JetBrains</td><td></td><td>JetBrains Toolbox.app</td><td></td></tr><tr><td>Join.me</td><td>GoTo (formerly LogMeIn)</td><td>join.me.exe</td><td>join.me</td><td></td></tr><tr><td>Insomnia REST Client</td><td>Kong Inc.</td><td></td><td>Insomnia.app; Insomnia Helper.app</td><td></td></tr><tr><td>Jamf</td><td>Jamf</td><td></td><td></td><td>*.jamf.com; *.jamfcloud.com</td></tr><tr><td>Kandji</td><td>Kandji, Inc.</td><td></td><td></td><td>*.kandji.io</td></tr><tr><td>Kubernetes CLI</td><td>CNCF</td><td>kubectl.exe</td><td>kubectl</td><td></td></tr><tr><td>LINE</td><td>LINE Corporation</td><td>LINE.exe</td><td>LINE</td><td></td></tr><tr><td>Microsoft Defender</td><td>Microsoft</td><td>Defender.exe; MsMpEng.exe; MpCmdRun.exe; MpDlpCmd.exe; ConfigSecurityPolicy.exe; NisSrv.exe; MsSense.exe; SenseCnCProxy.exe; SenseIR.exe; SenseCE.exe; SenseSampleUploader.exe; SenseNdr.exe; SenseSC.exe</td><td></td><td>*.dm.microsoft.com; *.wd.microsoft.com; winatp-gw-usmv.microsoft.com; winatp-gw-usmt.microsoft.com; winatp-gw-ukw.microsoft.com; winatp-gw-uks.microsoft.com; winatp-gw-weu.microsoft.com; winatp-gw-neu.microsoft.com; winatp-gw-cus.microsoft.com; winatp-gw-eus.microsoft.com; winatp-gw-usgv.microsoft.com; winatp-gw-usgt.microsoft.com; *.data.microsoft.com; *.core.windows.net; winatp-gw-eus3.microsoft.com; winatp-gw-cus3.microsoft.com; winatp-gw.microsoft.com; winatp-gw-weu3.microsoft.com; winatp-gw-neu3.microsoft.com; *.wdcp.microsoft.com; *.wdcpalt.microsoft.com; *.smartscreen-prod.microsoft.com; *.smartscreen.microsoft.com; *.checkappexec.microsoft.com; *.urs.microsoft.com; *.notify.windows.com; *.wns.windows.com; *.crl.microsoft.com; *.opsinsights.azure.com; *.azure-automation.net; *.officecdn-microsoft-com.akamaized.net; *.packages.microsoft.comt.com; winatp-gw-usgv.microsoft.com; winatp-gw-usgt.microsoft.com; *.data.microsoft.com; *.core.windows.net; winatp-gw-eus3.microsoft.com; winatp-gw-cus3.microsoft.com; winatp-gw.microsoft.com; winatp-gw-weu3.microsoft.com; winatp-gw-neu3.microsoft.com; *.wdcp.microsoft.com; *.wdcpalt.microsoft.com; *.smartscreen-prod.microsoft.com; *.smartscreen.microsoft.com; *.checkappexec.microsoft.com; *.urs.microsoft.com; *.notify.windows.com; *.wns.windows.com; *.crl.microsoft.com; *.opsinsights.azure.com; *.azure-automation.net; *.officecdn-microsoft-com.akamaized.net; *.packages.microsoft.com</td></tr><tr><td>Microsoft Entra</td><td>Microsoft</td><td></td><td></td><td>*.entra.microsoft.com</td></tr><tr><td>Microsoft Intune</td><td>Microsoft</td><td>intunemanagementextensionbridge.exe; companyportal.exe; Microsoft.Management.Services.IntuneWindowsAgent.exe</td><td></td><td>*.manage.microsoft.com; *.officeconfig.msocdn.com; *.config.office.com; *.graph.windows.net; *.enterpriseregistration.windows.net</td></tr><tr><td>Microsoft Store</td><td>Microsoft</td><td></td><td></td><td>*.delivery.mp.microsoft.com</td></tr><tr><td>Microsoft Windows Update</td><td>Microsoft</td><td></td><td></td><td>*.update.microsoft.com; *.download.microsoft.com; *.windowsupdate.com; *.windowsupdate.microsoft.com; *.ntservicepack.microsoft.com; *.wustat.windows.com; *.enterprise.activity.windows.com</td></tr><tr><td>Microsoft Teams Updater</td><td>Microsoft</td><td>msteamsupdate.exe</td><td></td><td></td></tr><tr><td>Microsoft Office docs (OneDrive/SharePoint)</td><td>Microsoft</td><td></td><td></td><td>*.docs.live.net; *.sharepoint.com</td></tr><tr><td>Microsoft Office (O365)</td><td>Microsoft</td><td></td><td></td><td>*.outlook.office365.com</td></tr><tr><td>Mimecast</td><td>Mimecast</td><td></td><td></td><td>*.mimecast.com</td></tr><tr><td>NPM registry</td><td>GitHub (npm, Inc.)</td><td></td><td></td><td>*.npmjs.org</td></tr><tr><td>Okta FastPass</td><td>Okta</td><td>OktaVerify.exe</td><td>Okta Verify.app</td><td></td></tr><tr><td>osquery (Vanta)</td><td>Vanta</td><td></td><td></td><td>*.osquery.vanta.com</td></tr><tr><td>PeopleGraph (Office add-in)</td><td>Microsoft</td><td></td><td></td><td>*.appsforoffice.microsoft.com</td></tr><tr><td>Perimeter 81 VPN</td><td>Check Point (Perimeter 81)</td><td>Perimeter81.Service.exe; Perimeter81.exe</td><td></td><td></td></tr><tr><td>Plex</td><td>Plex, Inc.</td><td>Plex.exe; Plex Media Server.exe</td><td>Plex.app</td><td></td></tr><tr><td>PS Remote Play</td><td>Sony Interactive Entertainment</td><td>RemotePlay.exe</td><td>PS Remote Play</td><td></td></tr><tr><td>PuTTY</td><td>Simon Tatham (PuTTY)</td><td>putty.exe; puTTYgen.exe</td><td></td><td></td></tr><tr><td>Python packaging</td><td>Python Software Foundation</td><td></td><td></td><td>*.pythonhosted.org; *.pypi.org; *.anaconda.org</td></tr><tr><td>Rapid7 Insight Agent</td><td>Rapid7</td><td></td><td>ir_agent; rapid7_endpoint_broker</td><td>*.rapid7.com</td></tr><tr><td>Ruby</td><td>Ruby community</td><td></td><td></td><td>rubygems.org; rubyonrails.org</td></tr><tr><td>Signal</td><td>Signal Messenger LLC</td><td>Signal.exe</td><td>Signal</td><td></td></tr><tr><td>Sniply</td><td>Sniply</td><td></td><td></td><td>sniply.io; .snip.ly</td></tr><tr><td>SolarWinds MSP (N‑able)</td><td>N‑able (formerly SolarWinds MSP)</td><td>BASupSrvc.exe</td><td></td><td></td></tr><tr><td>Sophos</td><td>Sophos</td><td>SophosUpdate.exe; SubmitTelem.exe</td><td></td><td></td></tr><tr><td>Tailscale</td><td>Tailscale</td><td>tailscaled.exe</td><td>io.tailscale.ipn.macsys.network-extension.systemextension</td><td></td></tr><tr><td>Tenable Nessus Agent</td><td>Tenable</td><td>nessus-agent-module.exe</td><td></td><td></td></tr><tr><td>Terraform</td><td>HashiCorp</td><td></td><td></td><td>releases.hashicorp.com</td></tr><tr><td>Thunderbird</td><td>Mozilla</td><td>thunderbird.exe</td><td>thunderbird</td><td></td></tr><tr><td>TinyURL</td><td>TinyURL</td><td></td><td></td><td>tinyurl.com</td></tr><tr><td>Touch VPN</td><td>Northghost</td><td></td><td></td><td>*.northghost.com</td></tr><tr><td>Trend Micro Apex One</td><td>Trend Micro</td><td>ATASAgent.exe; CETASvc.exe; CNTAoSMgr.exe; DSAgent.exe; ESClient.exe; ESEFrameworkHost.exe; ESEServiceShell.exe; EndpointBasecamp.exe; LogServer.exe; Ntrtscan.exe; NTRtScan.exe; PccNTMon.exe; ShowMsg.exe; TMBMSRV.exe; TMiACAgentSvc.exe; TmCCSF.exe; TmListen.exe; TmPfw.exe; TmSSClient.exe; TmWSCSvc.exe; TmsaInstance64.exe; WSCommunicator.exe; dsagent.exe; iVPAgent.exe</td><td></td><td></td></tr><tr><td>Twingate</td><td>Twingate</td><td>twingate.exe; twingate.service.exe; twingateupdater.exe</td><td>Twingate Tunnel Provider</td><td></td></tr><tr><td>Vizydrop</td><td>Vizydrop</td><td></td><td></td><td>reports.vizydrop.com</td></tr><tr><td>VMware Horizon</td><td>VMware (Broadcom)</td><td>vmware-view.exe; vmUpdateLauncher.exe; vmware-remotemks.exe; horizon_client_service.exe; ws_diag.exe; sdrclientworker.exe</td><td></td><td></td></tr><tr><td>Xerox</td><td>Xerox</td><td>XeroxPrintJobEventManagerLoader.exe; XeroxDeviceStatus.exe</td><td></td><td></td></tr><tr><td>Yarn (pkg manager)</td><td>Community (open source)</td><td></td><td>yarn</td><td>*.yarnpkg.com</td></tr><tr><td>Zoho</td><td>Zoho</td><td></td><td>dcondemand</td><td>*.zoho.com</td></tr><tr><td>Zoom</td><td>Zoom Video Communications</td><td>Zoom.exe</td><td>zoom.us</td><td>*.zoom.us</td></tr></tbody></table>


# Cloud Application Control (CAC)

### Traveling first class is all about putting your needs first, right? dope.swg lets you keep control of all of your users’ cloud apps to ensure your organization enjoys the safest possible internet experience.

dope.swg lets you control your users’ access to the following cloud applications:

* O365
* Google
* Dropbox
* Slack
* Box
* Salesforce
* WebEx
* ChatGPT
* Claude
* GitHub

With dope.swg Cloud Application Control (CAC), if any of your users try to access cloud apps accounts that have not been allowed, dope.swg will block access. Any policy created will inherit the dope.swg Base Policy on CAC.

If you want to add domains your users can use to access selected cloud apps, that’s no problem either.

{% hint style="info" %}
The CAC policy supersedes the restriction level set at category level, e.g. if you have blocked “File Storage” at the subcategory level but have enabled Dropbox or Box control in cloud application control, the selected user will be allowed access to both.
{% endhint %}

Configuring cloud apps is simple and works pretty much the same way for Office 365 and Google. Configuring WebEx, Box, Dropbox, Slack, and Salesforce varies slightly, but it is just as easy.


# Microsoft O365

### To configure O365, simply enter the list of domains you want to allow access to.

All other email domains will be blocked.

![O365 Configuration](/files/TrKXnZRUJ6iu1M6DyBU1)

For example, if you enter @voyager.com in the input field, then you can only access O365 accounts ending in this domain (e.g. <user@voyager.com>). If a user tries to access the O365 account with another unverified domain (e.g. <user@amazon.com>) then they will be blocked and the user will see a Microsoft O365 block page.

{% hint style="info" %}
You’ll see on the right side panel of your cloud application policy control screen a checkbox for personal login. If this is selected it means dope.swg allows access to personal Microsoft domains: hotmail.com, live.com, msn.com, passport.com, and outlook.com.
{% endhint %}


# Google

### To configure Google, simply enter the list of domains you want to allow access to.

All other email domains will be blocked.

![Box Configuration](/files/SRpTOdtEvJHWw1qh1xdW)

For example, if you enter @voyager.com in the input field, then you can only access Google accounts ending in this domain (e.g. <user@voyager.com>). If a user tries to access the Google account with another unverified domain (e.g. <user@amazon.com>) then they will be blocked and the user will see a Google block page.

{% hint style="info" %}
You’ll see on the right side panel of your cloud application policy control screen a checkbox for personal login. If this is selected it means we allow access to personal Google domains gmail.com and googlemail.com.
{% endhint %}


# Box

### To configure Box, enter the subdomains you want to allow access to.

All other Box subdomains will be blocked.

![Box Configuration](/files/bY8FmhxwxyUr3eNrOTCe)

With Box, you can select a block page from the dropdown in the righthand panel which will appear if your users attempt to access an unauthorized account.


# Salesforce

### To configure Salesforce, enter the email domains you want to allow access to.

All other Salesforce subdomains will be blocked.

![Salesforce Config](/files/rZCi2cS67u3cTJT1GeZk)

With Salesforce, you can select a block page from the dropdown in the righthand panel which will appear if your users attempt to access an unauthorized account.


# Dropbox

### To configure Dropbox, enter the Dropbox ID you want to allow access to.

All other Dropbox IDs will be blocked.

![Dropbox Configuration](/files/vfkzggfzoN557yt1NIbN)

If a user tries to access the account with another unverified Dropbox ID, then a dropbox block page is shown.

{% hint style="info" %}
If you need get further information from dropbox, you can get it here <https://help.dropbox.com/teams-admins/admin/network-control>.
{% endhint %}


# Slack

### To configure Slack, enter the Slack Workspace ID you want to allow access to.

All other Slack Enterprise IDs will be blocked.

![Slack Configuration](/files/02flAu0pVdXodSr7ZvaH)

If a user tries to access the account with another unverified Slack Workspace ID, then a Slack block page is shown.

{% hint style="info" %}
If you need get further information from Slack, you can get it here: <https://slack.com/intl/en-ie/help/articles/360024821873-Approve-Slack-workspaces-for-your-network>.
{% endhint %}


# WebEx

### To configure WebEx, enter the list of domains you want to allow access to.

All other email domains will be blocked.

![WebEx Configuration](/files/sSHvQyRj9mXPjkZDEDi1)

For example, if you enter @voyager.com in the input field, then you can only access WebEx accounts ending in this domain (e.g. <user@voyager.com>). If a user tries to access the WebEx account with another unverified domain (e.g. <user@amazon.com>) then they will be blocked and the user will see a WebEx block page.


# ChatGPT

### To configure ChatGPT, enter the list of Enterprise workspace IDS you want to allow access to.

{% hint style="info" %}
This control is limited to ChatGPT Enterprise customers.
{% endhint %}

Access to all other ChatGPT accounts will be blocked.

<figure><img src="/files/3nvEaZElO9rs9ZzgEamw" alt=""><figcaption></figcaption></figure>

If a user tries to access the account that is that an Enterprise Account not in the allowed list, then a ChatGPT block page is shown:\ <br>

<figure><img src="/files/rdCqE1IZautp4HvZ2zKY" alt="ChatGPT Tenant Restriction Error Page" width="375"><figcaption><p>ChatGPT Tenant Restriction Error Modal</p></figcaption></figure>

## Resolve certificate pinning message on macOS

The ChatGPT macOS desktop app uses [certificate pinning](/dope.console/notifications/ssl-errors) and requires an extra step to work correctly. The app will show an error below until this is resolved:

<figure><img src="/files/4iEIE9Ph7tio673CrgxU" alt="ChatGPT certificate pinning error referencing dope.security_root_ca"><figcaption><p>ChatGPT blocked by certificate pinning when dope inspects its traffic</p></figcaption></figure>

{% hint style="success" %}
To resolve, ChatGPT requires you to push an MDM profile with the certificate pinning exception. This adds the dope.security root CA to the `com.openai.pinned_cert_hash_list` so interception is honored on managed devices.
{% endhint %}

Deploy the MDM profile below (`com.openai.chat`) via MDM, scoped to all macOS devices. This will allow the dope.security root CA. Download the profile or copy the XML below.

{% file src="/files/RfbgNkIuAA1kdIIuRNvS" %}

```xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>PayloadContent</key>
    <array>
        <dict>
            <key>PayloadType</key>
            <string>com.openai.chat</string>
            <key>PayloadIdentifier</key>
            <string>com.openai.chat.6F319227-5470-486E-B3E0-05F94E6129CC</string>
            <key>PayloadUUID</key>
            <string>6F319227-5470-486E-B3E0-05F94E6129CC</string>
            <key>PayloadVersion</key>
            <integer>1</integer>
            <key>PayloadDisplayName</key>
            <string>ChatGPT Managed Configuration</string>
            <key>PayloadDescription</key>
            <string>Adds the dope.security root CA to the ChatGPT certificate pin exception list so TLS interception is honored on managed devices.</string>
            <key>com.openai.pinned_cert_hash_list</key>
            <array>
                <string>iNWD5OB/39KJxie93dnbzXfmJjiM8unOxvVv6BlFXMM=</string>
            </array>
        </dict>
    </array>
    <key>PayloadType</key>
    <string>Configuration</string>
    <key>PayloadVersion</key>
    <integer>1</integer>
    <key>PayloadIdentifier</key>
    <string>security.dope.chatgpt.cert-pin-exception</string>
    <key>PayloadUUID</key>
    <string>873EDEBC-998C-4B8D-B99E-35C00EBAFC3C</string>
    <key>PayloadDisplayName</key>
    <string>ChatGPT – dope.security Certificate Pin Exception</string>
    <key>PayloadDescription</key>
    <string>Allows the ChatGPT desktop/mobile app to accept TLS interception by the dope.security secure web gateway by pinning the dope.security root CA SPKI hash.</string>
    <key>PayloadOrganization</key>
    <string>dope.security</string>
    <key>PayloadScope</key>
    <string>System</string>
    <key>PayloadRemovalDisallowed</key>
    <false/>
</dict>
</plist>
```

{% hint style="info" %}
Pinning is checked against every certificate up to the trusted root, so adding the dope.security root CA hash is sufficient. Multiple hashes can be listed to cover additional/test CAs.
{% endhint %}


# Claude

### To configure Claude, enter the list of Claude Organization IDs you want to allow access to.

Access to all other Claude accounts will be blocked.

<figure><img src="/files/Bnvw9APxknAWVro3wSag" alt=""><figcaption></figcaption></figure>

If a user tries to access the account that is that a Claude Organization ID not in the allowed list, then a Claude block banner is shown.

{% hint style="info" %}
This control is limited to Claude Enterprise customers.
{% endhint %}


# GitHub

### To configure GitHub, enter the list of GitHub Enterprise IDs you want to allow access to.

Access to all other GitHib accounts will be blocked.

<figure><img src="/files/rgXVOOtjrf7450UTwPLN" alt=""><figcaption></figcaption></figure>

### Default Bypass List

There are 3 GitHub domains in the Dope Default Bypass list that need to be set to 'Do Not Bypass', these are \*.github.com , \*.githubcopilot.com and \*.githubusercontent.com.

{% hint style="warning" %}
If these domains are not set to 'Do Not Bypass' this GitHub CAC feature will not work correctly
{% endhint %}

### SSL Cert Errors

Once these domains are set to 'Do Not Bypass' endpoints running the dope agent may see some SSL cert errors for GitHub traffic. To ensure this doesn't happen running the following commands on all endpoints will solve for this issue.

#### Windows

```
git config http.sslcainfo C:\ProgramData\dope.security\res\certs\dope.security.root.crt
```

#### macOS

```
git config http.sslcainfo /Library/Application\ Support/dope.security/res/certs/dope.security.root.crt
```


# Custom Policy

### **The world’s a small place, but it’s got a lot of rules. When you’re flying first class, you want friction-free travel as you traverse the globe.**

**You may need to create multiple policies to deal with your organization’s needs** ⁠— **different geographical locations may require specific customizations for your organization’s needs in that location. Or you may need to create special requirements for some of your user groups. dope.swg has thought of that.**<br>

{% hint style="info" %}
To create a custom policy, you need to have previously imported all users and group data.
{% endhint %}

<figure><img src="/files/fwnjMQQnblXeZTSm6e69" alt=""><figcaption></figcaption></figure>

To create your first new policy, click on the “Create a New Policy” button on the right-side panel. Name your policy and click on the arrow\..

<figure><img src="/files/T2BmpZc6uc05syow0Kqc" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
A policy name can be up to 32 characters long and must be unique.
{% endhint %}

The new policy inherits the Base Policy <img src="/files/aHS0tZS59dZ4oaQ6Xf9M" alt="" data-size="line"> configuration but you can adjust this to your requirements.

<figure><img src="/files/heKQby2UDZJO1vipGqWn" alt=""><figcaption></figcaption></figure>

### Editing Your Custom Policy

Editing your new custom policy is the same as editing the base policy. [Editing the Base Policy](/dope.console/dope.swg-policy/editing-the-base-policy)

### Policy Testing

Before a policy can be tested it must be assigned to a user or group. [Policy Assignment](/dope.console/dope.swg-policy/policy-assignment)

## All Policies View

To view all Policies, select “Policies” in the navigation and it will bring you to the policy table view.

<figure><img src="/files/lx4odkg1UoXZwVCQDP4T" alt=""><figcaption></figcaption></figure>

### Deleting a Custom Policy

You can delete a policy from this list whenever you want. Simply select the policy you want to delete, then select the delete icon <img src="/files/uNxgynrGd5mmIUaUxyKW" alt="" data-size="line"> at the end of policy’s line in the table. Confirm the deletion in the right-hand side panel.

![Delete Confirmation Option](/files/2DR9VNuEiCoe9biJOrZ3)

{% hint style="danger" %}
It is not possible to delete the Base Policy.
{% endhint %}

To create additional new policies, click on the <img src="/files/1UoNPx9RTTnXOQl1GHBx" alt="" data-size="line"> button next to “All Policies”. This will restart the flow to create a new policy.


# Policy Tester

The Policy Tester can be accessed on the SWG tab, or inside of a SWG policy. With it, you will see exactly how a URL will be treated for a specific user or group without testing on your laptop. It mirrors the policy engine on the endpoint, so you can validate changes without asking users to reproduce on their device.

Use it to:

* Debug access issues for a user or group
* Verify new or edited policies before rollout
* Confirm that exceptions are working
* Check the category of a website

<figure><img src="/files/LuXAQmK3dSOEL5QosZIF" alt=""><figcaption><p>Find the policy tester at the bottom right of the SWG tab</p></figcaption></figure>

***

{% hint style="danger" %}
**No device-endpoint state**\
The Policy Tester will not know if a user clicked “Proceed” on a warning page on their device. If an endpoint is currently allowing a site because the user accepted a warning, the Policy Tester will show the verdict (e.g., `Warn`)\
\
**No network conditions**\
The tool does not simulate TLS errors or connectivity issues. It answers only: “If this traffic reaches dope.endpoint and is evaluated by policy, what should happen?”

**No malware override visibility**\
Policy Tester focuses on policy verdict evaluation. Runtime malware/security checks may still block traffic after policy evaluation.

**Use logs for history**\
Policy Tester shows expected behavior, not past events. To see what actually happened for a real request, use your activity or SIEM logs alongside this tool
{% endhint %}

### Running a test

1. **Select the user or group**\
   Start typing a name or email in **Search User/Group** and pick the correct identity. This determines which policy will be evaluated.
2. **Enter the URL**\
   Type a domain (`thepiratebay.org`) or full URL (`https://thepiratebay.org/`).
3. **Click&#x20;*****Go***\
   Policy Tester evaluates the request and shows the result under **Status**

<figure><img src="/files/x5Uwu2eevMAvgkRO8SA3" alt="" width="375"><figcaption></figcaption></figure>

### Understanding the results

#### Status can be:

* **Allowed**
* **Warn**
* **Blocked**

#### Explanations:

* **Policy assignment:** Shows the policy applied to the selected user/group
* **Category restrictions:** Shows the categories of the URL and any restrictions, e.g.:\
  `The Category "Torrents/P2P" has restrictions`
* **Other rule matches:** Indicates any custom URL rules or app controls that influenced the verdict.


# Policy Assignment

### When a new user is imported into dope.swg, they are automatically assigned to the Base Policy. If they are assigned to a policy based on a group, this will override the Base Policy.

On the creation of a new policy it is possible to assign users to a policy by either User Name or Group.

To do this, in the Policy select the Users tab on the lefthand side.

![Assigned Users/Groups to a Policy](/files/8rO1vtnfB2wFh2IoH5Rt)

In the text box, enter in a user or group from your imported users and groups. Once you start typing, the console will provide suggested users and groups.

<figure><img src="/files/TWUl7ykU0k7FHMA64zAz" alt=""><figcaption></figcaption></figure>

Once you have assigned the user or group, then the policy will need to be saved.

<figure><img src="/files/u9XYdLJ7oggpdQQ2fJmW" alt=""><figcaption></figcaption></figure>

It is also possible to delete an assignment. Simply select the user or group whose assignment you want to delete and from the righthand panel select the Delete option.

<figure><img src="/files/YTCFbAn8SsEnIKMuk2ka" alt=""><figcaption></figcaption></figure>

After you have deleted the assignment, save the policy.

## Some Simple Rules

{% hint style="warning" %}
You cannot add the same user or group to multiple policies.

In the case of multiple policies, where a user has been assigned to more than one policy, then the user shall default to the Base Policy.

If an individual user has been assigned to a policy and that user is already in a group assigned to another policy, the individual policy will take precedence over the group policy.

Any update to the user and group data will be reflected in the policy assignment view.

If a user is not assigned to a policy they will default to the Base Policy
{% endhint %}

{% hint style="info" %}
You can use the policy tester to check the policy that a user or group is assigned to.
{% endhint %}


# Policy Inheritance and Customization

### If you create a new security policy, it will inherit dope.swg’s Base Policy. You can adapt a policy to your individual user needs. And you can undo any policy changes by just reverting back to the dope.swg Base Policy. It's simple. It’s safe.

## Inheritance

Any new policy you create will inherit the entire base policy. An “Inherits Base” tag is visible in all the policy screens to highlight this.

![Dope Categories with the “Inherits Base” tag](/files/JUtk9khB7z8qYwu7sCM6)

![Cloud Application Control with the “Inherits Base” tag](/files/xEq9Cq9RkTlN64JleKZC)

For a policy that inherits from base, you can jump back to the base policy by hovering over the “Inherits Base” tag <img src="/files/aHS0tZS59dZ4oaQ6Xf9M" alt="" data-size="line">. This will change to a “Go to Base Policy” tag <img src="/files/pnloY9WKBWJGlk79xLAe" alt="" data-size="line"> when hovering. If you choose to select, you will be taken to the same policy section of the Base Policy.

{% hint style="info" %}
A policy that inherits from Base Policy will be automatically updated when an update is made to the Base Policy.
{% endhint %}

###

## Customization

A policy section will become customized once any edits are made to that section.

{% hint style="warning" %}
Once a policy section is customized, any edits made within the policy section will only affect that policy.
{% endhint %}

A policy has the following sections:

* Dope Categories (includes Custom Categories)
* Cloud Application Control
* Bypass
  * Domain Bypass
  * Application Bypass

### Dope Categories Customization

Any of the following edits will result in the section becoming Customized:

* Restriction level change for parent category, subcategory, and custom category
* New policy exceptions
* Updates to the block, security risk, and warning page assignments

### Cloud Application Control

Any of the following edits will result in the section becoming Customized:

* Addition of a new domain, sub domain, tenant ID, or account ID to any application
* Enabling a Cloud Application not already enabled
* Disabling a Cloud Application already enabled

### Domain Bypass

Any of the following edits will result in the section becoming Customized:

* Addition or deletion of a domain

### Application Bypass

Any of the following edits will result in the section becoming Customized:

* Addition or deletion of an application

{% hint style="info" %}
For a customized policy section you can revert it back to Base Policy by simply hovering over the “Customized” tag <img src="/files/5tFlHmXJObQSdNByih6U" alt="" data-size="line">. This will change to a “Reset Policy” tag <img src="/files/EeZWpqpI8V7h7VtYizf8" alt="" data-size="line"> when hovering. Selecting the Arrow icon will revert the policy section back to the Base configuration.
{% endhint %}


# CASB Neural

LLM-Powered Data Loss Prevention

CASB Neural is the first of its kind leveraging deep learning AI and Large Language Models (LLM). We instantly crawl your Microsoft 365 or Google tenant and identify all publicly and externally shared files containing PII, PCI, PHI, and IP, and will automatically monitor for any file-sharing changes. This is done with zero pre-configurations.

We call this **Dopamine DLP.**

<figure><img src="/files/qftdjHnFn5RqO1FJq1Fi" alt=""><figcaption><p>Real-world examples of different DOPAMINE hits</p></figcaption></figure>

Once activated, CASB Neural automatically scans your SaaS tenant, discovers all public/externally shared files, and monitors for any file-sharing changes. Leveraging deep learning LLM, it comprehends these files to find IP, PII, PCI, and PHI data. In other words, it answers the question, “Is this sensitive?”

By leveraging LLMs and actually comprehending the files, we materially reduce the amount of false positives—this results in higher precision and accuracy. Previously, this had to be done using regex and pattern matching, i.e. a 16-digit number = a credit card. This shift from matching to true file comprehension is an industry first and completely reduces the administrative overhead.


# Microsoft 365 - Authentication

### UX = dope.security. That’s why it only takes seconds to get your CASB scan of Microsoft 365 started.

## Authentication

From the CASB tab in dope.console, select Microsoft 365 from the left-hand panel.

The authentication URL can either be self-enrolled, or sent to your 365 tenant admin to grant the required permissions to dope.security. For them, it's a one-click authorization.

<figure><img src="/files/aPwCoHiOUyKL1GSE6e2h" alt=""><figcaption><p>Microsoft Authentication Link</p></figcaption></figure>

At the authentication URL, the Admin will be asked to grant dope.security with a set of permissions to allow CASB Neural to scan their Microsoft 365 tenant.\ <br>

<figure><img src="/files/R9zTLXxJ4lyT3Y0KmE2V" alt=""><figcaption><p>Example of the authorization screen an admin will click through</p></figcaption></figure>

Once permissions are granted then, your done! It really is that simple, dope.security will now scan your tenant, uncover any publicly shared files with sensitive data, and classify them!

{% hint style="info" %}
**SSPM Coming Soon:** Uncover all third-party apps connected to your Microsoft 365 or Google SaaS tenant, neatly organized by access type: global, limited, or login access.
{% endhint %}

| Scopes                             | Purpose                                                                                |
| ---------------------------------- | -------------------------------------------------------------------------------------- |
| ActivityFeed.Read                  | Allows us to read company activity data                                                |
| AuditLog.Read.All                  | Allows us to query logs for third-party integrations                                   |
| Application.Read.All               | Allows us to read third-party integrations                                             |
| Directory.Read.Write.All           | Allows us to read/write data for the company directory, such as users, groups and apps |
| Files.ReadWrite.All                | Allows us to read/write files in all site collections                                  |
| Policy.Read.All                    | Allows us to read company policies. Used to inspect Security + Conditional Access.     |
| Policy.ReadWrite.ConditionalAccess | Allows us to read/write conditional policies                                           |
| Sites.FullControl.All              | Allows us to control site collections                                                  |
| User.Read                          | Allows us to read profile and basic company information                                |
| User.ReadWrite.All                 | Allows us to read/write details about users                                            |


# Google - Authentication

UX = dope.security. That's why it takes seconds to get CASB Neural scanning your Google Drive.

## Authentication

Under CASB, select Google. Self-enroll with the URL or send it to your Google admin.

<figure><img src="/files/FzB0XU92xb5x1MvBiLKj" alt=""><figcaption><p>Google Authentication Link to be used by Admin</p></figcaption></figure>

Your Google admin will need to copy & paste permissions into the Google admin console (Underneath API Controls -> [Domain-Wide Delegation](https://admin.google.com/u/0/ac/owl/domainwidedelegation))

<figure><img src="/files/O3LR9yEioSaSv2kifK3g" alt=""><figcaption><p>Admins must copy/paste this information into the Workspace Admin Console</p></figcaption></figure>

{% hint style="info" %}
These are the required Google scopes

"<https://www.googleapis.com/auth/drive>", "<https://www.googleapis.com/auth/admin.directory.user>", "<https://www.googleapis.com/auth/admin.directory.domain.readonly>", "<https://www.googleapis.com/auth/admin.directory.customer.readonly>", "<https://www.googleapis.com/auth/drive.activity.readonly>", "<https://www.googleapis.com/auth/admin.directory.group.readonly>", "<https://www.googleapis.com/auth/admin.directory.user.readonly>", "<https://www.googleapis.com/auth/admin.directory.user.security>", "<https://www.googleapis.com/auth/admin.reports.audit.readonly>", "<https://www.googleapis.com/auth/gmail.settings.basic>",
{% endhint %}

<table><thead><tr><th width="307">Scope</th><th>Purpose</th></tr></thead><tbody><tr><td><p>admin.directory.user</p><p>admin.directory.domain.readonly admin.directory.customer.readonly<br>admin.directory.group.readonly<br>admin.directory.user.readonly</p></td><td>Retrieves group member information for user/group import, identify posture (2FA/Admin) for CASB Neural SSPM</td></tr><tr><td>admin.directory.user.security</td><td>Retrieves OAuth tokens and allows deletion for CASB Neural SSPM</td></tr><tr><td>admin.reports.audit.readonly</td><td>Retrieves logs for OAuth apps for CASB Neural SSPM</td></tr><tr><td>gmail.settings.basic</td><td>Retrieves mail rules (not email content) to find suspicious mail rules for CASB Neural SSPM</td></tr><tr><td>drive<br>drive.activity.readonly</td><td>Retrieves drive information for CASB Neural DLP</td></tr></tbody></table>

About Google Admin Console Configuration

{% hint style="warning" %}
To complete authorization the Google admin will need to copy & paste the scopes into the Google Admin Console. You must be a Google admin to continue.
{% endhint %}

Because of CASB Neural's sensitive permissions, the scopes are added to Domain Wide Delegation page. It's under: [Security > API Controls > MANAGE DOMAIN WIDE DELEGATION](https://admin.google.com/ac/owl/domainwidedelegation) in the Google Admin Console.

From here, you will add a new domain-wide delegation to their account. This includes CASB Neural's client ID and the required scopes (provided).

{% hint style="info" %}
See Google help docs [here](https://developers.google.com/identity/protocols/oauth2/service-account#delegatingauthority)
{% endhint %}

### Google Workspace Super Admin Email

The final step is to provide the Google Workspace super admin email

<figure><img src="/files/R5tq52nBM6MloaxYecKx" alt=""><figcaption><p>Add the super admin email used here.</p></figcaption></figure>

Once the correct email is entered, you're done! It's that simple. dope.security will now scan your tenant, uncover any publicly shared files with sensitive data, and classify them.

{% hint style="info" %}
**SSPM Coming Soon:** Uncover all third-party apps connected to your Microsoft 365 or Google SaaS tenant, neatly organized by access type: global, limited, or login access.
{% endhint %}


# CASB DLP

Once setup is complete, CASB Neural will immediately start scanning your tenant.

{% hint style="success" %}
Depending on your company, this can take hours (thousands of files) to days (millions of files) to complete. But, we will start to show you results as soon as we have them!
{% endhint %}

<figure><img src="/files/Z31FwGBtuxB11Nj4Xhiu" alt=""><figcaption><p>Your CASB Neural Landing Page</p></figcaption></figure>

## File Count

At the top, you'll see two file counts:

* Total Number of Files
* Total Number of Publicly Accessible Files
* Total Number of Externally Shared Files

<figure><img src="/files/zaEpLEu1PN8P8sQz5yBh" alt=""><figcaption><p>Total Number of Files/ Total Publicly Accessible / Total Externally Shared</p></figcaption></figure>

{% hint style="danger" %}
Publicly accessible files can be accessed by anyone on the Internet without any authentication. Once you have the link, which could be guessed or found by any user, it can be used forever.\
\
They're a big risk to your company.
{% endhint %}

{% hint style="info" %}
Files that are shared both Publicly and Externally are counted in Public Only
{% endhint %}

CASB Neural will automatically monitor your Microsoft 365 / Google tenant, and these numbers will update to reflect what's up-to-date.

## Data Graph

The CASB DLP graph shows the classification results of your public files.

The graph shows the breakdown of files that have been classified as IP (Intellectual Property), PHI (Protected Health Information), PCI (Payment Card Industry), PII (Personally Identifiable Information), or Other Public Files (Public files with no sensitive information found).

Clicking on any classification result will bring you to the CASB table filtered to this classification type.

<figure><img src="/files/4viC0W1o8oirS0XNDDXz" alt=""><figcaption><p>CASB Graph</p></figcaption></figure>


# DLP Files Table

### While the CASB DLP Data Graph gives a high-level overview of the scan results, the table retrieves specific details of each publicly shared file.

Unlike any other CASB product, this table extracts the exact details on why a file was classified as possible risk and provides the **Dopamine Hit (LLM-Generated DLP)** which summarizes the contents of the file.

This makes it easy for you to make a decision on next steps.

## Contents

<table><thead><tr><th width="264">Field</th><th>Description</th></tr></thead><tbody><tr><td>Name</td><td>The name of the file from your tenant</td></tr><tr><td>Type</td><td><p>The classification type assigned to the file. This can be one or more of the following:</p><ul><li>IP (Intellectual Property)</li><li>PHI (Public Health Information)</li><li>PCI (Payment Card Industry)</li><li>PII (Personally Identifiable Information)</li><li>Other Public Files (Public files with no sensitive information)</li><li>Unclassified (External Shared Files Only)</li></ul></td></tr><tr><td>Status</td><td>Indicates if the admin has marked a file as reviewed or not</td></tr><tr><td>Shared</td><td>Indicates if the file is shared publicly or with an external email</td></tr><tr><td>Comment</td><td>A review comment can be added to each file, <em>coming soon</em></td></tr><tr><td>Created By</td><td>The email address of the user who created the file</td></tr><tr><td>Created On</td><td>The time or date the file was created</td></tr></tbody></table>

## File Classification Details

### Detections

The right hand panel provides the details on why the file given its classification type.

Where a file has been detected to have either IP, PHI, PCI, or PII, the information from the file that resulted in this classification is listed, color coded based on classification type.

<figure><img src="/files/LuVh6QhzQMwEe5TWcih3" alt="" width="563"><figcaption><p>Detection Example</p></figcaption></figure>

### Dopamine

Unlike any other CASB product on the market, dope.security provides a Dopamine summary of the document that has been classified. This is only possible because of the AI technology that we are using to provide classification. This Dopamine summary allows admins to get an understanding of what type of documents have been exposed publicly.

<figure><img src="/files/2AykrtLhKOifUY6yf6ej" alt="" width="563"><figcaption><p>Dopamine Example</p></figcaption></figure>

{% hint style="info" %}
Currently files that are shared with an external email are not classified. The ability to classify these files will be added shortly.
{% endhint %}

### Who has access to the file

The right-hand panel is also where you can go to see who has access to the file. The email addresses of the people who have access to the file will be grouped into three sections Public, External and Internal. Within the external sections any email marked with the following icon <img src="/files/dF02Htbmiu5HtsCMWOWG" alt="" data-size="line"> highlights that this is a personal email.

<figure><img src="/files/0eoJgPBRGESA9kS1qbOW" alt="" width="563"><figcaption><p>Right Hand Panel Example</p></figcaption></figure>

## Search, Filtering, and Sorting

### Search

At the top of the table, you will find a search bar that can search within ***File Name*** or ***User Name***.

### Filtering

Filter the table by classification type by clicking on the menu.

<figure><img src="/files/8Mm3akPo07H0pT60IpVd" alt="" width="563"><figcaption><p>Filter Dialog for Type</p></figcaption></figure>

It is also possible to filter by simply selecting a classification tag <img src="/files/bJcoigBiilCqRLbzosIP" alt="" data-size="line"><img src="/files/WjrPCtucjwqpKvvWPc40" alt="" data-size="line"><img src="/files/iXOkqjE7lx3Y7u6YZque" alt="" data-size="line"><img src="/files/lhLffSBoflAlnVfuVa7o" alt="" data-size="line"><img src="/files/HlZWWKzfjP1kPVcjCQ4j" alt="" data-size="line"> in the ***Type*** column.

You can also filter the table by Shared Type by clicking on the menu.

<figure><img src="/files/B1Cj1ogGzW7FKuknorRY" alt="" width="563"><figcaption><p>Filter Dialog for Shared</p></figcaption></figure>

## Removing permissions

It is possible to remove the public sharing permissions from one, many, or all of your public from within the dope console. Removing the Public sharing permissions will mean the file is no longer publicly shared i.e. anyone with the link can no longer access the file.

Where a file is shared both publicly and externally it is also possible to remove both the public and external sharing permissions. And where a file is shared with just externally it is possible to just remove the external sharing permissions.

To remove the public permissions select one or multiple files in the CASB table and select the ***Remove Public*** button on the bottom right of your view.

<figure><img src="/files/QcQuQ5UDQDxTj8BWgkbC" alt=""><figcaption><p>Remove Public Option</p></figcaption></figure>

To remove both public and external sharing permissions elect one or multiple files in the CASB table and select the ***Remove Public + External*** button on the bottom right of your view.

<figure><img src="/files/Ghr4XaZxtat3ozPFFECo" alt=""><figcaption><p>Remove Public + External Option</p></figcaption></figure>

To remove just external sharing permissions select one or multiple files in the CASB table and select the ***Remove External*** button on the bottom right of your view.

<figure><img src="/files/rp5JXgG91R1WXmReeeSm" alt=""><figcaption></figcaption></figure>

That’s all that you need to do! The file will have the sharing permissions removed from your Microsoft 365 / Google tenant. Once the permissions are removed, your CASB table will update to remove the files from view. These files will now be included in the private or external file count.

{% hint style="info" %}
In some cases, it can take up to 15 minutes for the Microsoft 365 / Google tenant to respond. It is possible to get the latest status of the file by hovering over it in the CASB table.
{% endhint %}

## Marking a file as “Reviewed”

There are probably some publicly shared files that you will not want to remove the sharing permissions for. These can be marked as “Reviewed” to let others know that the file has been reviewed for content and intentionally kept public.

To mark a file as “Reviewed,” select the arrow next to “Remove Public” to toggle the option open.

<figure><img src="/files/wDnSq6yT5Sy5YRcuv2ki" alt=""><figcaption><p>Comment Box</p></figcaption></figure>

When you mark a file as “Reviewed,” it is then possible to add a comment to explain why the file has been reviewed and remains publically accessible. Once the comment has been added, confirm by reselecting the “Mark as Reviewed” button.

<figure><img src="/files/2JB2MBdO9bAo5ojzdecq" alt="" width="563"><figcaption></figcaption></figure>

The file will then update its status and move to the bottom of the CASB table.

<figure><img src="/files/gxQsgpzruLhdk6DFOabu" alt="" width="563"><figcaption><p>Mark as Reviewed</p></figcaption></figure>

{% hint style="info" %}
Leaving a review comment is optional, a file can be marked as “Reviewed” without a comment.
{% endhint %}


# Endpoint Manager View

### The Endpoint Manager View lets you see all of the dope.swg endpoints installed across your organization, allowing you to keep track of your users at a glance.

**All of your organization’s users who have successfully installed dope.swg are listed on the Endpoint Manager View.**

![Endpoint Manager View](/files/lkfOd1xOOXc9aNxXhPLm)

## The Endpoint Manager View

The Endpoint Manager View lets you see:

* **Device Name:** The name of the device running the dope.swg endpoint.
* **Status:** The current status of the dope endpoint. The endpoint will display the endpoint as healthy, error, disabled, or dormant.
  * **Healthy:** The dope.swg endpoint is working, with no errors.
  * **Error:** The dope.swg endpoint has an error and is not working.
  * **Disabled:** The dope.swg endpoint has been put into disabled mode by the admin
  * **Dormant:** The dope.swg endpoint has not sent a health check for more than seven days. These devices are removed from the view if a health check is not received for 28 days.
* **User:** This shows the email address of the user currently logged in to the device. Where users and groups have not been imported this will be the logged-in user.
* **Policy Assigned to User:** This shows the dope.swg policy you are currently assigning to the selected user and which is being applied on the endpoint.
* **Last Seen:** The last time the dope.swg endpoint sent a health check to the dope.cloud.
* **Endpoint Version:** The version of dope.swg currently installed on the selected device.
* **Debug Mode:** If the dope.swg endpoint is currently running in debug mode, it will be indicated by the icon in the status column.
* **Location:** The current location of the device.

{% hint style="info" %}
You can sort the endpoint table by “Last Seen” Time
{% endhint %}

<figure><img src="/files/VpRRBNLMzSHR7DcdmJmf" alt=""><figcaption></figcaption></figure>

### **Endpoint Count**

When the Endpoint Manager View initially opens there’s a count of all of your organization's endpoints and their current states.

* **Total MacOS Endpoints:** Total number of endpoints running on macOS
* **Total Windows Endpoints:** Total number of endpoints running on Windows
* **Total in Error:** Total number of endpoints in an Error state. Select individual Endpoints to see the type of error.
* **Total Disabled:** Total number of endpoints that have been manually disabled.
* **Total Uninstalled:** Total Endpoints that have been uninstalled.
* **Fallback Mode:** Total endpoints in Fallback Recovered state.
* **Connected for Updates:** Total Endpoints that are connected and able to receive updates.

{% hint style="info" %}
Active Endpoints = Healthy + Error + Disabled + Dormant
{% endhint %}

​

<figure><img src="/files/dc7mRsEyOOELwfWEHZXz" alt=""><figcaption></figcaption></figure>

## Individual Device

If you select an individual device, the Endpoint Manager View will show you additional information, alongside the device name and last seen time.

* **Processor Type:** The selected device’s processor type.
* **OS Version:** The operating system that the selected device is running.
* **Status:** Where the endpoint is in error you can see the type of error:
  * DopeRedirector is not running.
  * DopeRedirector is running but bypassing all traffic.
  * Agent is running but inactive.
  * Agent is in an Error state.
  * Agent is not running.
  * Fallback Recovered. This indicates that the dope.endpoint has been in Fallback mode at least once in the last 24 hours but has recovered.


# Searching the View

**It’s easy to search the Endpoint Manager View.**

You can search the Endpoint Manager View using either a device name or a user’s email address. Click on the search bar and enter either the device or email address. You don’t need to enter the full name or email address to carry out a search. When you input any text, it will automatically start fetching matching entries.

![](/files/PqLkSViuoNY5NFsdnnDo)

You can also search the Endpoint Manager View by OS version, location, or endpoint version. To do this, simply click on the OS version, location, or endpoint version in the table you want to search. This displays all endpoints with the same OS version, location, or endpoint version.

![](/files/vgcr197sUI9YGlYkQseG)


# Filtering and Sorting the Endpoint View

### dope.swg has set up the Endpoint Management View to be simple and informative for your organization’s needs. But flying first class, you can choose always to do things your way.

You can filter the table to display by the health status of your endpoints, i.e. Healthy, Error, Dormant, Disabled, etc.

To do this, simply select the filter icon next to the column name, and select the status you wish to filter by from the dropdown.

![](/files/2P9eJs5TqgDZZnYe7uwl)

This dropdown allows multiple status selections at once, e.g. you could search for endpoints in both “Healthy” and “Dormant,” or in any combination you select. You can also filter for endpoints in Debug and in Fallback Recover states.

Once you have made your selections the Endpoint Manager View will filter to show just those devices.


# Endpoint Count

### You want your organization’s internet security to be kept up to date — that’s what first class is all about. dope.swg keeps the Endpoint Manager View updated so you are kept informed across your organization.

## **Dormant endpoints**

A dope.swg endpoint that has not sent a health check for more than 7 days is considered to be “dormant.”

A dope.swg endpoint in a dormant state for 28 days will be deleted from the Endpoint Manager View. It will no longer be counted as an active device in your organization.

## **Uninstalled endpoints**

If a dope.swg endpoint is uninstalled from a device, the endpoint sends an uninstalled health check to the dope.security cloud. On receipt of this health check, the endpoint is deleted from the Endpoint Manager View. It is also no longer considered an active device in your organization and is removed from your active device count.

{% hint style="info" %}
For deletions of a dormant or uninstalled device, an event is added to the Audit Log where it can be viewed for 30 days. See [Audit Log](/dope.console/settings/audit-log) for more information.
{% endhint %}


# Running Diagnostics

### dope.swg offers the smoothest internet experience for your organization. But if there's a problem, we’re on it.

#### If there’s something that doesn’t seem right with any of your dope.endpoints, or you just want added reassurance, you can run a diagnostics check on your dope.endpoints, all done from the cloud without ever having to bother your organization’s users.

To launch the diagnostic view, select the Diagnostic Icon <img src="/files/t8rnfAcYP88kRQA0r67V" alt="" data-size="line"> on the bottom-right of the console in the Endpoint Manager View.

<figure><img src="/files/0zJ3ApgRaFAej4KyOEbU" alt=""><figcaption></figcaption></figure>

The selected dope.swg endpoint must be put into debug mode while you run diagnostics. Click Enable Debug Mode.

## **Auto Endpoint Diagnostics**

On the rare occasion that a dope.endpoint goes into error, the dope.endpoint will automatically run a set of diagnostic tests to try and help understand what the problem is. When a dope.endpoint is in error on selection in the Endpoint Manager View, you can view the results of diagnostic tests by launching the diagnostic view. This will display errors like this:

<figure><img src="/files/PqSQPnG1f3VjnxunBgL8" alt=""><figcaption></figcaption></figure>

## **Enable Debug Mode**

In some cases it may be necessary to retrieve more detailed diagnostics from a dope.swg endpoint that is in error. With dope.swg there’s no need to bother the end user to get this information: it can all be done from the dope.cloud Endpoint Manager View.

By selecting the Enable Debug Mode button ​<img src="/files/F5IxK4c7BFJeU7TL6gsh" alt="" data-size="line">, you can put the selected dope.swg endpoint into debug mode. The endpoint views background will turn blue to clearly indicate that the selected endpoint is running in Debug mode. The Endpoint Manager View status will also indicate that the selected Endpoint is in Debug mode.

When in debug mode the endpoint will run further diagnostic tests, enable deeper endpoint logging, and gather OS level logs. During this time, you will see the following icon <img src="/files/xibJ6Z6ISRUZLklpcRIU" alt="" data-size="line"> in the diagnostic view. Once all the debug information has been gathered and has been sent to the cloud, a new download icon <img src="/files/Wc4LHdftFbxVLfSUu865" alt="" data-size="line"> will appear.

If you click this icon a .zip file will be downloaded to your administrator’s machine. This .zip file can be shared with dope.security to help fix an endpoint issue.

Once the endpoint error has been fixed, you are ready to take the endpoint out of Debug mode. Just select the Exit Debug mode button at the bottom of the console.

![](/files/XqLFiCFKS86Yrqj6AoaS)

When this is selected, the endpoint will come out of debug mode and the Endpoint Manager View will return to normal. You’re good to go again.


# Disable Endpoint

### On occasion, you may need to disable a dope.swg endpoint for one of your organization’s user for a period of time. dope.swg ensures that you can do this from the dope.cloud in just a few seconds.

## Disable Endpoint

To disable dope.swg for a specific endpoint:

1. Select the endpoint in the Endpoint Manager View.
2. Select the disable button <img src="/files/ygBp0ZJHbaZvsfzGZ5ZB" alt="" data-size="line"> at the bottom right of the console
3. Once the selected endpoint is disabled, the icon will change to the following blue color <img src="/files/CeJrOTxGrTGYHDaOXhW5" alt="" data-size="line">.

The selected endpoint is now disabled.

## **Re-enable endpoint**

1. When you decide to enable an endpoint again — just click the same button <img src="/files/CeJrOTxGrTGYHDaOXhW5" alt="" data-size="line">.
2. Once the selected endpoint is re-enabled, the button will return to its normal color <img src="/files/ygBp0ZJHbaZvsfzGZ5ZB" alt="" data-size="line">.

{% hint style="info" %}
It’s also possible to disable the dope.swg endpoint from the endpoint itself. This process is described here: [Disable Endpoint](/dope.endpoint/disable-agent)
{% endhint %}


# Settings


# General

## Setting up

On initial sign up to the dope.swg product the first admin will be brought to the Settings -> General -> Account Settings page.

![Account Settings Page](/files/cOiqOPKi1V4VxhYIx3Z9)

It's from this screen that you—or your organization’s first administrator—can invite other users to be dope.swg console admins.

### Inviting Admins

To invite another user the admin simply needs to select the plus button <img src="/files/ntej2FfzhD8p8SWP1TnN" alt="" data-size="line">

In the right-hand panel, select the role you want the user to have, either **Administrator, SOC Analyst** or **Read Only**. For more information on the Roles Permissions see [RBAC Type Permissions](#rbac-type-permissions)

<figure><img src="/files/3TOV7hR9oryGNh0LqYEf" alt="" width="360"><figcaption><p>Select Role Type</p></figcaption></figure>

Enter the new admin’s email address in the text box provided and hit your enter key or select the arrow icon. This will send an invite email to the new admin.

The newly invited admin will appear in the administrator table.

#### The administrator table shows the following data:

* **Name:** Administrator Name
* **Email:** Administrator Email Address
* **Role:** The console displays their role as Administrator, SOC Analyst, or Viewer (Read Only)
* **Last Active:** The last time and date this admin logged into the console

{% hint style="info" %}
Until an admin accepts an invite, the name column will state ‘Invited.’
{% endhint %}

### Removing Admins

You can remove admins from the dope.console.

To remove an admin, select the admin you want to remove in the administrator table by clicking on the 3 dot menu. The right-side panel will open, allowing you to select the delete button.

<figure><img src="/files/HGEbb8CLWVggOMMjtubo" alt="" width="375"><figcaption></figcaption></figure>

{% hint style="info" %}
It is not possible for an admin to remove themselves.
{% endhint %}

## RBAC Type Permissions

Below is a table listing the allowed permissions for the three RBAC roles, Admin, SOC Analyst and Read Only User.

| Feature                                                            | Admin | SOC Analyst | Read Only User |
| ------------------------------------------------------------------ | ----- | ----------- | -------------- |
| **User/Admin Management**                                          |       |             |                |
| Create Users                                                       | ✅     | ❌           | ❌              |
| Delete Users                                                       | ✅     | ❌           | ❌              |
| Change User Roles (between read only and admin)                    | ✅     | ❌           | ❌              |
| View Admins                                                        | ✅     | ❌           | ❌              |
|                                                                    |       |             |                |
| **Analytics**                                                      |       |             |                |
| Search Analytics Data                                              | ✅     | ✅           | ✅              |
| View Analytics Data                                                | ✅     | ✅           | ✅              |
| Download Analytics Data                                            | ✅     | ✅           | ✅              |
|                                                                    |       |             |                |
| **Policy**                                                         |       |             |                |
| View Policies                                                      | ✅     | ✅           | ✅              |
| Create Policy                                                      | ✅     | ❌           | ❌              |
| Delete Policy                                                      | ✅     | ❌           | ❌              |
| View Entire Policy Configuration                                   | ✅     | ✅           | ✅              |
| Change Restriction Level (Switch between Allow, Block and Warning) | ✅     | ❌           | ❌              |
| Add/Update Exception                                               | ✅     | ✅           | ❌              |
| Change Block/Warning Page                                          | ✅     | ❌           | ❌              |
| Add Custom Categories                                              | ✅     | ❌           | ❌              |
| Add URL to Custom Category                                         | ✅     | ✅           | ❌              |
| Add Exceptions to Custom Categories                                | ✅     | ✅           | ❌              |
| **Policy-Users**                                                   |       |             |                |
| Assign Users to a Policy                                           | ✅     | ❌           | ❌              |
| **Policy-Bypass**                                                  |       |             |                |
| Add to the URL Bypass List                                         | ✅     | ❌           | ❌              |
| Add to the Application Bypass List                                 | ✅     | ❌           | ❌              |
| **Policy->Cloud App**                                              |       |             |                |
| Configure Cloud App Controls                                       | ✅     | ❌           | ❌              |
| Policy Tester                                                      | ✅     | ✅           | ✅              |
|                                                                    |       |             |                |
| **Endpoints**                                                      |       |             |                |
| View Endpoints                                                     | ✅     | ✅           | ✅              |
| Search Endpoints                                                   | ✅     | ✅           | ✅              |
| Filter Endpoints                                                   | ✅     | ✅           | ✅              |
| Enable Debug                                                       | ✅     | ✅           | ❌              |
| Disable Endpoint                                                   | ✅     | ✅           | ❌              |
| Policy Tester                                                      | ✅     | ✅           | ✅              |
|                                                                    |       |             |                |
| **Settings**                                                       |       |             |                |
| General                                                            | ✅     | ❌           | ❌              |
| **Block Pages**                                                    |       |             |                |
| View Block Pages                                                   | ✅     | ❌           | ✅              |
| Edit Default Page text                                             | ✅     | ❌           | ❌              |
| Add Custom Block/Warning Pages                                     | ✅     | ❌           | ❌              |
| **Endpoints**                                                      |       |             |                |
| View Endpoint Configuration                                        | ✅     | ❌           | ✅              |
| Refresh Anti Uninstall Password                                    | ✅     | ❌           | ❌              |
| Copy Anti Uninstall Password                                       | ✅     | ❌           | ✅              |
| Edit Fail Closed Parameter                                         | ✅     | ❌           | ❌              |
| **Users**                                                          |       |             |                |
| Change Endpoint Configuration Parameter                            | ✅     | ❌           | ❌              |
| Add Acceptable Domain                                              | ✅     | ❌           | ❌              |
| View Users Import Link                                             | ✅     | ❌           | ❌              |
| **Audit Log**                                                      |       |             |                |
| View Log Details                                                   | ✅     | ✅           | ✅              |
| Search Log                                                         | ✅     | ✅           | ✅              |
| **SIEM**                                                           |       |             |                |
| Add S3 Bucket Location                                             | ✅     | ❌           | ❌              |
| **Billing**                                                        |       |             |                |
| View Billing Details                                               | ✅     | ❌           | ❌              |
| **Notifications**                                                  |       |             |                |
| View                                                               | ✅     | ❌           | ❌              |
| Add to Bypass                                                      | ✅     | ❌           | ❌              |
| **CASB**                                                           |       |             |                |
| Overview Screen                                                    | ✅     | ✅           | ✅              |
| CASB Table                                                         | ✅     | ✅           | ✅              |
| Make Private                                                       | ✅     | ❌           | ❌              |
| Add Review Comment                                                 | ✅     | ❌           | ❌              |
| **General Actions**                                                |       |             |                |
| Download Bundles                                                   | ✅     | ✅           | ✅              |
| Switch Accounts                                                    | ✅     | ✅           | ✅              |
| Display Policy Clashes                                             | ✅     | ✅           | ✅              |


# Multi-Tenant Support for MSPs

Dope Security supports Managed Service Providers (MSPs) that manage security for multiple customers. As an MSP, you can access and manage several customer tenants using a single admin identity, and switch between them without needing separate logins.

## How It Works

Multi-tenant access is achieved by adding your MSP domain email address as an admin to each customer tenant you manage. Once added, that single email can be used to log in and access any tenant it has been granted admin rights to.

## Setting Up a Customer Tenant

To onboard a new customer under your MSP:

{% stepper %}
{% step %}

### Create the tenant using the customer's domain

Each customer tenant must be set up with the customer's own domain — not your MSP domain.
{% endstep %}

{% step %}

### Add your MSP admin email as an admin in the customer's tenant

This grants your MSP admin account access to that tenant, alongside the customer's own admins.
{% endstep %}
{% endstepper %}

Repeat this process for each customer tenant you need to manage.

## Logging In and Switching Between Tenants

When you log into [fly.dope.security](https://fly.dope.security/) using your MSP admin email, you'll be prompted to select which customer tenant you want to access for that session.

If you need to switch tenants during a session:

{% stepper %}
{% step %}

### Select the login icon

Select the login icon in the top-right corner of the screen.
{% endstep %}

{% step %}

### Choose a tenant

Choose the tenant you want to switch to from the list of tenants associated with your MSP admin email.
{% endstep %}
{% endstepper %}

All tenants you've been added to as an admin will appear in this list, letting you move between customer environments without logging out or using multiple credentials.


# Block Pages

**dope.swg** always aims to simplify things for you. It comes with ready-made block and warning pages, and you can fully customize these pages for your organization.

When a user visits a restricted web category (block or warning), **dope.swg** displays the appropriate selected block page.

The default block and warning pages can be assigned to any category or custom category with the restriction levels of (block or warning). You can also create custom pages for these categories.

### Default Pages

To edit the default block and warning pages, go to Setting -> Block Pages:

![Default Block Pages (Block, Warning, Security Risk, and Cloud Application)](/files/7vZBEOdiVR8KUUm9Gu2K)

{% hint style="success" %}
Security Risk is a block page used with Malicious Categories (Block)
{% endhint %}

#### Edit Block Page Text

To edit the Title or Message on a default block page, select the page (Block, Warning, Security Risk, or Cloud Application):

<figure><img src="/files/aXlJgmEDG7jc4lR2w81q" alt="" width="375"><figcaption><p>Only Title &#x26; Message can be edited on default block pages.</p></figcaption></figure>

### Custom Block Pages

You can create fully customized block pages using HTML too!

Select the **custom** tab, and click the<img src="/files/7kMVdjzh04WbtIkpF2la" alt="" data-size="line">button next to Block Page Configuration:

![Create a Custom Page](/files/1N4D1BmltrzZOnaYdeV2)

{% hint style="success" %}
It is possible to create a custom page from the Default block page
{% endhint %}

![Enter the name of the page, and hit enter.](/files/gog7owTKidt4qklOYkqu)

This creates the custom page will open on the right-hand side view:

![](/files/kVdS5YxVQpJQTBv0OyIb)

Next, select what type of page it is going to be — Block, Warning, Security Risk, or Cloud Application. This is done from the drop-down at the top:

<img src="/files/pv0QPi5RqeQJTj5Vto87" alt="" data-size="original">

There is also a text area where you can paste in HTML code. Once you have pasted the HTML code into the text area you can view the page by selecting the Preview Page button.\ <br>

<figure><img src="/files/PSnIdWDwaMAesFRk3Vuw" alt="" width="375"><figcaption><p>The %destination% and %category% are used to display the related data when a page is blocked</p></figcaption></figure>

If you are happy with the custom page, save it by selecting Save .

#### For information on how to assign block pages to categories see [Assigning a Block Page](/dope.console/dope.swg-policy/assigning-a-block-page)


# Endpoints

The endpoints screen within the dope.console settings allows you to configure your dope.endpoints, which is minimal effort—it requires *only two* parameters to be configured!

## Anti-uninstall Password

The first endpoint configuration is the anti-uninstall password.

**By default this parameter is not enabled,** but once there are greater than 20 endpoints installed, we recommend that you an anti-uninstall password. When you reach this milestone, you will see the following information in the right-side panel.

<figure><img src="/files/R7G1JJa2ZhRMrQj3HcF0" alt=""><figcaption><p>Endpoint side panel before and after installing greater than 20 endpoints.</p></figcaption></figure>

To enable the password, simply select the arrow next to the “Not yet configured” text.

<figure><img src="/files/QvQ6BBXG2ajDAp7Xnka9" alt="" width="563"><figcaption></figcaption></figure>

This will automatically generate an anti-uninstall password to be used for all your dope.endpoints.

<figure><img src="/files/I0DF0ZFDrJFwWhkiRBCV" alt="" width="563"><figcaption></figcaption></figure>

{% hint style="warning" %}
Once you enable an anti-uninstall password it cannot be disabled.
{% endhint %}

To generate a new password select the refresh icon <img src="/files/YovIWmFZU6YHqGQ97dam" alt="" data-size="line">.

If you want to copy the password so it can be shared simply select the copy icon <img src="/files/4iugK9dzcVPDGICk5jPY" alt="" data-size="line">.

{% hint style="info" %}
The Anti-Uninstall Password is used on the dope.endpoint for:

* End users to uninstall
* End users to disable
  {% endhint %}

## Fallback Mode

The fallback mode parameter deals with how the dope.endpoint should behave when it cannot connect to either the dope.cloud Web Category or Malware services.

When this happens the dope.endpoint can be configured to switch Fail Close Mode **‘ON’** or **‘OFF.’**

### Fail Close ON

When Fail Close is switched **‘ON,’** any website that an end user has previously accessed and is cached will have policy applied to it. If the user has previously attempted to access a blocked website, they will still be blocked.

Any attempt to access a new website will result in a ‘Block‘ response.

### Fail Closed OFF

When Fail Closed is switched **‘OFF,’** any website that an end user has previously accessed and is cached will have policy applied to it. If the user has previously attempted to access a blocked website they will still be blocked.

Any attempt to access a new website will result in an ‘Allow’ response.

{% hint style="info" %}
By default Fail Close is set to **‘OFF.’**
{% endhint %}

To set Fail Close to **‘ON’** or **‘OFF’** simply toggle the check box.

<figure><img src="/files/C4fs2Ly0XMi428ahZNaI" alt=""><figcaption><p>Fallback Mode status indicating if Fail closed is ‘OFF’ or ‘ON.’</p></figcaption></figure>

After updating any of the Endpoint configuration parameters, the updated configuration must be saved.

<figure><img src="/files/44HY8Suz60Ev1Vo88bmR" alt=""><figcaption></figcaption></figure>


# Users

To unlock all dope features, there are two easy steps:

1. **Enable Endpoint Authentication:** Forces users to authenticate with corporate accounts before they can access the Internet and automatically applies correct web security policy
2. **User & Group Import:** Allows for User/Group-based policies, and for analytics

## Endpoint Authentication

This is a one-time authentication for end-users. We do not prompt for re-authentication unless a device has been [dormant for 30 days](#user-content-fn-1)[^1].

<table data-header-hidden><thead><tr><th width="146"></th><th></th></tr></thead><tbody><tr><td>Windows</td><td>Windows users will receive a notification in the lower-right to authenticate. If they do not, web traffic will be blocked (<a data-footnote-ref href="#user-content-fn-2">unless bypassed</a>), and users will be prompted to authenticate</td></tr><tr><td>Mac</td><td>Mac users will receive a pop-up. If this window is closed, it will automatically reopen to prompt the user to authenticate. Web traffic will be blocked (unless bypassed), until this is complete</td></tr></tbody></table>

## User & Group Import

{% hint style="info" %}
See [Import User and Group Data](/introducing-dope.swg/quick-start-guide/import-user-and-group-data) for a more detailed breakdown.
{% endhint %}

The Google or Microsoft 365 admin must authorize access to the users and groups for the import. Once authenticated, dope.security will import your users and groups.

{% hint style="warning" %}
Special steps are required on Google (See [Importing from Google](/dope.console/settings/users/importing-from-google)).
{% endhint %}

{% hint style="warning" %}
Azure / Microsoft Entra Security Groups are not currently supported for policy assignment and exceptions in dope.console
{% endhint %}

Every 15 minutes, all user & group updates are automatically synchronized. i.e. any employee who joins, leaves, or changes groups will automatically update

<figure><img src="/files/z0oHRjBtNoeK06y9ENmY" alt=""><figcaption><p>Click &#x26; save to enable SSO</p></figcaption></figure>

{% hint style="danger" %}
Without importing users and groups into the console, the following functionality will not be available:

* Custom Policies
* Policy Exceptions
* Shadow IT & Productivity Analytics
  {% endhint %}

[^1]: Devices move from Active -> Dormant if offline for 7 days.

[^2]: Application/domain bypasses will not be impacted by this.


# Importing from Microsoft

Importing users from Microsoft can typically be performed directly via the link without extra steps. However, if there are restrictive permissions in Microsoft, you will need to manually enable the permissions.

{% hint style="warning" %}
These steps are not required unless you are blocked from signing in using your corporate Microsoft domain
{% endhint %}

{% hint style="warning" %}
Azure / Microsoft Entra Security Groups are not currently supported for policy assignment and exceptions in dope.console
{% endhint %}

### Add Enterprise Applications

We use a single OIDC application for both endpoint authentication and importing the users.

```
Application ID: 0556f6fa-1833-4b20-ac87-c3721972ead0
```

{% hint style="info" %}
Add this enterprise application in Microsoft Entra ID and grant admin consent for the permissions below.
{% endhint %}

### Add Permissions

All required permissions are listed below, and should be granted admin consent:

<figure><img src="/files/ou8JuQm7EVazCXbJas5c" alt=""><figcaption></figcaption></figure>


# Importing from Google

When importing users & groups from Google, you will face the below error on the first-time you try to authenticate:

<figure><img src="/files/15fOqnEyumqk3z4vJWqR" alt="" width="375"><figcaption></figcaption></figure>

The reason is that certain sensitive permissions are required for the import:

| Sensitivity                      | Scopes                                                                                                                                                                                                                                                                  | Why Dope Requires This                                                                                                                                                      |
| -------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Non‑sensitive** (OIDC Auth)    | `openid` `https://www.googleapis.com/auth/userinfo.profile` `https://www.googleapis.com/auth/userinfo.email`                                                                                                                                                            | Returns the user’s ID‑token + profile + primary email for identification                                                                                                    |
| **Sensitive** (User/Group Synch) | `https://www.googleapis.com/auth/admin.directory.user.readonly` `https://www.googleapis.com/auth/admin.directory.group.readonly` `https://www.googleapis.com/auth/admin.directory.group.member.readonly` `https://www.googleapis.com/auth/admin.reports.audit.readonly` | Read‑only access to users, groups, group memberships, and Admin SDK audit logs to perform regular User/Group synchronization, and process delta for groups every 15 minutes |

## To resolve this:

1. Login to [Google Admin Sconsole](https://admin.google.com/u/0/ac/owl/list?tab=configuredApps\&hl=en) as an Administrator. Navigate to Security -> Access and Data Control -> API controls, and select **MANAGE THIRD-PARTY APP ACCESS**

![API Security Controls are managed here](/files/wQtBN7uxOEakukteAbjI)

2. Select Configure new app\ <br>

   <figure><img src="/files/kN28dj9j2wLBSWLzbbSC" alt=""><figcaption></figcaption></figure>
3. Search for dope.security's Client ID

`478881077855-4cs12s5t8lae8vsh43svpsahneb1fgu2.apps.googleusercontent.com`

<figure><img src="/files/5YA6z9oOJMNBI80q7Jgd" alt=""><figcaption></figcaption></figure>

3. Click the “Dope Security” app and Configure the App access to **Trusted**<br>

   <figure><img src="/files/J7oFXg9bHJiBKP1XNxoE" alt=""><figcaption><p>Mark app as Trusted</p></figcaption></figure>
4. Once configured, you will see the app listed as Trusted in the third-party app list.

![](/files/gU44RY2wJze6UV957Z9x)


# Why not SAML & SCIM?

One of our values is to get you up and running in a few minutes, but that can easily stretch to weeks if you start using certain capabilities, such as SAML or SCIM or even allowing non Google/365 logins to the console.

{% hint style="success" %}
Ultimately, our goal is to give you high level of security controls (SSO, Endpoint Auth, Group Policies) with zero hassles & just a couple of clicks. That's why we chose a different integration (OIDC and 365/Google APIs) rather than SAML and SCIM
{% endhint %}

There are three main areas this improves on:

1. **Admin Login & Sign-Up Process**: our authentication removes the need for any password resets, SSO integrations, or MFA integrations by instantly SSO with your existing IDP
2. **Endpoint Authentication**: removes any complex endpoint auth testing, SAML configurations, and certificate rotations - no IAM team required to configure
3. **User & Group Policies**: removes any user attribute mapping, complex SCIM configuration, and there's no IAM team required to configure

### Admin Logins

<figure><img src="/files/lD2gVSlDUjjGxfIiFQuW" alt="" width="360"><figcaption><p>Logins are only possible at dope.security with a 365 or Google Workspace</p></figcaption></figure>

To achieve the goal of an **Instant SSO** admin login, we have required all admins to use their 365 or Google account to authenticate. From there, the authentication will jump to whatever Identity Provider you have configured.

For example, if you were using Okta:

```
Okta <======SAML======> Microsoft 365 / Google Workspace <======OIDC======> Dope
```

The beauty of this mechanism is that you can even add a managed service provider, or other admin, and dope.security will automatically facilitate the SSO for that admin as well. This can range from Okta, Onelogin, Azure AD/Entra ID, and more!

{% hint style="info" %}
If you are using special accounts for admins, such as <admin-js@voyager.com>, add that instead. This will allow you to inherit the security policy automatically when that account authenticates.
{% endhint %}

### Endpoint Authentication

Traditionally, this has been a hodgepodge of authentication options to get the user ID on the device they are using: Active Directory, LDAP, SAML, NTLM, etc. The most-used standard today is SAML for performing the authentication.

However, integrating a POC environment into your IAM/SSO tool via SAML is not so straightforward. There are a lot of fields that need to be correctly aligned, you'll need to re-test at least a few times to make sure that there are no issues, coordinate with the actual IAM team to do all of this, and above all, you'll need to re-coordinate to rotate the SAML certificate eventually. Else, people will have no Internet if they're installing for the first time.

By using the same method of OIDC to 365/Google, we removed all of this complexity and replaced it with a checkbox:

<figure><img src="/files/WPgVq73VetMYbM8DQm7a" alt="" width="375"><figcaption><p>One-checkbox, hit save, and you are SSO!</p></figcaption></figure>

Yes, your Okta/Azure AD/etc. will work perfectly. By using the native browser, we have even allowed you to use any MFA mechanism that your device supports, ranging from YubiKeys (FIDO U2F), to Bluetooth U2F, etc.

### User & Group Policies

Last, but not least, is actually applying policies to particular user & group combinations and creating category exceptions for particular users & groups.

<figure><img src="/files/gMmOYhh4Bfe5vfNMVUIE" alt="" width="375"><figcaption><p>How did we make it so easy to do this?</p></figcaption></figure>

Given that Google or 365 is a prerequisite to use dope, we can instantly import the Users/Groups from those services using the APIs they expose (after you've authorized this, of course). It ends up being a few clicks from your Google/365 admin, and we will automatically synchronize the User/Group data every 15 minutes.\
\
We have customers from 100 users to 400,000 using this process today - many of them also use Okta or Azure AD or other IAM solutions to manage their User Groups. By leveraging this mechanism, your group changes will synch from IAM -> 365/Google -> DS very quickly.

{% hint style="info" %}
It's very common for groups & users to be managed from within an HR or IAM software, and we have tested this with many configurations where it automatically flows through to 365/Google (due to previous config) and dope is able to pick it up from there.
{% endhint %}

### FAQs

1. What do I tell my compliance team about this?\
   Compliance can be told that dope supports single sign on by default, and provides automatic de-authorization for any admins who are no longer with the company
2. What if I want an Okta tile or Azure AD button for the dope console?\
   You can configure either app to be redirected to **<https://fly.dope.security>**
3. What do I tell my compliance team if they say dope needs to be integrated with the SSO tool?\
   You can tell them that it is automatically integrated with SSO via 365 and Google. There is no additional configuration required.


# Audit Log

If you need to see what has been happening within dope.swg console, then go to the Audit Log. The Audit Log works as a log of actions that have occurred within an account over the last 30 days.

To view the Audit Log go to Settings -> Audit Log

<figure><img src="/files/C9Iv1B48vFw6Pvrc9JIU" alt=""><figcaption></figcaption></figure>

## Audit Log Actions

The Audit Log will report on the following dope.swg console events

**Settings**

<details>

<summary>Admin Management</summary>

* New Admins
* Admin Removal
* Logins
* Logout

</details>

<details>

<summary>User/Group Updates</summary>

* Initial import — No. of users/groups added/removed
* Delta import — No. of users/groups added/removed
* Errors — update user/group fails e.g. authorization failure

</details>

<details>

<summary>Endpoint Configuration</summary>

* Anti-uninstall password configured/changed
* Fail closed ON/OFF

</details>

<details>

<summary>OIDC Configuration</summary>

* OIDC Configuration enabled/disabled
* Config update i.e. domains edited

</details>

<details>

<summary>Block Pages Updates</summary>

* New custom page added/deleted/changed

</details>

<details>

<summary>Security Information and Event Management (SIEM) Integration</summary>

* SIEM Integration enabled/disabled

</details>

<details>

<summary>Policy</summary>

* Policy created/deleted/updated

</details>

**Cloud App Control (CAC) Policy Updates**

**Application and Domain Bypass Updates**

<details>

<summary>Policy Assignments</summary>

* User/group assigned to a policy
* Policy Clashes i.e. a user(s) associated with two groups assigned to different policies

</details>

<details>

<summary><strong>Endpoint Manager</strong></summary>

* New endpoint registered with the dope.cloud
* Endpoint uninstalled
* Dormant endpoint deleted after 35 days
* Admin enabled endpoint to Debug Mode
* Admin disabled endpoint from Debug Mode

</details>

<details>

<summary><strong>Analytics</strong></summary>

* Export to CSV

</details>

## **Audit Log Format**

As well as recording the action, the log will record the admin responsible for the action and the timestamp for the action.

![Audit Log Example](/files/e4fq2uyLvTVke9Pn9LXH)

{% hint style="info" %}
Automatic actions are assigned to the user dope.cloud<img src="/files/2NL1kr0eIppdCjJPrd6y" alt="" data-size="original">
{% endhint %}

## Audit Log Search

### Search by action

You have the option of searching by email or by specific action. When selecting the search icon, different groups of actions will appear as a dropdown.

<figure><img src="/files/nNIPtgDPr9U4PBvtHqhI" alt=""><figcaption></figcaption></figure>

Select the type of Audit group action to search. On selection, a deeper breakdown of actions will be presented specific to the group.

For example, selecting the group Policy will result in the following Audit Log Actions to be presented:

<figure><img src="/files/5yoRetcLWLMnWflEKLF6" alt="" width="375"><figcaption></figcaption></figure>

Selecting the Action from the list will filter the Audit Log to show only these actions.

### Search by time

On the left-hand side of the Audit Log, there’s a date widget showing the last 30 days.

<figure><img src="/files/IYaagJ4X9jtIwaKQeA5V" alt=""><figcaption></figcaption></figure>

Selecting a specific date will scroll the Audit Log’s position to that date, providing an easy way to jump to a date where an action of interest may have happened.


# SIEM Integration

It is possible to integrate your dope.swg with whichever SIEM tool your organization is using. We provide two methods for integration using an AWS S3 bucket or HTTP Integration.

## Method 1. AWS S3 Integration

Simply provide dope.security with the location of your organization's AWS S3 Bucket where we can send all web transactions from each dope. endpoint.

Each dope.endpoint sends all web transactions for that endpoint to the dope.cloud every 15 mins. Once SIEM Integration is enabled the dope.cloud will ensure all of this log data is sent to your organization's AWS S3 bucket as it is received from the dope.endpoint.

The data is sent to the AWS S3 Bucket in a compressed GZIP format. This data can then be ingested into whichever SIEM product your organization is using.

### S3 Bucket Name

The first step to configure SIEM integration is to navigate to the Settings ➔ SIEM page. From here, you must provide the name of the AWS S3 Bucket to which you want the dope.cloud to send the log data.

<figure><img src="/files/eLlfhFOBzMRI7S52S60B" alt=""><figcaption><p>Ensure your S3 bucket is in the location shown on the right-hand side (<em>US-EAST-2</em> in this example)</p></figcaption></figure>

{% hint style="danger" %}
Your AWS S3 Bucket must be in the AWS region noted on the right-hand side of the SIEM integration page on the right-hand side (above).

e.g. *US-EAST-2* should have a *US-EAST-2* S3 Bucket location
{% endhint %}

{% hint style="danger" %}
Your AWS S3 Bucket should not have KMS encryption enabled (unsupported at this time)
{% endhint %}

### Configuring the AWS S3 Bucket Policy

The AWS S3 bucket that you want to log data to be sent to must be configured to give the dope.cloud write access.

Within the SIEM integration page on the right-hand panel, dope.security has provided the policy that the AWS S3 Bucket needs to be configured with. You need to copy and paste this policy and use it to configure the organization’s AWS S3 Bucket.

<figure><img src="/files/gJKYO3h4HQnqdA83Hwre" alt="" width="375"><figcaption></figcaption></figure>

### Synchronise

Once the AWS S3 Bucket is configured correctly return to the Settings ➔ SIEM Page and simply click the Sync Button <img src="/files/clj8bINb0WICC0jCMUAQ" alt="" data-size="line">

When everything has been configured correctly a successful synchronization will be clearly indicated on the SIEM page.

A green tick will appear next to the AWS S3 Bucket name and the last synchronization time will appear on the top right of the page.

![Successful Synchronization](/files/hvBnLDWmfsX4x3IyxICC)

{% hint style="danger" %}

#### Synchronization Errors

Where the synchronization fails it will be because of one of the following errors:

* AWS S3 bucket not found
* AWS S3 Bucket needs to be in Data Residency Region
* AWS S3 access policy is not set
* AWS S3 access policy is incorrect.

The synchronization failure will be clearly indicated on the SIEM page.
{% endhint %}

{% hint style="warning" %}

#### Connection Lost

It is possible that the connection to the AWS S3 Bucket could get lost. This will result in log data not getting sent to the organization’s AWS S3 Bucket. The reasons for a lost connection be because of one of the following errors:

* AWS S3 bucket not found
* AWS S3 Bucket needs to be in Data Residency Region
* AWS S3 access policy is not set
* AWS S3 access policy is incorrect.

The SIEM Integration page will clearly indicate that the connection is lost and will indicate the possible reasons.
{% endhint %}

![SIEM Page Lost Connection](/files/62KRYfftVCI0EixRrMHJ)

The Audit Log will have an event posted that shows the number of files that have not been sent to the organization's AWS S3 Bucket.

When connection to the AWS S3 Bucket is restored then the SIEM page will again indicate that the synchronization was successful. There will also be a connection returned event added to the Audit Log.

### Log Data Format

The data is sent in JSONL format below you can find the JSON Schema and an example JSONL file.

{% file src="/files/AFM2Znn9NcjRgs41vXEW" %}
Schema File
{% endfile %}

{% file src="/files/KwIiTJNKpBI9ClVlc8CG" %}
SIEM JSONL Example
{% endfile %}

Below is a description of each parameter in the JSONL file:

<table><thead><tr><th width="253">Parameter</th><th>Description</th></tr></thead><tbody><tr><td>Timestamp (ISO 8601 time format)</td><td>The timestamp of when the web transaction was requested</td></tr><tr><td>Duration</td><td>The duration that the connection was open for, this is in milliseconds</td></tr><tr><td>Matched Destination</td><td>The domain that the dope category was matched against</td></tr><tr><td>Destination IP</td><td>The destination IP address for the requested URL</td></tr><tr><td>Tenant ID</td><td>The customers dope.cloud unique tenant ID</td></tr><tr><td>Agent ID</td><td>The unique agent ID for the dope.endpoint where the data is being sent from</td></tr><tr><td>User</td><td>The logged in user on the dope.endpoint</td></tr><tr><td>OIDC User</td><td>The email address for the authenicated user on the dope.endpoint. Only shown when OIDC authentication is enabled</td></tr><tr><td>Categories</td><td>The matched <a href="/pages/1bPsotUkYMjgcbNuqTVr">dope category numbers</a> for the requested URL</td></tr><tr><td>Verdict</td><td>The policy verdict for the requested URL. This can be Allow (0), Block (1), Warning (2) or Bypass (3) where the URL is part of a policies bypass list.</td></tr><tr><td>Data Sent</td><td>The amount of data sent in the connection</td></tr><tr><td>Data Received</td><td>The amount of data received in the connection</td></tr><tr><td>Policy Type</td><td>The type of policy that was applied to the URL.This can be either Web, Cloud Application Control (CAC), Custom Category, Bypass or Malware.</td></tr><tr><td>Block Detail</td><td>Populated for a block verdict. It will be either a dope category, a custom category, Cloud Application or a malware type.</td></tr><tr><td>Filename</td><td>The name any file downloaded.</td></tr><tr><td>File Hash</td><td>The file hash for the downloaded file</td></tr><tr><td>Process Name</td><td>The name of the process making the URL request.</td></tr><tr><td>URL</td><td>The complete requested URL</td></tr><tr><td>Policy Name</td><td>The name of the policy applied</td></tr><tr><td>Protocol</td><td>Protocol used, e.g.: HTTP/2, HTTP/1.1</td></tr><tr><td>Hostname</td><td>Device hostname</td></tr><tr><td>HTTP Request Method</td><td>HTTP Request Method e.g. Put</td></tr><tr><td>Process Call Tree</td><td>Shows the parent-child relationships established via process spawn operations, also includes the command arguments</td></tr></tbody></table>

## Method 2. Configuring the HTTP Integration

Currently DOPE HTTP Integration supports the following SIEM tools:

* Splunk
* QRadar
* Taegis
* MS Sentinel
* Crowdstrike

### Splunk

To configure Splunk, you must have the HTTP Event Collector (HEC) URI and the token. The steps to obtain these can be found in [**Splunk's Enterprise Documentation: Set up and use HTTP Event Collector in Splunk Web**](https://docs.splunk.com/Documentation/Splunk/latest/Data/UsetheHTTPEventCollector).

In the dope.console, navigate to Settings ➔ SIEM ➔ SIEM Integration Settings ➔ HTTP. From here select "Splunk" as the SIEM type and update the HEC URI and the HEC token in the following SIEM HTTP settings page of the dope.console and sync.

<figure><img src="/files/aFvCVjafpTwoYi3YU2PD" alt=""><figcaption></figcaption></figure>

In order to confirm that the sync is successful, you should see a couple of sample records in your SIEM as a validation test.

### QRadar

To configure Taegis, you must have the Taegis integration URL and the integration key. The steps to obtain these can be found in [**IBM's QRadar Security Intelligence Platform Documentation: HTTP Receiver protocol configuration options**](https://www.ibm.com/docs/en/dsm?topic=options-http-receiver-protocol-configuration).

In the dope.console navigate to Settings ➔ SIEM ➔ SIEM Integration Settings ➔ HTTP. From here select “QRadar” as the SIEM type and update the integration URL and the integration key and sync.

<figure><img src="/files/0nYQFO6KfdQeJ4AP0XaE" alt=""><figcaption></figcaption></figure>

In order to confirm that the sync is successful, you should see a couple of sample records in your SIEM as a validation test.

### Taegis

To configure Taegis, you must have the Taegis integration URL and the integration key. The steps to obtain these can be found in [**Securework's Documentation: Configure HTTP Ingest**](https://docs.taegis.secureworks.com/integration/connectCloud/http_ingest/).

In the dope.console navigate to Settings ➔ SIEM ➔ SIEM Integration Settings ➔ HTTP. From here select “Taegis” as the SIEM type and update the integration URL and the integration key and sync.

<figure><img src="/files/lCzMpAPa61Y1zZf6lkGq" alt=""><figcaption></figcaption></figure>

In order to confirm that the sync is successful, you should see a couple of sample records in your SIEM as a validation test.

### MS Sentinel

To integrate with Microsoft Sentinel using HTTP, you'll need to utilize the Azure Monitor Logs Ingestion API. The steps to configure this can be found in [**Azure Monitor's Documentation: Logs Ingestion API in Azure Monitor**](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/logs-ingestion-api-overview)

#### **Azure Prerequisites:**

> 1. Register a **Microsoft Entra application** → copy **Tenant ID**, **Client ID**, and generate a **Client Secret**.
> 2. Create or select a **Log Analytics workspace**.
> 3. Add a **Custom table** called `DopeSwg_CL`; keep the default “Custom-DopeSwg” stream name.
> 4. Create a **Data-Collection Endpoint (DCE)** in the same region.
> 5. Create a **Data-Collection Rule (DCR)** that routes the `Custom-DopeSwg_CL` stream to your workspace. Record the **DCR immutable ID**.
> 6. Open the DCR → **Access control (IAM)** → add the Entra app to the **Monitoring Metrics Publisher** role (scope = this DCR)

{% hint style="success" %}
Ensure that your Entra App has the Monitoring Metrics Publisher Role
{% endhint %}

#### **Configure dope.console:**

In the dope.console navigate to Settings ➔ SIEM ➔ SIEM Integration Settings ➔ HTTP.

<figure><img src="/files/fbJVR6F9uuL2ng9RgKB4" alt=""><figcaption><p>Select “MS Sentinel” as the SIEM type</p></figcaption></figure>

Confirm the sync is successful when you see two sample validation records in your SIEM

### Crowdstrike

To configure Crowdstrike, you must create a HEC Connector within your Crowdstrike console. First login to your Crowdstrike console and go to Data Onboarding. Then add a HEC Connector and add the dopesecurity-swg parser. Once this is saved you will be provided with an API key and an API URL, copy these so you can add them to the SIEM configuration in the dope console.

In the dope.console, navigate to Settings ➔ SIEM ➔ SIEM Integration Settings ➔ HTTP. From here select "Crowdstrike" as the SIEM type and update the API Token and the API URL token in the following SIEM HTTP settings page and sync.

<figure><img src="/files/5J5imxdLzP8BLY89hJO2" alt=""><figcaption></figcaption></figure>

In order to confirm that the sync is successful, you should see a couple of sample records in your SIEM as a validation test.

### Datadog

To configure Datadog, you must have the Datadog API URL andAPI key. The steps to obtain these can be found in the user profile page here [https://app.datadoghq.com](https://app.datadoghq.com/).

Once you have these in the dope.console navigate to Settings ➔ SIEM ➔ SIEM Integration Settings ➔ HTTP. From here select “Datadog” as the SIEM type and update the API URL and the API Key and then select sync.

<figure><img src="/files/kqxljFn75kG8i9Ljeknq" alt=""><figcaption></figcaption></figure>


# Category & Verdict Mappings

{% hint style="info" %}
Verdicts can be either Allow (0), Block (1), Warning (2) or Bypass (3)
{% endhint %}

<table data-full-width="false"><thead><tr><th width="96">Cat #</th><th width="280">Category Name</th><th>Grouping</th><th data-hidden>Default Verdict</th></tr></thead><tbody><tr><td>0</td><td>Unknown</td><td>Unknown</td><td>0</td></tr><tr><td>1</td><td>Abortion</td><td>Abortion</td><td>0</td></tr><tr><td>2</td><td>Ads/Analytics</td><td>IT</td><td>0</td></tr><tr><td>3</td><td>Adult/Mature</td><td>Adult Material</td><td>1</td></tr><tr><td>4</td><td>Alcohol</td><td>Society and Lifestyle</td><td>0</td></tr><tr><td>5</td><td>Arts/Culture</td><td>Society and Lifestyle</td><td>0</td></tr><tr><td>6</td><td>Auctions/Classifieds</td><td>Shopping</td><td>0</td></tr><tr><td>7</td><td>Music/Audio</td><td>Entertainment</td><td>0</td></tr><tr><td>8</td><td>Brokerage/Trading</td><td>Business</td><td>0</td></tr><tr><td>9</td><td>Business/Economy</td><td>Business</td><td>0</td></tr><tr><td>10</td><td>Chat/Messaging</td><td>Internet Communication</td><td>0</td></tr><tr><td>11</td><td>Child Pornography/Abuse</td><td>Illegal</td><td>1</td></tr><tr><td>12</td><td>CDN/Content Servers</td><td>IT</td><td>0</td></tr><tr><td>13</td><td>Dating</td><td>Society and Lifestyle</td><td>0</td></tr><tr><td>14</td><td>Digital Postcards</td><td>Society and Lifestyle</td><td>0</td></tr><tr><td>15</td><td>Controlled Substances</td><td>Drugs</td><td>0</td></tr><tr><td>16</td><td>Education</td><td>Education</td><td>0</td></tr><tr><td>17</td><td>Email</td><td>Internet Communication</td><td>0</td></tr><tr><td>18</td><td>General Entertainment</td><td>Entertainment</td><td>0</td></tr><tr><td>19</td><td>Extreme/Gruesome</td><td>Extreme/Gruesome</td><td>0</td></tr><tr><td>20</td><td>File Storage</td><td>Business</td><td>0</td></tr><tr><td>21</td><td>Finance</td><td>Business</td><td>0</td></tr><tr><td>22</td><td>For Kids</td><td>Society and Lifestyle</td><td>0</td></tr><tr><td>23</td><td>Forums</td><td>Internet Communication</td><td>0</td></tr><tr><td>24</td><td>Gambling</td><td>Gambling</td><td>0</td></tr><tr><td>25</td><td>Games</td><td>Games</td><td>0</td></tr><tr><td>26</td><td>Government/Legal</td><td>Government/Legal</td><td>0</td></tr><tr><td>27</td><td>Hacking Tools</td><td>Hacking Tools</td><td>0</td></tr><tr><td>28</td><td>Hate/Discrimination</td><td>Hate/Discrimination</td><td>0</td></tr><tr><td>29</td><td>Health</td><td>Health</td><td>0</td></tr><tr><td>30</td><td>Hobbies/Recreation</td><td>Society and Lifestyle</td><td>0</td></tr><tr><td>31</td><td>Hosting</td><td>IT</td><td>0</td></tr><tr><td>32</td><td>Humor/Comics</td><td>Entertainment</td><td>0</td></tr><tr><td>33</td><td>Alternative Ideology</td><td>Religion</td><td>0</td></tr><tr><td>34</td><td>Information Technology</td><td>IT</td><td>0</td></tr><tr><td>35</td><td>Cybersecurity Technology</td><td>IT</td><td>0</td></tr><tr><td>36</td><td>Infrastructure/IOT</td><td>IT</td><td>0</td></tr><tr><td>37</td><td>Job Search</td><td>Job Search</td><td>0</td></tr><tr><td>38</td><td>Lingerie/Swimsuit</td><td>Adult Material</td><td>1</td></tr><tr><td>39</td><td>Malicious</td><td>Security</td><td>1</td></tr><tr><td>40</td><td>Marijuana</td><td>Drugs</td><td>0</td></tr><tr><td>41</td><td>Marketing/Merchandising</td><td>Business</td><td>0</td></tr><tr><td>42</td><td>Media Sharing</td><td>Entertainment</td><td>0</td></tr><tr><td>43</td><td>Military</td><td>Government/Legal</td><td>0</td></tr><tr><td>44</td><td>Mixed Content</td><td>Entertainment</td><td>0</td></tr><tr><td>45</td><td>News</td><td>News</td><td>0</td></tr><tr><td>46</td><td>Non-Profit/Advocacy</td><td>Non-Profit/Advocacy</td><td>0</td></tr><tr><td>47</td><td>Nudity</td><td>Adult Material</td><td>1</td></tr><tr><td>48</td><td>Parked Site</td><td>Parked Site</td><td>0</td></tr><tr><td>49</td><td>Torrents/P2P</td><td>Illegal</td><td>1</td></tr><tr><td>50</td><td>Personal Sites/Blogs</td><td>Society and Lifestyle</td><td>0</td></tr><tr><td>51</td><td>Phishing</td><td>Security</td><td>1</td></tr><tr><td>52</td><td>Piracy/Plagiarism</td><td>Illegal</td><td>1</td></tr><tr><td>53</td><td>Politics/Opinion</td><td>Government/Legal</td><td>0</td></tr><tr><td>54</td><td>Pornography</td><td>Adult Material</td><td>1</td></tr><tr><td>55</td><td>Potentially Unwanted Applications</td><td>Security</td><td>1</td></tr><tr><td>56</td><td>Productivity Applications</td><td>Business</td><td>0</td></tr><tr><td>57</td><td>Proxy Avoidance</td><td>Security</td><td>1</td></tr><tr><td>58</td><td>Real Estate</td><td>Society and Lifestyle</td><td>0</td></tr><tr><td>59</td><td>Reference/Encylopedia</td><td>Society and Lifestyle</td><td>0</td></tr><tr><td>60</td><td>Major Religions</td><td>Religion</td><td>0</td></tr><tr><td>61</td><td>Remote Desktop</td><td>IT</td><td>0</td></tr><tr><td>62</td><td>Restaurants/Food</td><td>Society and Lifestyle</td><td>0</td></tr><tr><td>63</td><td>Scam/Illegal/Unethical</td><td>Illegal</td><td>1</td></tr><tr><td>64</td><td>Search Engines</td><td>IT</td><td>0</td></tr><tr><td>65</td><td>Sex Education</td><td>Adult Material</td><td>1</td></tr><tr><td>66</td><td>Stores</td><td>Shopping</td><td>0</td></tr><tr><td>67</td><td>Social Media</td><td>Society and Lifestyle</td><td>0</td></tr><tr><td>68</td><td>Personal Lifestyle</td><td>Society and Lifestyle</td><td>0</td></tr><tr><td>69</td><td>Software Downloads</td><td>IT</td><td>0</td></tr><tr><td>70</td><td>Spam</td><td>Security</td><td>1</td></tr><tr><td>71</td><td>Sports</td><td>Sports</td><td>0</td></tr><tr><td>72</td><td>Suspicious</td><td>Security</td><td>1</td></tr><tr><td>73</td><td>VOIP/Telephone</td><td>Internet Communication</td><td>0</td></tr><tr><td>74</td><td>Tobacco</td><td>Society and Lifestyle</td><td>0</td></tr><tr><td>75</td><td>Translation</td><td>IT</td><td>0</td></tr><tr><td>76</td><td>Travel</td><td>Travel</td><td>0</td></tr><tr><td>77</td><td>URL Redirect</td><td>IT</td><td>0</td></tr><tr><td>78</td><td>Vehicles</td><td>Vehicles</td><td>0</td></tr><tr><td>79</td><td>Video Streaming</td><td>Entertainment</td><td>0</td></tr><tr><td>80</td><td>Violence</td><td>Violence</td><td>0</td></tr><tr><td>81</td><td>Video Conferencing</td><td>Internet Communication</td><td>0</td></tr><tr><td>82</td><td>Weapons</td><td>Weapons</td><td>0</td></tr><tr><td>83</td><td>AI/ML Applications</td><td>AI/ML Applications</td><td></td></tr><tr><td>84</td><td>Alternative Currency</td><td>Business</td><td></td></tr><tr><td>85</td><td>Dynamic DNS</td><td>IT</td><td></td></tr><tr><td>86</td><td>Login/Challenge</td><td>IT</td><td></td></tr><tr><td>87</td><td>Newly Registered</td><td>Newly Registered</td><td></td></tr><tr><td>88</td><td>Promotional Compensation</td><td>Security</td><td></td></tr></tbody></table>


# API Client Credentials

The dope.swg offers Public APIs to allow our customers automate specific tasks.

For more information on the Public APIs we have available and how to use them please see [Broken mention](broken://pages/Fv4IZGn86IncLNyfYRFg)

## Generating Client Credentials

In order to be able to access the dope.SWG APIs a client credential token will need to be generated. When using the APIs this token is exchanged to get an access token. This access token can then be used to access the dope.SWG APIs.

To generate a token select the <img src="/files/tv2NaMthpph9EP0yITKB" alt="" data-size="line"> button on the right hand panel.

<figure><img src="/files/jqph678QqQj9P8EHpQQy" alt=""><figcaption><p>Generate Client Credentials</p></figcaption></figure>

You will then be prompted to provide a name for the token in the right hand panel.

<figure><img src="/files/5C4hSBhUdZXLgzJYT9v5" alt="" width="509"><figcaption><p>Provide Token Name</p></figcaption></figure>

Once you have provided a name for the Token it will get added to the table. Here you will see the following information, Token Name, Client ID, Created By and Created On.

You will also see the Token Secret. This must be copied immediately as for security reasons it will not be shown again.

<figure><img src="/files/ZTQIP4qA2AjcBfh9TrT4" alt=""><figcaption><p>New Token Added to Table</p></figcaption></figure>

{% hint style="info" %}
You can select the Copy icon or the string of text to copy the secret.
{% endhint %}

If required, it is possible to create multiple tokens following the same process.

## Revoking Client Credentials

### Revoke a single credential

To revoke a single credential select the ellipsis at the right hand side of the credentials table, and then select Revoke.

<figure><img src="/files/tpOIIRA5bP8PeqRMbs26" alt=""><figcaption><p>Revoke a single credential</p></figcaption></figure>

After selecting Revoke you will need to confirm the action when presented with the following dialog.

<figure><img src="/files/iWgIanpR59tuBlQao3MU" alt="" width="509"><figcaption><p>Revoke Single Confirmation Dialog</p></figcaption></figure>

### Revoke all credentials

To revoke all of the created credentials then select the <img src="/files/sOSBSdwSvToum15S3Rm1" alt="" data-size="line"> button on the right hand panel.

Then, confirm you want to revoke all credentials when presented with the following dialog.

<figure><img src="/files/WnrWiI1vuzK95Qinw4kx" alt="" width="509"><figcaption><p>Revoke All Confirmation Dialog</p></figcaption></figure>


# Billing Details

## Purchasing the Product

When a customer is trialing dope.swg but wants to purchase the product then all the required details to complete the purchase are available in Settings -> Billing.

### Purchase Directly

Where a customer wishes to purchase the product directly from dope.security, they need to contact us directly by emailing <sales@dope.security>.

![](/files/tGe2LWY4YUFieelH6b38)

For more details see [our website](https://dope.security/pricing).

### Purchase through a partner

Where a customer wishes to purchase the product through a partner, then they need to provide the partner with their dope.security Tenant ID.

The Tenant ID is provided in the Billing Page, it can be copied by selecting the copy icon next to the ID <img src="/files/cVDgEB9vHbJ8sMVu5UbM" alt="" data-size="line">.

![](/files/i3pTk2SLFNfYj27zhy7m)

There is also a link to a list of Preferred Partners (Coming Soon).

## Subscription Details

Customer subscription details can also be viewed from the billing page. These details include:

* Subscription Type i.e. Trial/Paid/NFR
* Number of Purchased Devices
* Number of Active Devices
* Renewal Date
* Number of Days Remaining

![](/files/Tpn1YDyh5VmT7J0oCvjG)

{% hint style="info" %}
Number of purchased and active devices will not be displayed for Trial Customers
{% endhint %}


# Notifications

The dope.console provides a notification service that informs admins of any actions they may need to take or any recent activities that may be of interest.

The notification icon can be seen in the top right-hand corner of the Admin Console.

<figure><img src="/files/fFhc6B83gA1mP7X1tjec" alt="" width="188"><figcaption></figcaption></figure>

When there’s a new notification for an admin to view, the icon will update to the following <img src="/files/grgFow1PzpopkkLGK2J4" alt="" data-size="line">.

Selecting the icon will open the notification panel which will display a list of the latest notifications from the dope.console.

The following sections describe the different types of notifications that can display.


# SSL Errors

**SSL inspection can sometimes cause issues and break some applications that rely on SSL encryption to function correctly. There can be different underlying reasons for breaking applications, which include certificate validation issues, hard-coded IP addresses and domains, and application-specific SSL configurations.**

Unlike other products dope.swg does not expect admins to work out what needs to be bypassed from inspection to get an application to work. At dope.security we have implemented a SSL error reporting feature. With this feature the dope.endpoint detects any application and URL that is breaking on the device. It then reports this to the dope.cloud where the admin can add the required application or URL to the bypass list with a single click.

## How does it work?

When an SSL error happens on a dope.endpoint then the endpoint will send the combination of the application and the URL affected by the error. This can then be seen as a new notification in the notification view. When there’s a new SSL error notification for an admin to view the notification will be updated to the following icon <img src="/files/grgFow1PzpopkkLGK2J4" alt="" data-size="line">.

Once the admin selects the notification icon they will get to see the notification view with the errors split into “By App” and “By Url.” This allows the admin to decide how he wants to fix the SSL problem. It is possible to bypass the entire application which means all traffic from the application would be bypassed. Or if the admin does not want to bypass the entire application they can bypass based on URL.

## By App View

Selecting the “By App” view shows a list of applications that have reported SSL errors. As well as listing the applications, it's also possible to see the URLs associated with the application’s SSL error. This visibility will help the admin decide if they should add the application or the URL(s) to the bypass list.

<figure><img src="/files/w3LfLNDJ99eI2fsRFX68" alt="" width="375"><figcaption><p>SSL Errors 'By App'</p></figcaption></figure>

{% hint style="info" %}
By hovering over the user icon it is possible to see which users have reported the issue.
{% endhint %}

### Bypassing an Application

To bypass an application, all an admin must do is select one or many applications using the checkbox.

Once an application selection is made, a button to add the application to all bypass lists will appear.

<figure><img src="/files/WNCUPDx635ZTnWxfEr7G" alt="" width="375"><figcaption><p>Bypass Application Action</p></figcaption></figure>

Selecting the “Bypass for all policies” button will add the checked application(s) to all policies in your dope.swg tenant.

Once an application is added to the Bypass list, it will no longer be seen in the notifications view unless it is removed from the Bypass list.

{% hint style="info" %}
Admins can only bypass applications from this view. They cannot bypass URLs.
{% endhint %}

## By URL View

Selecting the “By URL” view shows a list of each URL that has reported SSL errors. As well as displaying each URL, the view groups the URLs by Top Level Domain (TLD). This parent grouping allows the admin to bypass the TLD instead of each URL individually.

<figure><img src="/files/3THlytHIdb360blEV2gK" alt="" width="375"><figcaption><p>SSL Errors 'By URL'</p></figcaption></figure>

### Bypassing a URL

To bypass a TLD or an individual URL, an admin only needs to select either the TLD or the individual URL.

Once the admin makes their selection, a button to add the TLD or URL to all bypass lists will appear.

<figure><img src="/files/vzpfaG7l42VjKN55QZZI" alt="" width="375"><figcaption><p>Bypass URL Action</p></figcaption></figure>

Selecting the “Bypass for all policies” button will add the checked TLD or URL to all policies in your dope.swg tenant.

Once a URL is added to the Bypass list, it will no longer be seen in the notifications view unless it is removed from the Bypass list.

{% hint style="info" %}
Selecting the (parent) TLD will result in all its children URLs getting selected, however, only the TLD will be added to the Bypass list.
{% endhint %}

## Quick Decision Guide: App Bypass or URL Bypass?

If you are deciding how to resolve an SSL issue quickly:

* Choose **By URL** when only specific domains should bypass SSL inspection.
* Choose **By App** when the entire process/application should bypass policy inspection.

{% hint style="warning" %}
An **Allow** rule is not the same as bypass. Allowed traffic can still be inspected.\
If cert errors persist after an Allow rule, add a bypass entry instead.
{% endhint %}

{% hint style="info" %}
After adding a bypass entry, always **Save Policy** and ask users to relaunch the affected app.
{% endhint %}

{% hint style="info" %}
If an admin chooses not to act on a URL or an application, then its alert will remain in the notifications view for 14 days. After this time, they will be removed and not shown again.
{% endhint %}


# Trusted Process Names

To prevent false positives caused by EDR/EPP vendors running alongside dope.security, you can add the following process names to your list of trusted application processes:

\
**Mac:**\
`security.dope.DopeSecurityApp.Redirector`

`/Applications/DopeSecurityApp.app/Contents/MacOS/DopeSecurityApp`

`/Applications/DopeSecurityApp.app/Contents/Applications/ProxyAgent.app/Contents/MacOS/ProxyAgent`

`/Applications/DopeSecurityApp.app/Contents/Applications/DopeMonitorService.app/Contents/MacOS/DopeMonitorService`

`/Applications/DopeSecurityApp.app/Contents/Applications/DopeTools.app/Contents/MacOS/DopeTools`

`/Applications/DopeSecurityApp.app/Contents/Library/bin/Upgrader`

\
\
**Windows:**\
`C:\Windows\system32\drivers\DopeRedirector.sys`

`C:\Program Files\dope.security\agent.exe`

`C:\Program Files\dope.security\DopeMonitorService.exe`

`C:\Program Files\dope.security\DopeSecurityUI.exe`

`C:\Program Files\dope.security\DopeTools.exe`

`C:\Program Files\dope.security\Upgrader.exe`

`C:\ProgramData\dope.security\dope.security\extracted\dope_upgrade_service_restart.ps1`


# Generate Diagnostics

### Diagnostics can be requested on dope.cloud, but you can also generate diagnostics from the endpoint itself.

Select **Generate Diagnostics** from the [https://github.com/dopesecurity/docs/blob/main/dope.endpoint/dope.endpoint-ui](https://github.com/dopesecurity/docs/blob/main/dope.endpoint/dope.endpoint-ui "mention").

## Run Diagnostics

To get the dope.endpoint to run a set of diagnostic tests, select the “Generate Diagnostics” option from the dope.endpoint UI.

{% hint style="info" %}
**Windows:** Right click on the DS, and select “Generate Diagnostics.”

**macOS:** Option ⌥ + click on the DS icon in the menu bar, then select “Generate Diagnostics.”
{% endhint %}

dope.endpoint will run a set of tests, gather internal and relevant OS logs, and upload it to the dope.cloud.

{% hint style="info" %}
Debug logs can also be manually retrieved from these directories:\
\
**Windows:** `C:\ProgramData\dope.security`

**macOS:** `/Library/Application\ Support/dope.security`
{% endhint %}

## Enable Debug Mode

In some cases, you may need to enable debug mode to help solve a problem. This can be done by selecting “Enable Debug Mode” from the dope.endpoint UI.

{% hint style="info" %}
**Windows:** Right click on the DS icon, and select “Enable Debug Mode”

**macOS:** Option ⌥ + click on the DS icon in the menu bar. Select “Enable Debug Mode.”
{% endhint %}

Once the problem is resolved, you can disable debug mode by selecting "Disable Debug Mode" in the dope.endpoint UI.


# Disable Endpoint

To disable dope.swg from the endpoint, right click (Option ⌥ + click on macOS) the DS icon and select disable endpoint. The end-user must enter the anti-tampering password (if enabled under Settings).\
\
Alternatively, it can be remotely disabled from the dope.console.<br>

<figure><img src="/files/26iA5vUJRhiRCkrZ1F1c" alt=""><figcaption><p>The user needs to type in the anti-tampering password if enabled on your tenant</p></figcaption></figure>

{% hint style="danger" %}
Once the endpoint is disabled, it will stop intercepting any web traffic.
{% endhint %}

The dope.console and the dope.endpoint UI disable status is always kept in sync.


# Installing using MDM on Mac

{% hint style="info" %}
Without MDM, permissions have to be manually approved due to Apple requirements. It's a few button clicks to approve if you're just testing, but it doesn't scale for wider deployments, for which we highly recommend (require) MDM
{% endhint %}

We've pre-created a custom profile to make MDM profile deployment easy. Our mac MDM profile (`.mobileconfig`) consists of 5 configurations:

1. Root Certificate - for trusting the on-device SSL inspection
2. Network Extension Permission - for re-routing traffic to the on-device proxy
3. VPN Permission - for re-routing traffic to the on-device proxy
4. Privacy Preferences Permission - for anti-tampering
5. Service Management Permission - for anti-tampering to login & background items

<figure><img src="/files/9jOCFsKrUVMNB6enlQr9" alt=""><figcaption><p>Sample system extension policy from Simple MDM</p></figcaption></figure>

The easiest method to import these is to upload, or copy & paste the custom profile below into your MDM software. You can also manually create it.

{% hint style="info" %}
Some MDM software will require you to save & upload this as a `.mobileconfig` file
{% endhint %}

{% file src="/files/0GjlTO5toD39rGgdbCGv" %}

```
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
	<key>PayloadContent</key>
	<array>
		<dict>
			<key>PayloadDisplayName</key>
			<string>DopeSecurityApp</string>
			<key>PayloadIdentifier</key>
			<string>com.apple.vpn.managed.3FC862E3-0F98-45DA-9BA0-B00D74C6E82E</string>
			<key>PayloadType</key>
			<string>com.apple.vpn.managed</string>
			<key>PayloadUUID</key>
			<string>798346BB-9A01-40B3-8EA6-377B26B0018B</string>
			<key>PayloadVersion</key>
			<integer>1</integer>
			<key>UserDefinedName</key>
			<string>DopeSecurityApp</string>
			<key>VPN</key>
			<dict>
				<key>AuthenticationMethod</key>
				<string>Password</string>
				<key>ProviderBundleIdentifier</key>
				<string>security.dope.DopeSecurityApp.Redirector</string>
				<key>ProviderDesignatedRequirement</key>
				<string>anchor apple generic and identifier "security.dope.DopeSecurityApp.Redirector" and (certificate leaf[field.1.2.840.113635.100.6.1.9] /* exists */ or certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = 63JU25B8Q7)</string>
				<key>RemoteAddress</key>
				<string>localhost</string>
			</dict>
			<key>VPNSubType</key>
			<string>security.dope.DopeSecurityApp</string>
			<key>VPNType</key>
			<string>VPN</string>
			<key>VendorConfig</key>
			<dict>
				<key>Group</key>
				<string>63JU25B8Q7.security.dope.DopeSecurityApp</string>
			</dict>
		</dict>
		<dict>
			<key>AllowedTeamIdentifiers</key>
			<array>
				<string>63JU25B8Q7</string>
			</array>
			<key>PayloadDisplayName</key>
			<string>System Extension Policy</string>
			<key>PayloadIdentifier</key>
			<string>com.apple.system-extension-policy.190E1DB5-015F-4CAF-8AD5-9F0C293663DE</string>
			<key>PayloadType</key>
			<string>com.apple.system-extension-policy</string>
			<key>PayloadUUID</key>
			<string>1CAA9256-333E-4F53-BF59-F54984275562</string>
			<key>PayloadVersion</key>
			<integer>1</integer>
			<key>NonRemovableFromUISystemExtensions</key>
			<dict>
				<key>63JU25B8Q7</key>
				<array>
					<string>security.dope.DopeSecurityApp.Redirector</string>
					<string>security.dope.DopeSecurityApp.PacketFilter</string>
				</array>
			</dict>
			<key>RemovableSystemExtensions</key>
			<dict>
				<key>63JU25B8Q7</key>
				<array>
					<string>security.dope.DopeSecurityApp.Redirector</string>
					<string>security.dope.DopeSecurityApp.PacketFilter</string>
				</array>
			</dict>
		</dict>
		<dict>
			<key>PayloadCertificateFileName</key>
			<string>dope.security.root</string>
			<key>PayloadContent</key>
			<data>
			LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUR1RENDQXFD
			Z0F3SUJBZ0lVZHlRUUc3eFoyUUFFVEZncVhQZHptbGVCUlNBd0RR
			WUpLb1pJaHZjTkFRRUwKQlFBd2RERUxNQWtHQTFVRUJoTUNWVk14
			RXpBUkJnTlZCQWdNQ2tOaGJHbG1iM0p1YVdFeEZqQVVCZ05WQkFj
			TQpEVTF2ZFc1MFlXbHVJRlpwWlhjeEZqQVVCZ05WQkFvTURXUnZj
			R1V1YzJWamRYSnBkSGt4SURBZUJnTlZCQU1NCkYyUnZjR1V1YzJW
			amRYSnBkSGxmY205dmRGOWpZU0F4TUI0WERURTVNRFV3TWpBd01E
			QXdNRm9YRFRNNU1EVXcKTVRBd01EQXdNRm93ZERFTE1Ba0dBMVVF
			QmhNQ1ZWTXhFekFSQmdOVkJBZ01Da05oYkdsbWIzSnVhV0V4RmpB
			VQpCZ05WQkFjTURVMXZkVzUwWVdsdUlGWnBaWGN4RmpBVUJnTlZC
			QW9NRFdSdmNHVXVjMlZqZFhKcGRIa3hJREFlCkJnTlZCQU1NRjJS
			dmNHVXVjMlZqZFhKcGRIbGZjbTl2ZEY5allTQXhNSUlCSWpBTkJn
			a3Foa2lHOXcwQkFRRUYKQUFPQ0FROEFNSUlCQ2dLQ0FRRUF2MC9D
			eEREUXZWaCttRzJ5aDNTOUZWdEp2RytDVzBPYjY4K2Jpck14Z2Vq
			NQpUNVhMV1ZxUldSYURoaUIrUGRKRXBab21JakUvNXI4UWRrWlB5
			cHNacVZOakJ6ejJNOGZsb1lJeHM1MW5VZ3U0ClkrUU1wOEFEamli
			NWN1a2p0N2hUSTdaUU5nZmRVaVk3MGloTzhGOUh4Q09kM0Mzd25J
			TVhGN0FyTXlCTDVIRisKbm1DT2psRzMxbE90Yjg3WUJsa3B0WmlY
			VzlOV3dmcWVCaHlhWlJRcmxURGQ5VDJkRWhLdzBsTjMrelprbU4v
			WQp0QkNkbSs0bWU4WHBVV05Bc0NCTVJYRStqajVjbXZ5SlJHNmxh
			UTZJVi92T08xNjNrSUF4UkhTYyt3M0NjY1lXCklua2pJdnJhcEoy
			UWNjWnJEcnEreEhISnFLZEJ1b2FwTTBpN0o4dExSUUlEQVFBQm8w
			SXdRREFkQmdOVkhRNEUKRmdRVXJBWGZFTnk4Nlh0TFZxRUF1REJh
			alNvL1J6d3dFZ1lEVlIwVEFRSC9CQWd3QmdFQi93SUJBakFMQmdO
			VgpIUThFQkFNQ0FRWXdEUVlKS29aSWh2Y05BUUVMQlFBRGdnRUJB
			RUFiRWRLeUFUdzB0KzB6QUJENlM3NzVoa2ozCmNMU2JwSXNjLzFt
			T0ZpdE1Jck4wTjFCSFFrZ0FlaHJsK2F0anVpM2dXQktGZCtJYWpO
			MWZqUTRRdG9BUVQyUWMKTVFzajVZWlNWeURlUjdQaTF3UHdtUG01
			YmlFaFFER0RVSG42RWd0RDF0MWNMWnlmNnRuUE9meFZ3VDlQZ0dP
			QQpGRWNVS3BNNjlMRzNJMWtFa0ljOTI5cTNUZXFXbGZGZi9kWnUy
			eWg4SDhBUUttcXh1dno1K3A0Q2ZHT0U0QzdjCmIzUEFZclJlQmY1
			aXptdlNxREFjSjNpRTdON0ZRaG5lR3ZNK1NNbWJnUy83ZndYaVpP
			clZvY2JvdCtSM2N1eXAKd2hIUmxaa2pXK1ZJQWsvNkJBeStZQ0x4
			MXZiVGZtd3J6M3Eva3p4cU5pMURydk5WWXByVU9KK2dZOU09Ci0t
			LS0tRU5EIENFUlRJRklDQVRFLS0tLS0K
			</data>
			<key>PayloadDisplayName</key>
			<string>Certificate</string>
			<key>PayloadIdentifier</key>
			<string>com.apple.security.pem.16D10826-5C9D-4C3E-968C-BE5792B1AAF2</string>
			<key>PayloadType</key>
			<string>com.apple.security.pem</string>
			<key>PayloadUUID</key>
			<string>16D10826-5C9D-4C3E-968C-BE5792B1AAF2</string>
			<key>PayloadVersion</key>
			<integer>1</integer>
		</dict>
		<dict>
			<key>PayloadDisplayName</key>
			<string>Privacy Preferences Policy Control #1</string>
			<key>PayloadIdentifier</key>
			<string>com.apple.TCC.configuration-profile-policy.979E8021-9009-488A-9387-BFD0A394B1CC</string>
			<key>PayloadType</key>
			<string>com.apple.TCC.configuration-profile-policy</string>
			<key>PayloadUUID</key>
			<string>979E8021-9009-488A-9387-BFD0A394B1CC</string>
			<key>PayloadVersion</key>
			<integer>1</integer>
			<key>Services</key>
			<dict>
				<key>SystemPolicyAllFiles</key>
				<array>
					<dict>
						<key>Allowed</key>
						<true/>
						<key>CodeRequirement</key>
						<string>anchor apple generic and identifier "security.dope.DopeSecurityApp" and (certificate leaf[field.1.2.840.113635.100.6.1.9] /* exists */ or certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = "63JU25B8Q7")</string>
						<key>Identifier</key>
						<string>security.dope.DopeSecurityApp</string>
						<key>IdentifierType</key>
						<string>bundleID</string>
						<key>StaticCode</key>
						<false/>
					</dict>
				</array>
			</dict>
		</dict>
		<dict>
			<key>PayloadDisplayName</key>
			<string>Dope - Login + Background Items</string>
			<key>PayloadIdentifier</key>
			<string>com.apple.servicemanagement.979E8021-9009-488A-9387-BFD0A394B1CD</string>
			<key>PayloadType</key>
			<string>com.apple.servicemanagement</string>
			<key>PayloadUUID</key>
			<string>B8F2A3C1-4D5E-4F6A-8B9C-1D2E3F4A5B6C</string>
			<key>PayloadVersion</key>
			<integer>1</integer>
			<key>Rules</key>
			<array>
				<dict>
					<key>RuleType</key>
					<string>TeamIdentifier</string>
					<key>RuleValue</key>
					<string>63JU25B8Q7</string>
					<key>Comment</key>
					<string>dope.security - all login and background items</string>
				</dict>
			</array>
		</dict>
	</array>
	<key>PayloadDisplayName</key>
	<string>DopeSecurityApp</string>
	<key>PayloadIdentifier</key>
	<string>DOPE.D66FA254-FEC6-4BBD-80CC-7CFB4A93CF8E</string>
	<key>PayloadScope</key>
	<string>System</string>
	<key>PayloadType</key>
	<string>Configuration</string>
	<key>PayloadUUID</key>
	<string>FFC74072-37BC-46C4-B376-81547F290B9F</string>
	<key>PayloadVersion</key>
	<integer>1</integer>
</dict>
</plist>
```

#### Anti-tampering on Mac

To prevent end-users from tampering or disabling the endpoint, there are several permissions that must be part of the above MDM profile. You'll know that these are in effect as they will show up inside of your System Preferences:

<figure><img src="/files/vjotzdjZuIaBxN391M3R" alt="" width="375"><figcaption><p>The Login &#x26; Background Items is fixed to be <strong>On</strong></p></figcaption></figure>

<div data-full-width="false"><figure><img src="/files/BJ1J49K9vpxkUQJnvRz6" alt="" width="375"><figcaption><p>The Network Extension is fixed to be <strong>On</strong></p></figcaption></figure></div>

{% hint style="success" %}
These settings were updated to prevent disabling in MacOS 15 onwards
{% endhint %}

#### Deploying the .zip

After deploying the MDM profile, you can now upload the `.zip` and have it deployed to your target systems.

It's unusual, but if you need a DMG for any reason, you can run this command:

```
hdiutil create -format UDZO -srcfolder dope_security_mac_1.0.9723 dope_1-0-9721.dmg
```

After deploying MDM & the installer to your target devices, users will no longer be required to enter your password or accept other permissions.\
\
That's it!

#### Troubleshooting: "Requires Setup" on macOS

If a device remains in setup-required/error state after deployment, use this checklist:

1. Confirm the dope MDM profile is assigned to the device scope
2. Confirm all 5 payloads are present in the profile:
   * Root Certificate
   * Network Extension
   * VPN
   * Privacy Preferences
   * Service Management (Login + Background Items)
3. Force profile sync/check-in from your MDM
4. Verify the endpoint checks in again in Endpoint Manager View

{% hint style="info" %}
Very rarely, macOS defects can cause extension-loading issues even when the profile is correct. In these cases, a device reboot will complete extension loading.
{% endhint %}


# Using JAMF

JAMF simplifies mass-installation of the dope.endpoint on Mac. This removes all manual steps: trusting the Certificate and accepting system extension permissions.<br>

There are two primary components:

1. **MDM Profile**: this is the config profile that contains the certificate, extension, VPN, and privacy permission to ensure the user will never see a pop-up. Otherwise, there will be manual interaction for accepting/authorizing the installation (due to Apple security policies)<br>
2. [Managed Installation](https://learn.jamf.com/bundle/jamf-pro-documentation-current/page/Package_Deployment.html): this is where you upload the full zip to JAMF to deploy to your devices - same steps as any managed deployment (upload the install zip as-is). Once distributed, JAMF will run the installer

{% hint style="warning" %}
Known JAMF Issues outside of dope.security control:

1. JAMF documentation mentions that .zip is not supported, but it works perfectly fine
2. JAMF can be intermittently slow and will display an **Availability Pending** message. It can take up to an hour to process<br>

   <figure><img src="/files/msnoz0hxpCSioRRWTHcy" alt="" width="294"><figcaption></figcaption></figure>
3. JAMF intermittently imports only 4 of 5 required items, and misses the root certificate. Ensure that your MDM profile contains all 5 permissions & upload the root certificate if required.
   {% endhint %}

## 1. Upload the `MobileConfig` File

You can retrieve the MDM profile's XML [here](/dope.endpoint/installing-using-mdm-on-mac) and directly upload it to JAMF. This will contain all requisite permissions at once, including:

1. Root Certificate - for trusting the on-device SSL inspection
2. Network Extension Permission - for re-routing traffic to the on-device proxy
3. VPN Permission - for re-routing traffic to the on-device proxy
4. Privacy Preferences Permission - for anti-tampering
5. Service Management Permission - for anti-tampering to login & background items

{% file src="/files/0GjlTO5toD39rGgdbCGv" %}

<figure><img src="/files/B6aEpVcI1C0QhLN4c69k" alt=""><figcaption><p>You can validate that the 5 payloads are configured</p></figcaption></figure>

After uploading it to JAMF, you will have the full profile available to target and deploy to devices.

## 2. Deploy profile to devices

Take your new profile scope, click Scope, and target it to your endpoints:

<figure><img src="/files/uD3uy3BnM0hf4DmFWzKF" alt=""><figcaption><p>An screenshot sample of deploying to targets</p></figcaption></figure>

Add the target machines you want to distribute to.

The profile should have 4 items (certificate, system extension, vpn, and privacy preferences):

<figure><img src="/files/JmnPfm7hZOzvqzC0JXab" alt="" width="563"><figcaption><p>All 4 permissions are now on the device. This screen looks slightly different on Mac12</p></figcaption></figure>

<figure><img src="/files/HPrBrDmli7b0U4u415zN" alt=""><figcaption><p>You can also validate the certificate is marked as Always Trust on Keychain Access</p></figcaption></figure>

## 3. Install the application pkg

Create a [JAMF package deployment](https://learn.jamf.com/en-US/bundle/jamf-pro-documentation-current/page/Package_Deployment.html) and upload the installation `.zip`. Recall, it includes:

* Installer `.pkg` (Universal binary supports both Intel & Arm)
* `agent_parameters.json`
* Certificate

{% hint style="success" %}
JAMF documentation does not explicitly say that .zip is supported, however you can directly upload the .zip to JAMF without issues
{% endhint %}

Scope the target machines you want to install to and send. Target machines will pick up, install the dope.security package, and require no manual intervention.

<figure><img src="/files/D6gCmmzgtSIu94QgAd9M" alt=""><figcaption><p>You'll need to write a policy with the package &#x26; scope it. Use cloud distribution and install once per device.</p></figcaption></figure>

The next step on the target machines will be to authenticate using Google or O365.


# Using Kandji

Kandji allows you to do a managed device deployment with a Kandji blueprint. Kandji (or any MDM) eliminates manual steps on Mac to trust the Certificate and accept permissions for our system extension.

There are two primary components:

1. **MDM Profile**: this is the config profile that contains the certificate, extension, VPN, and privacy permission to ensure the user will never see a pop-up. Otherwise, there will be manual interaction for accepting/authorizing the installation (due to Apple security policies)<br>
2. [Custom App Deployment](https://support.kandji.io/support/solutions/articles/72000559807-deploying-custom-apps): this is where you upload the full zip to Kandji to deploy to your devices - same steps as any managed deployment (upload the install zip as-is). Once distributed, Kandji will run the installer

### 1. Upload the `MobileConfig` File

You can retrieve the MDM profile's XML [here](/dope.endpoint/installing-using-mdm-on-mac) and directly upload it to Kandji. This will contain all requisite permissions at once, including:

1. Root Certificate - for trusting the on-device SSL inspection
2. Network Extension Permission - for re-routing traffic to the on-device proxy
3. VPN Permission - for re-routing traffic to the on-device proxy
4. Privacy Preferences Permission - for anti-tampering
5. Service Management Permission - for anti-tampering to login & background items

{% file src="/files/0GjlTO5toD39rGgdbCGv" %}

<figure><img src="/files/OntJUj8lEMSfnbViaPp8" alt=""><figcaption><p>Add a custom profile using Kandji library items</p></figcaption></figure>

{% hint style="info" %}
You will need to add the XML to a .mobileconfig file, and upload it to Kandji as show below.
{% endhint %}

<figure><img src="/files/w2LRpud4om6mJSlOJ4lY" alt=""><figcaption><p>After uploading the mobileconfig file</p></figcaption></figure>

### 2. Deploy profile to devices <a href="#id-2.-deploy-profile-to-devices" id="id-2.-deploy-profile-to-devices"></a>

Add the custom profile to the blueprints you are going to install the endpoint on. We always recommend to deploy the profile prior to installing the software to ensure there are no user pop-ups.

### 3. Upload the application pkg zip <a href="#id-2.-deploy-profile-to-devices" id="id-2.-deploy-profile-to-devices"></a>

Add a new custom app into your library with the Mac package downloaded from your dope.console:

<figure><img src="/files/tQLEU9T4HzkVBZnr85EA" alt=""><figcaption><p>You can directly upload the zip here</p></figcaption></figure>

You can add the Blueprints that the application will be deployed to here, and select either:

* Install once per device: This option will install the software only
* Audit & Enforce: This will use a [script](https://github.com/kandji-inc/support/blob/main/Scripts/audit-enforce-scripts/enforce_app_install.zsh) to ensure the software remains installed (best practice, although the software is built to prevent removal)

<figure><img src="/files/DaKyVx2LtzsBfn2kuzyc" alt=""><figcaption><p>Upload the zip, extract to /tmp or your preferred directory, and add in the installer command</p></figcaption></figure>

After the library item has been setup, you will be able to deploy this to all of your devices quickly. You may opt to do a small test deployment, but we have seen admins deploy thousands of healthy installs in minutes.


# Using Intune

{% embed url="<https://youtu.be/cV12Hc1QVpM>" %}

Unfortunately, Intune does not support deployment of zipped PKG files natively (ZIP contains the agent\_parameter.json, certificate, and installer). Therefore, there are a few extra steps required to deploy to Macs via Intune.

{% hint style="warning" %}
Review [Installing using MDM on Mac](/dope.endpoint/installing-using-mdm-on-mac) and ensure that the MDM profile is on the devices you install to. Otherwise, the user will need to manually accept permissions.
{% endhint %}

{% file src="/files/0GjlTO5toD39rGgdbCGv" %}

***

### **Overview**

Using Microsoft Intune to deploy *dope.security* on macOS involves three major steps:

1. **Deploy** [**MDM Profile**](/dope.endpoint/installing-using-mdm-on-mac) to Mac devices via Intune
2. **Create a`.pkg`** with all required files and a unique receipt identifier.
3. **Write a post-install script** to automate additional installation tasks and clean-up.
4. **Upload and configure your PKG** in Intune with the proper detection rules.

***

### **1. Create a PKG with Files and a Custom Receipt**

Due to Intune limitations, a single macOS installer package (`.pkg`) needs to be created:

* The **installer files** required by *dope.security* (installer, agent\_parameters.json, certificate) downloadable from the dope.console
* **Unique package identifier** for Intune/macOS to confirm successful install

#### **Steps**

1. **Organize Files**
   * Create a temp directory with the three dope.security installation files:

     ```bash
     e.g. /tmp/myfiles
     ```
2. **Build the Package**
   * Use `pkgbuild` to create the `.pkg`. Below is a simple example:

     ```bash
     bash;
     pkgbuild --root /tmp/myfiles --identifier installer.dope.com --version 1.0 --install-location /tmp /tmp/my_package.pkg
     ```
   * Key flags:
     * `--identifier installer.dope.com`: A unique identifier for this package.
     * `--install-location /tmp`: Where the files will be placed on the Mac. Adjust to suit your environment, for instance `/Applications` or `/usr/local/bin`.
3. **Verify the Package**
   * **Check Package Signature**:

     ```bash
     pkgutil --check-signature /tmp/my_package.pkg
     ```
   * **List Package Contents**:

     ```bash
     pkgutil --payload-files /tmp/my_package.pkg
     ```
   * Confirm it includes the three files before proceeding

***

### **2. Customize Post-Install Script**

The post-install script automates the extra steps-- running the *dope.security* installer and cleaning up.

{% hint style="info" %}
Change the package version to what you've downloaded in the script below
{% endhint %}

#### **Post-Install Script**

```bash
#!/bin/bash

# Variables
INSTALLER_PATH="/tmp/dope_security_1.0.INSERT_VERSION.pkg"
LOG_FILE="/var/log/dope_install.log"

# Step 1: Silent installation
echo "Starting silent installation..." | tee -a "$LOG_FILE"
sudo installer -pkg "$INSTALLER_PATH" -target / >> "$LOG_FILE" 2>&1

# Step 2: Cleanup
echo "Cleaning up temporary files..." | tee -a "$LOG_FILE"
rm -f "$INSTALLER_PATH"

# Finalize
echo "Installation complete." | tee -a "$LOG_FILE"
exit 0
```

***

### **3. Upload the PKG to Intune**

Intune needs the package and detection to ensure successful installation. Upload the `.pkg` file, configure the Intune checks, and add the post-install script.

#### **Steps**

1. **Upload the PKG**
   * Sign in to the [Microsoft Endpoint Manager admin center](https://endpoint.microsoft.com).
   * Go to: **Devices** > **macOS** > **macOS Apps** > **Add**.
   * When prompted, select and upload your `.pkg` (e.g., `/tmp/my_package.pkg`).
2. **Configure Detection Logic**

   * For detection, use:

   ```bash
   security.dope.DopeSecurityApp
   ```

   *

   ```
   <figure><img src="../../.gitbook/assets/image (3) (1).png" alt=""><figcaption></figcaption></figure>
   ```
3. **Add the Post-Install Script**
   * Paste your `postinstall` script here.
4. **Test the Deployment**
   * Assign the app to a test device or test group.
   * Once installed, verify:
     * *dope.security* is active and running.
     * The PKG appears:

       ```bash
       FOUND="$(mdfind 'kMDItemKind == "Application"' -onlyin /Applications | while read app; do BID="$(mdls -name kMDItemCFBundleIdentifier -raw "$app" 2>/dev/null)"; [ "$BID" = "security.dope.DopeSecurityApp" ] && echo "$app" && break; done)"; [ -z "$FOUND" ] && echo "Not found" || echo "Found at $FOUND"
       ```


# Digital Guardian Compatibility

When both DG and dope are deployed, dope.endpoint may intercept browser traffic before Digital Guardian, causing DG's DLP policies to not apply.

### The Issue

macOS processes network extensions in order. By default, the most recently installed transparent proxy handles traffic first.\
\
This means:

* Browser → Dope (intercepts) → DG (sees traffic from Dope, not the browser, so ignores it) → Internet

{% hint style="info" %}
DG only monitors traffic from browsers (Chrome, Firefox, Safari, Edge). It must come first in the network extension ordering to function.
{% endhint %}

### The Fix

Deploy this MDM profile to set explicit ordering so that DG processes traffic before dope.security:

```xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
	<key>PayloadContent</key>
	<array>
		
		<dict>
			<key>PayloadDisplayName</key>
			<string>DopeSecurityApp</string>
			<key>PayloadIdentifier</key>
			<string>com.apple.vpn.managed.3FC862E3-0F98-45DA-9BA0-B00D74C6E820</string>
			<key>PayloadType</key>
			<string>com.apple.vpn.managed</string>
			<key>PayloadUUID</key>
			<string>798346BB-9A01-40B3-8EA6-377B26B00180</string>
			<key>PayloadVersion</key>
			<integer>1</integer>
			<key>UserDefinedName</key>
			<string>DopeSecurityApp</string>
			<key>TransparentProxy</key>
			<dict>
				<key>AuthenticationMethod</key>
				<string>Password</string>
				<key>ProviderBundleIdentifier</key>
				<string>security.dope.DopeSecurityApp.Redirector</string>
				<key>ProviderDesignatedRequirement</key>
				<string>anchor apple generic and identifier "security.dope.DopeSecurityApp.Redirector" and (certificate leaf[field.1.2.840.113635.100.6.1.9] /* exists */ or certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = 63JU25B8Q7)</string>
				<key>Order</key>
				<integer>999</integer>
				<key>RemoteAddress</key>
				<string>localhost</string>
			</dict>
			<key>VPNSubType</key>
			<string>security.dope.DopeSecurityApp.Redirector</string>
			<key>VPNType</key>
			<string>TransparentProxy</string>
			<key>VendorConfig</key>
			<dict>
				<key>Group</key>
				<string>63JU25B8Q7.security.dope.DopeSecurityApp</string>
			</dict>
		</dict>
		<dict>
			<key>PayloadDisplayName</key>
			<string>DGWebProxy</string>
			<key>PayloadIdentifier</key>
			<string>com.apple.vpn.managed.DGWebProxy</string>
			<key>PayloadType</key>
			<string>com.apple.vpn.managed</string>
			<key>PayloadUUID</key>
			<string>91FFBEFB-B887-420D-A701-9E377BA08764</string>
			<key>PayloadVersion</key>
			<integer>1</integer>
			<key>UserDefinedName</key>
			<string>DGWebProxy</string>
			<key>TransparentProxy</key>
			<dict>
				<key>AuthenticationMethod</key>
				<string>Password</string>
				<key>ProviderBundleIdentifier</key>
				<string>com.digitalguardian.webproxy</string>
				<key>ProviderDesignatedRequirement</key>
				<string>identifier "com.digitalguardian.webproxy" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = HLGBMCXUS7</string>
				<key>Order</key>
				<integer>100</integer>
				<key>RemoteAddress</key>
				<string>localhost</string>
			</dict>
			<key>VPNSubType</key>
			<string>com.digitalguardian.webproxy</string>
			<key>VPNType</key>
			<string>TransparentProxy</string>
		</dict>
	</array>

	<key>PayloadDescription</key>
	<string>Sets NETransparentProxy provider ordering so Digital Guardian receives flows before Dope Security.</string>
	<key>PayloadDisplayName</key>
	<string>Transparent Proxy Order: Digital Guardian before Dope Security</string>
	<key>PayloadEnabled</key>
	<true/>
	<key>PayloadIdentifier</key>
	<string>security.dope.networkextension.transparentproxy.order</string>
	<key>PayloadOrganization</key>
	<string>Dope Security Inc.</string>
	<key>PayloadRemovalDisallowed</key>
	<false/>
	<key>PayloadScope</key>
	<string>System</string>
	<key>PayloadType</key>
	<string>Configuration</string>
	<key>PayloadUUID</key>
	<string>DE2A62BB-014D-494B-BCC6-0F90BE6C508E</string>
	<key>PayloadVersion</key>
	<integer>1</integer>
</dict>
</plist>
```

### Notes

* A reboot may be required after deploying the ordering profile
* The `Order` key only works with MDM, not manual installation
* Without MDM, the only way to control order is through installation/reinstallation timing (DG, then Dope)


# Installing using Intune on Win

{% embed url="<https://youtu.be/esBHBqcIqtw>" %}

Use Intune to mass-deploy to all corporate devices. There are two primary steps, and one optional:

1. [IntuneWin File Prep](https://learn.microsoft.com/en-us/mem/intune/apps/apps-win32-prepare): A Microsoft binary that prepares the zip for deployment
2. [Intune Deployment](https://learn.microsoft.com/en-us/mem/intune/apps/apps-win32-add): The series of steps to deploy the installer
3. [Autopilot Provisioning](https://learn.microsoft.com/en-us/mem/intune/enrollment/windows-enrollment-status) (Optional): Automated installation of applications when a new laptop is Entra joined

{% hint style="info" %}
If missing, the installer automatically installs the [Visual C++ redistributable](https://learn.microsoft.com/en-us/cpp/windows/latest-supported-vc-redist?view=msvc-170#latest-microsoft-visual-c-redistributable-version) (dependency). This causes a VC++ download prior to the dope.endpoint installation. Very rarely, this can cause install failures during managed deployments (bad network etc). To avoid, stage an Intune install of VC++ first
{% endhint %}

## 1. Prepare IntuneWin File

Intune requires a Win32 "preparation" process before uploading to the Intune console. You'll perform this step first.

{% hint style="info" %}
Microsoft docs are located [here](https://learn.microsoft.com/en-us/mem/intune/apps/apps-win32-prepare).
{% endhint %}

Download `IntuneWinAppUtil`, and use it to prepare the `.intunewin` package with this PowerShell command modified for version:

```
IntuneWinAppUtil -c .\dope_security_windows_1.0.x -s .\dope_security_1.0.x.exe -o .\ -q
```

{% hint style="warning" %}
Ensure that you use PowerShell for the above one-line command to work. If you just double-click the IntuneWinAppUtil executable, you will have to manually input the locations.
{% endhint %}

## 2. Intune Deployment

The application deployment process is standard and similar to any other application

{% hint style="info" %}
Microsoft docs are located [here](https://learn.microsoft.com/en-us/mem/intune/apps/apps-win32-add).
{% endhint %}

Here are a few hints for setting it up:

1. Install command should be `dope_security_<build number>.exe -silent`
2. Uninstall command: `dope_security_<build number>.exe -silent -uninstall AT_PASSWORD=<password>`
3. Detection rule: `C:\Program Files\` Folder: `dope.security` and use the `File or Folder Exists`dropdown
4. Assignment: `Required`

## 3. Autopilot Provisioning

When a new device is entra joined for the first time, it will run through the [checklist of apps](https://learn.microsoft.com/en-us/mem/intune/enrollment/windows-enrollment-status#block-access-to-a-device-until-a-specific-application-is-installed) to install prior to allowing a user access to the system. Sometimes, the Intune configured application can automatically be a part of the **Blocking Apps** inside of Autopilot which will naturally cause a conflict.

{% hint style="danger" %}
Ensure that you have removed dope.security from "blocking apps" in Autopilot, and instead, keep it as a required app. Blocked apps will prevent the enrollment process from successfully completing.
{% endhint %}

If you have this setup correctly, there will not be any issue during initial Entra-device joining.


# Mac Installer

Supports MacOS 13, 14, 15, and 26

### Download the macOS Installation Package

The dope.endpoint [universal installer](#user-content-fn-1)[^1] runs on both Apple Intel and Apple Silicon Native (M1, M2 etc).

To download the macOS installation package, log in to the dope.console, and click the download button <img src="/files/Wc4LHdftFbxVLfSUu865" alt="" data-size="line"> in the top right:

<figure><img src="/files/x9atVD7TaV3gVz1SO19t" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
This page explains installations where MDM has **not** been configured. To configure MDM, see [Installing using MDM on Mac](/dope.endpoint/installing-using-mdm-on-mac).
{% endhint %}

### Install the package on your device

After downloading the installer, extract the ZIP (***dope\_security\_mac\_\<build number>.zip).*** It contains three files:

* dope\_security\_\<build number>.pkg — The dope.endpoint installer.
* dope.security.root.crt — The dope.security Root CA, required for SSL inspection.
* agent\_parameters.json — Tenant-specific data required for the installation process.

{% hint style="warning" %}
All three files must be in the same directory or the installation will **FAIL**
{% endhint %}

Double click on the PKG file to launch the Installer:

<figure><img src="/files/EVBaSSV2wbqnICppWPDb" alt=""><figcaption></figcaption></figure>

Click Continue. A new screen will appear:

<figure><img src="/files/BwrWGYJbPj4LMSTU0naQ" alt=""><figcaption></figcaption></figure>

There will be a prompt to allow the dope.security Root CA to be installed:

<figure><img src="/files/eGtHOxBdZEuIfBNqdOJi" alt=""><figcaption></figcaption></figure>

### Manually approve the extension

Once these steps are complete a dope.security icon can be seen in the macOS menu bar <img src="/files/mRDElIB1vd9SEV3sMraO" alt="" data-size="line">.

{% hint style="info" %}
This dialogue could be hidden due to MDM, if so

MacOS 15: manually approve in: System Settings -> General -> Login Items & Extensions

MacOS 14: manually approve in Privacy & Security

Remember, to remove manual approvals you must [add an MDM profile](/dope.endpoint/installing-using-mdm-on-mac)
{% endhint %}

{% hint style="danger" %}
In MacOS 15, you must scroll down System Settings -> General -> Login Items & Extensions **all the way** to Extensions and find Network Extensions:\
\
![](/files/f4BoV04tJpEcEjRYMDdb)\
\
![](/files/WGpV16miKMV0drFA1hHU)

Remember, to remove manual approvals you must [add an MDM profile](/dope.endpoint/installing-using-mdm-on-mac)
{% endhint %}

The final prompts allow the dope.security application exstension to run. You should see a prompt to open settings:

<figure><img src="/files/XhAkmXzTJ2McbZWvQSuX" alt="" width="372"><figcaption><p>Without MDM, MacOS requires manual approvals</p></figcaption></figure>

Open the security preferences dialog box.

On MacOS 14 and lower, you will see the following:

<figure><img src="/files/yiaRMALqFfIPIBk7WNTy" alt="" width="375"><figcaption><p>System Settings Dialog in MacOS 14 "requires attention"</p></figcaption></figure>

On MacOS 15, this will open a different area with similar manual approval:

<figure><img src="/files/9rq0V0OV3nkPmNB4mBgQ" alt="" width="563"><figcaption></figcaption></figure>

Toggle to allow DopeSecurityApp to run:

<figure><img src="/files/eMZvUgZPCWafSQtbMtsV" alt="" width="375"><figcaption></figcaption></figure>

Finally, you will be prompted with a warning that the dope app will filter web traffic, again select to allow.

{% hint style="warning" %}
If you accidentally clicked **Don't Allow**, re-prompt the message by Option ⌥ + click the DS icon in the menu bar, and clicking **Quit.** It will re-open and prompt you again.
{% endhint %}

<figure><img src="/files/F3rnvYdULXagHCBfCQjb" alt="" width="375"><figcaption><p>Allow DopeSecurityApp to filter traffic</p></figcaption></figure>

{% hint style="info" %}
Prompts do not appear on devices that have the [dope MDM profile](/dope.endpoint/installing-using-mdm-on-mac) installed. On these deployments, the experience is completely invisible to the end-user.
{% endhint %}

If endpoint authentication has been enabled (See [Users](/dope.console/settings/users)), the user will be required to authenticate with M365 or Google credentials.

[^1]: Single installer Intel + Apple Silicon builds are known as Universal Installers


# Installation Process - Silent

### Downloading the macOS Installation Package

To download the macOS installation package log in to the dope.console. From the top right-hand corner select the download button <img src="/files/Wc4LHdftFbxVLfSUu865" alt="" data-size="line">. This will provide the different dope.endpoint installation packages available for download.

In the case of macOS, the dope.endpoint has one universal installation package that supports:

• Apple Intel\
• Apple Silicon (Native)

<figure><img src="/files/x9atVD7TaV3gVz1SO19t" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
This page is for a device where a Mobile Device Management (MDM) profile has **not** been installed. To install on a device with an MDM profile installed see [Installing using MDM on Mac](/dope.endpoint/installing-using-mdm-on-mac)
{% endhint %}

### Select the installer package for your device

After selecting the installation package you require, a ZIP file will be downloaded to your device. The ZIP file will be called **dope\_security*****\_mac\_\<processor type>\_\<build number>.zip***

The ZIP file will contain the following three files:

* dope.security-\<build number>.pkg — The dope.endpoint installer.
* dope.security.crt — The dope.security Root CA, required for SSL inspection.
* agent\_parameters.json — Tenant-specific data required for the installation process.

{% hint style="warning" %}
All three files must be in the same directory or the installation will FAIL.
{% endhint %}

To install the dope.endpoint go to a terminal and enter the following command:

```
sudo installer -pkg dope.security-<build number>.pkg -target /
```

Running this command will kick off the installation process but with no UI. There will be a prompt to allow the installation to start:

<figure><img src="/files/BwrWGYJbPj4LMSTU0naQ" alt=""><figcaption></figcaption></figure>

There will be a prompt to allow the dope.security Root CA to be installed:

<figure><img src="/files/eGtHOxBdZEuIfBNqdOJi" alt=""><figcaption></figcaption></figure>

The final prompt is to allow the dope.security application to run. There's a prompt to open the macOS security and preferences settings:

<figure><img src="/files/NM8JcbuZ0dEq141bWego" alt=""><figcaption></figcaption></figure>

Open the security preferences dialog box. Run the dope.security application:

<figure><img src="/files/07rhZoHZyzAu0aqDpeWn" alt=""><figcaption></figcaption></figure>

Once these steps are complete a dope.security icon can be seen in the macOS menu bar <img src="/files/09Vda7z9bqmXOhFm9ZXj" alt="" data-size="line">.

{% hint style="info" %}
All of the prompts above will not appear on a device where a MDM profile has been installed. For more details see [Installing using MDM on Mac](/dope.endpoint/installing-using-mdm-on-mac).
{% endhint %}

When the dope.endpoint has been successfully installed, and endpoint authentication has been enabled (see: [Users](/dope.console/settings/users)), one of these dialogs will be displayed prompting you to login via either your Google or Microsoft O365 corporate email.

<figure><img src="/files/oTiUhI8n9YrIQHoMhXzK" alt=""><figcaption><p>Google Login Example</p></figcaption></figure>

Log in with the appropriate corporate email address.

{% hint style="info" %}
Multi Factor Authentication (MFA) will also be required if enabled
{% endhint %}

Once the user has successfully authenticated, the dope.endpoint will be configured with the dope policy you have assigned them in the dope.console. If you have not assigned them a specific policy, they will automatically be assigned the Base Policy.

To check that the authentication was successful, simply click on the <img src="/files/09Vda7z9bqmXOhFm9ZXj" alt="" data-size="line"> icon in the menu bar. This will show the following information including the logged-in user.

<figure><img src="/files/O9umcbu4y5yRzQkad6SA" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Where endpoint authentication has **not** been enabled (see: [Users](/dope.console/settings/users)) the user will not be prompted to authenticate and will get the Base Policy.
{% endhint %}


# Uninstall

### On macOS the dope.endpoint can be uninstalled using an uninstall script.

Th uninstall script can be found within the dope.security installation folder /Library/Application Support/dope.security. The script is called uninstall.sh.

```
sudo zsh /Library/Application\ Support/dope.security/uninstall.sh
```

{% hint style="warning" %}
Users will always be prompted for an uninstall password where an anti-uninstall password has been configured in the dope.console (see: [Endpoints](/dope.console/settings/endpoints)).
{% endhint %}

Where an MDM profile has not been installed on the device there will be an initial prompt to allow the uninstall to start.

<figure><img src="/files/clhXg82pTHe7Fm727SLX" alt=""><figcaption></figcaption></figure>

You will then be prompted to enter the Anti-Tampering password.

You will then be prompted for your system password to uninstall the System Extension.

The uninstallation should continue and be successful.

### Uninstall Parameters

The uninstall script can take two parameters `-s` and `-p`.

Using `-s` makes the uninstall silent:

{% hint style="warning" %}
Using `-s` will not stop the password prompt where an anti-uninstall password has been configured in the dope.console (see: [Endpoints](/dope.console/settings/endpoints)).
{% endhint %}

Using `-p` allows a password to be sent with the following command:

```
sudo zsh /Library/Application Support/dope.security/uninstall.sh -p '<password>'
```

Using `-p` on its own with an incorrect password will result in a password re-prompt until the correct password is provided:

{% hint style="warning" %}
Where `-s` and `-p` are used together, an incorrect password will not result in a re-prompt but the uninstall will fail.
{% endhint %}

```
sudo zsh /Library/Application Support/dope.security/uninstall.sh -s -p '<password>'
```


# Endpoint Authentication

When dope.endpoint first installs and endpoint authentication is enabled (See [Users](/dope.console/settings/users)), every user must login with their Microsoft 365 / Google corporate email.

<figure><img src="/files/hJ9YSRJ7MDbSOmHhUWvN" alt=""><figcaption><p>Google Login Example</p></figcaption></figure>

Log in with the appropriate corporate email address.

{% hint style="info" %}
macOS supports silent auto-login for Intune-managed devices when that feature is configured. For other deployments, users will complete a one-time interactive OIDC sign-in flow.
{% endhint %}

{% hint style="info" %}
If enabled, Multi Factor Authentication (MFA) will be required.
{% endhint %}

Once the user has successfully authenticated the following page will be displayed.

<figure><img src="/files/PSbD1TOGdnHKSMRWwMaQ" alt=""><figcaption><p>Successful Authentication Page</p></figcaption></figure>

Close this page to continue browsing. The dope.endpoint will automatically enforce dope policy as assigned in the dope.console. If you haven't assigned a group or user policy, the user will be assigned the Base Policy.

To confirm authentication was successful, click the <img src="/files/mRDElIB1vd9SEV3sMraO" alt="" data-size="line"> icon in the menu bar. This shows the logged-in user & policy refresh:

<figure><img src="/files/1V4WBvN68ym1JMdb3edf" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
If endpoint authentication is **not** enabled (See [Users](/dope.console/settings/users)) the user \***will not\*** be prompted to authenticate. They will receive the Base Policy.
{% endhint %}

### Unauthenticated Users

If a user has not authenticated and they attempt to access the internet, they will see the following screen, selecting continue here will bring them to the M365 or Google Login Screen.

<figure><img src="/files/ryVad2jyDl7E0RfpXglH" alt=""><figcaption><p>OIDC Block Page</p></figcaption></figure>


# Windows Installer

Supports Windows 10 & 11

### Downloading the Windows Installation Package

To download the Windows installation package, log in to the Dope Console. Then, click the download button in the top right corner. <img src="/files/Wc4LHdftFbxVLfSUu865" alt="" data-size="line">

<figure><img src="/files/fQDPHiDLxLRru7dtP9jg" alt=""><figcaption></figcaption></figure>

The ZIP file will be called **dope\_security*****\_windows\_\<build number>.zip**.*

Extract the ZIP file, it will contain the following three files:

* \<build number>.exe — The dope.endpoint installer.
* dope.security.crt — The dope.security Root CA, required for SSL inspection.
* agent\_parameters.json — Tenant specific data required for the installation process.

{% hint style="warning" %}
All three files must be in the same directory or the installation will **FAIL**
{% endhint %}

{% hint style="info" %}
If missing, the installer automatically installs the [Visual C++ redistributable](https://learn.microsoft.com/en-us/cpp/windows/latest-supported-vc-redist?view=msvc-170#latest-microsoft-visual-c-redistributable-version) (dependency). This causes a VC++ download prior to the dope.endpoint installation. Very rarely, this can cause install failures during managed deployments (bad network etc). To avoid, stage an install of VC++ first
{% endhint %}

To install the dope.endpoint, double click on the EXE file. This will launch the following Installer UI.

<figure><img src="/files/DWTNST0D6cXDNpKJ0dso" alt=""><figcaption></figcaption></figure>

Before installation can start the dope.security End User License Agreement (EULA) needs to be accepted. Once this has been accepted, select the install option to start the installation process.

MS Windows will also prompt to accept installing the dope.endpoint on the Windows machine.

<figure><img src="/files/aiuijebeBZGXGPvSlf3w" alt=""><figcaption></figcaption></figure>

On selection of Yes the installation process will continue. Once it is complete the following dialog will be displayed.

<figure><img src="/files/oW9aiuudFykGUc11KRA0" alt=""><figcaption></figcaption></figure>

Once the installation is complete a dope.security icon can be seen in the Windows systems tray icon.

Where endpoint authentication has been enabled (See [Users](/dope.console/settings/users)), then the user will be prompted to authenticate with their M365 or Google credentials.


# Installation Process - Silent

### Downloading the Windows Installation Package

To download the Windows installation package log in to the dope.console and from the top right-hand corner select the download button <img src="/files/Wc4LHdftFbxVLfSUu865" alt="" data-size="line">.

This will provide the different dope.endpoint installation packages available for download.

Select the Windows Download option.

<figure><img src="/files/fQDPHiDLxLRru7dtP9jg" alt=""><figcaption></figcaption></figure>

The ZIP file will be called **dope\_security\_windows\_\<build number>.zip***.*

The ZIP file will contain the following three files:

* dope\_security\_\<build number>.exe — The dope.endpoint installer.
* dope.security.crt — The dope.security Root CA, required for SSL inspection.
* agent\_parameters.json — Tenant specific data required for the installation process.

{% hint style="warning" %}
All three files must be in the same directory or the installation will FAIL
{% endhint %}

To install the dope.endpoint go to a command line prompt and enter the following command:

```
dope_security_<build number>.exe -silent
```

Once the installation is complete a dope.security icon can be seen in the Windows systems tray icon <img src="/files/09Vda7z9bqmXOhFm9ZXj" alt="" data-size="line">.

When the dope.endpoint has been successfully installed, and endpoint authentication has been enabled (see: [Users](/dope.console/settings/users)), one of these dialogs will be displayed prompting the user to login via their Microsoft 365 / Google corporate emails

<figure><img src="/files/PZrA63N7Yik1EBdkfsk0" alt=""><figcaption><p>Microsoft 365 Login Example</p></figcaption></figure>

Log in with the appropriate corporate email address.

{% hint style="info" %}
If enabled, Multi Factor Authentication (MFA) will be required.
{% endhint %}

Once the user has successfully authenticated, the dope.endpoint will be configured with the dope policy you have assigned them in the dope.console. If you have not assigned them a specific policy, they will be assigned the Base Policy.

To check that the authentication was successful simply click on the <img src="/files/09Vda7z9bqmXOhFm9ZXj" alt="" data-size="line"> icon in the menu bar. This will show the following information including the logged-in user.

<figure><img src="/files/w5lLap4s6FLpBawVFpQB" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Where endpoint authentication has **not** been enabled (see: [Users](/dope.console/settings/users)) the user will not be prompted to authenticate and will get the Base Policy.
{% endhint %}


# Uninstall

On Windows the dope.endpoint can be uninstalled via the Add or Remove Programs feature or via an uninstall script.

### Add Remove Programs

In the search box on the windows taskbar, type Add or Remove Programs and select it from the results. From the list of Programs presented find the dope.security Endpoint and select Uninstall or Uninstall/Change. Then follow the directions on the screen.

{% hint style="warning" %}
Users will always be prompted for an uninstall password where an anti-uninstall password has been configured in the dope.console (see: [Endpoints](/dope.console/settings/endpoints)).
{% endhint %}

### Uninstall Script

To uninstall via the windows script run the following command from a command line:

```
dope_security_<build number>.exe -silent -uninstall
```

### Uninstall Parameters

Using `SILENT_INSTALL=yes` makes the uninstall silent.

{% hint style="warning" %}
Using `-s` will not stop the password prompt where an anti-uninstall password has been configured in the dope.console (see: [Endpoints](/dope.console/settings/endpoints)).
{% endhint %}

Using `AT_PASSWORD` allows a password to be sent with the command:

```
dope_security_<build number>.exe -silent -uninstall AT_PASSWORD=<password>
```

Where `-SILENT_INSTALL` and `AT_PASSWORD` are used together it means an incorrect password will not result in a re-prompt but the uninstall will fail.


# Endpoint Authentication

When the dope.endpoint has been successfully installed, and endpoint authentication has been enabled (See [Users](/dope.console/settings/users)), the following Windows notification will appear.

<figure><img src="/files/K5fVM7jVbHveWkreuizn" alt=""><figcaption><p>Windows System Notification</p></figcaption></figure>

Once you select Sign-In you will be prompted to login via your Microsoft 365 / Google corporate email.

{% hint style="info" %}
Windows supports silent auto-login for Intune-managed devices when that feature is configured. For other deployments, users will complete a one-time interactive OIDC sign-in flow.
{% endhint %}

<figure><img src="/files/AtwdT03KgKbWuiJZm2AP" alt=""><figcaption><p>Microsoft 365 Login Example</p></figcaption></figure>

{% hint style="info" %}
If enabled, Multi-Factor Authentication (MFA) will be required.
{% endhint %}

Once the user has successfully authenticated the following page will be displayed.

<figure><img src="/files/PSbD1TOGdnHKSMRWwMaQ" alt=""><figcaption><p>Successful Authentication Page</p></figcaption></figure>

This page can then be closed and the user can continue browsing. The dope.endpoint will be configured with the dope policy you have assigned them in the dope.console. If you have not assigned them a specific policy, they will automatically be assigned the Base Policy.

To check that the authentication was successful simply click on the <img src="/files/N5J8LERdzZ6fbASU8kAx" alt="" data-size="line"> icon in the menu bar. This will show the following information including the logged-in user.

<figure><img src="/files/sXqxhdYfHoPYaUFTXoRl" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Where endpoint authentication has **not** been enabled (see: [Users](/dope.console/settings/users)) the user will not be prompted to authenticate and will get the Base Policy.
{% endhint %}

### Unauthenticated Users

Where a user has not successfully authenticated and they attempt to access the internet they will get the following screen, selecting continue here will bring them to the M365 or Google Login Screen.

<figure><img src="/files/ryVad2jyDl7E0RfpXglH" alt=""><figcaption><p>OIDC Block Page</p></figcaption></figure>


# dope.endpoint UI

## The dope.security icon means peace of mind that your organization is being protected with the world’s best internet security. When you see the DS icon, you know you’re flying first class.

### **Using dope.swg at your endpoints**

When you’ve successfully installed a dope.swg endpoint, the DS icon will become visible.

On systems operating **Windows**, it will be visible in the Windows System Tray. On systems operating **macOS**, it will be on the macOS Menubar.

![The dope.security icon](/files/I7ynm2kFknPMqoiNOPfy)

This allows your users to see that the software is running on their endpoint.

{% hint style="info" %}
**On windows:** left click on the icon to access the UI.

**On macOS:** basic click on the icon to access the UI.
{% endhint %}

### When you click on the DS icon, your user can see basic information:

* Date/time of last policy update
* OpenID Connect email
* About

{% hint style="info" %}
The latest policy time should be the last updated from the Domain Controller, this is a field in the config.json.
{% endhint %}

There is more detailed information that’s available (see: [Windows UI](/dope.endpoint/dope.endpoint-ui/windows-ui) and [macOS UI](/dope.endpoint/dope.endpoint-ui/macos-ui)).

### UI diagnostics

The UI provides your users with the ability to run a diagnostic check and retrieve diagnostic logs from dope.endpoint. This information can be helpful if your user’s endpoint can’t connect to your organization’s admin or dope.console.

See [Running Diagnostics](/dope.console/endpoint-manager-view/running-diagnostics) for more information.


# Windows UI

## Clicking on the dope.security UI will give you access to further information on your endpoint. Left click for basic information, right click for more detailed information.

### Basic dope.endpoint information

If your endpoint user left clicks on the DS icon in the Windows System Tray, they can see basic information on the dope.endpoint running on their device.

<figure><img src="/files/w5lLap4s6FLpBawVFpQB" alt=""><figcaption></figcaption></figure>

* **User Identity**: When OIDC authentication is enabled this will show the email used by the user to verify their identity. Where OIDC is not enabled this will show the Logged-in User in the following format: \<Domain>/\<User Name>.
* **Last Policy Update**: Shows the date and time of the last policy update sent to the dope.endpoint from the dope.cloud.
* **About**: Displays the version of the dope.endpoint running on the device.

{% hint style="info" %}
Policies are automatically pushed from the console to the endpoint. When the <img src="/files/n3ZskrpzlhveUixfCAn7" alt="" data-size="line"> icon appears next to “Policy updated...” this indicates the last policy update included a policy change for the logged-in user.

To make sure you have the latest policy from the dope.cloud, you may select “Policy updated...” and it will fetch a policy push.
{% endhint %}

### Advanced dope.endpoint information

If you right click on the DS icon in the Windows System Tray, more advanced information and options will be displayed.

<figure><img src="/files/hjHYFu5QxfxfPpWCJJJW" alt=""><figcaption></figcaption></figure>

As well as displaying the same basic information available on a left click, the right click extends to show the following details:

**Account Detail:**

* **Tenant:** The name of the organization’s dope.cloud tenant
* **Provider:** The service provider being used (either Google or O365)
* **Type:** The organization’s current license type (In Trial, NFR, or Licensed)

**Status:** The current status of the dope.endpoint

* **Healthy:** dope.endpoint is working with no errors
* **Error:** dope.endpoint has an error and is not working
* **Disabled:** dope.swg endpoint has been put into disabled mode by the admin
* **Fallback:** If the agent is ever in Fallback Mode it will be shown next to the Status
  * **Enable Debug Mode:** If there's a need to debug an issue, this option will put the dope.endpoint into trace level loggin&#x67;**.** Use the same option to return the dope.endpoint to Error Level logging.
  * **Generate Diagnostics:** Selecting this option will get the dope.endpoint to run a set of tests and to save the results, along with an extensive set of logs, to the user's desktop.
  * **Disable Endpoint:** This option can be used to disable the endpoint. The anti-uninstall password will be required for the dope.endpoint to be disabled.

{% hint style="info" %}
The dope.cloud is kept up to date with the dope.endpoint status. It is still possible to re-enable the dope.endpoint from the Endpoint Manager View (see: [Disable Endpoint](/dope.console/endpoint-manager-view/disable-endpoint)).
{% endhint %}


# macOS UI

## Clicking on the dope.security UI will give you access to further information on your endpoint. Basic click for basic information, Option ⌥ + click for more detailed information.

### Basic dope.endpoint Information

If your endpoint user basic clicks on the DS icon in the macOS Menu Bar, they can see basic information on the dope.endpoint running on their device.

<figure><img src="/files/O9umcbu4y5yRzQkad6SA" alt=""><figcaption></figcaption></figure>

* **Last Policy Update**: Shows the date and time of the last policy update sent to the dope.endpoint from the dope.cloud.
* **User Identity**: When OIDC authentication is enabled this will show the email used by the user to verify their identity. Where OIDC is not enabled this will show the Logged-in User in the following format: \<Domain>/\<User Name>.
* **About**: Displays the version of the dope.endpoint running on the device.

{% hint style="info" %}
Policies are automatically pushed from the console to the endpoint. When the <img src="/files/n3ZskrpzlhveUixfCAn7" alt="" data-size="line"> icon appears next to “Policy updated...” this indicates the last policy update included a policy change for the logged-in user.

To make sure you have the latest policy from the dope.cloud, you may select “Policy updated...” and it will fetch a policy push.
{% endhint %}

### Advanced dope.endpoint Information

If you Option ⌥ + click on the DS icon in the macOS Menu Bar. more advanced information and options will be displayed.

<figure><img src="/files/F71Ygdd7rTpfCoZdUX4k" alt=""><figcaption></figcaption></figure>

As well as displaying the same basic information, the advanced information extends to show the following details:

**Account Detail:**

* **Tenant:** The name of the organization’s dope.cloud tenant
* **Provider:** The service provider being used (either Google or O365)
* **Type:** The organization’s current license type (In Trial, NFR, or Licensed)

**Status:** The current status of the dope.endpoint

* **Healthy:** dope.endpoint is working with no errors
* **Error:** dope.endpoint has an error and is not working
* **Disabled:** dope.swg endpoint has been put into disabled mode by the admin
* **Fallback:** If the agent is ever in Fallback Mode it will be shown next to the Status
  * **Enable Debug Mode:** If there's a need to debug an issue, this option will put the dope.endpoint into trace level loggin&#x67;**.** Use the same option to return the dope.endpoint to Error Level logging.
  * **Generate Diagnostics:** Selecting this option will get the dope.endpoint to run a set of tests and to save the results, along with an extensive set of logs, to the user's desktop.
  * **Disable Endpoint:** This option can be used to disable the endpoint. The anti-uninstall password will be required for the dope.endpoint to be disabled.

{% hint style="info" %}
The dope.cloud is kept up to date with the dope.endpoint status. It is still possible to re-enable the dope.endpoint from the Endpoint Manager View (see: [Disable Endpoint](/dope.console/endpoint-manager-view/disable-endpoint)).
{% endhint %}


# Automatic Updates

One of dope fundamentals is to reduce operational overhead & manual work, including deploying new agent versions, and waiting for policy updates to occur. Instead, an admin can instantly push new policies to an endpoint, and the endpoint will automatically upgrade to the latest version.

Our number one focus for this process is to be **invisible** to end users, by rigorously testing our releases, including build acceptance tests, automation QA, manual sanity tests, stress/load tests, and internal -> phased rollouts.

For transparency, we've documented frequently asked questions around how updates are pushed to your device and how we ensure the process has no impact to your end devices.

### What different updates can occur with Dope?

All dope upgrades are invisible, they are designed to be unnoticeable by end-users. Software updates do not require any system restarts.

* **dope.endpoint**: this is the main installable on your device (MacOS/Windows). It consists of multiple components, including:\
  \- Redirector: re-routes traffic to the Proxy. On Windows, this is driver that uses Microsoft's [WFP](https://learn.microsoft.com/en-us/windows/win32/fwp/windows-filtering-platform-start-page) to operate. On Mac, this is a [network extension](https://developer.apple.com/documentation/xcode/configuring-network-extensions) that uses exposed Apple's APIs.\
  \- Proxy: performs the SSL inspection, URL filtering, etc. The code is identical in both OS
* **Config/Policy Update**: these are admin-configured changes, such as blocking a web category, or adding a new URL to a custom category, adding a new domain to the cloud app controls etc.
* **Global Application/Domain Bypass**: these are delivered via the policy update, but are a set of dope-specified applications that are known to cause issues with SSL Inspection proxies. For example, the Zoom application
* **URL Categorization**: these are requested on-demand by the endpoint and are kept up-to-date via a regular cache update. For example, if a user visits google.com, the categorization for google.com will be requested, locally cached, and updated regularly

Each update occurs slightly differently:

* **dope.endpoint**: when a software update becomes available for a specific device, it is advertised to the endpoint via the configuration. The endpoint software update is then downloaded, and installed via the updater process. Except during a rollout period, all devices should be on the latest version
* **Config/Policy Update & Global Application/Domain Bypass:** both of these updates are part of the policy. So, if an admin makes a SWG policy change, or if a new application is added to the default bypass, the endpoints will retrieve the latest policy\
  \- Policy Push Websocket: the endpoint websocket receives notifications that a policy update has been made. In real-time, the endpoint will call the API to retrieve the latest policy update\
  \- Polling Policy Refresh: the endpoint automatically calls the API to retrieve the latest policy multiple times an hour, or when a device comes back online
* **URL Categorization:** these are either requested on-demand as websites are accessed, or updated as part of the category cache. URLs are tiered to ensure that requests are made sooner for websites that might change categorization. In the cloud, these are automatically updated multiple times a day.

### How are updates tested?

Each area of the different updates has a varied level of testing:

#### dope.endpoint Testing

Each release is thoroughly tested in a multi-step process, as detailed later, released in a multi-stage process.

<table><thead><tr><th width="249">Test Type</th><th>Purpose</th></tr></thead><tbody><tr><td>BAT (Branch Build Acceptance Test)</td><td>To allow for developers after making a Pull Request (could contain feature additions, bug fixes, or enhancements) to automatically compile a branch build and test against the top use-cases an end-user will go through. The BAT includes SSL inspection test-cases, bypass list, category blocking, etc.</td></tr><tr><td>Manual Sanity Test</td><td>Builds are manually tested to ensure there are no easy-to-spot issues to be fixed</td></tr><tr><td>Regression Test</td><td>Takes RC (release candidate) build and runs through an automated regression test suite that contains a very large set of test cases which includes feature coverage, previous bug coverage, and build upgrade coverage</td></tr><tr><td>Compatibility Test</td><td>Takes RC build and runs through compatibility tests with all major VPN clients, Endpoint Security software, and various networking environments (IPV6/V4 hybrid)</td></tr><tr><td>Load/Stress Test</td><td>Takes a fully tested RC build and runs the build through significant load for multiple days while monitoring for memory leaks, crashes, CPU spikes, and other potential issues</td></tr></tbody></table>

After the testing is complete and the release is ready, it is released internally on employee devices.

#### Config/Policy Update Testing

Admins push policy updates live via the cloud console. This is not controlled by dope.security. The general process of receiving a policy, whether via policy push or polling policy refresh is regularly tested via automation outlined above

#### Global Application/Domain Bypass Testing

Any addition to the default bypass list is manually tested before being pushed live.

#### URL Categorization Testing

URL categorizations are tested as part of all tests and is not tested specifically (except for [uptime](https://status.dope.security)). The main risk is a mis-categorization of a website, in which case we focus on speed of remediation/rollback of an incorrect categorization.

### Does dope.security use dope.security internally? (dogfood)

All devices at dope.security run our endpoint to ensure that we can see & resolve any issues that could've sneaked through release testing. The version in our environment is typically the upcoming release as a test-bed. It is in two phases:

1. **Internal Environment**: devices that are on branch builds, automation & load systems
2. **Production Environment**: employee devices that are on release candidate versions, that can eventually be used for a customer release

Both the Internal & Production environment both run the latest cloud deployment to reduce edge-cases

### How are updates rolled out?

The multi-stage rollout process helps ensure there are no large scale surprise issues, especially in customer environments. The release phase applies to the dope.endpoint only. The dope.cloud\_console only uses feature flags for releases.

<table><thead><tr><th width="249">Release Phase</th><th>Purpose &#x26; Scope</th></tr></thead><tbody><tr><td>Internal/Prod Dogfood</td><td>Allows for sanity tests and ensuring that no issues are seen on internal employee laptops</td></tr><tr><td>Partner &#x26; Early Access Tenants</td><td>Certain partners &#x26; customers have opted to receive releases at the earliest point. After deployment, these are monitored to ensure devices are healthy.</td></tr><tr><td>Customer-Specified Endpoints</td><td>Certain customers have specified canary endpoints that should receive builds first to ensure that if there are any issues it is caught early</td></tr><tr><td>Customer Tenants</td><td>After all health checks are positive, customer tenants are progressively updated to use the latest build</td></tr></tbody></table>

### Does dope monitor for failures, and rollback?

As upgrades are rolled out for each area, there are different options available to rollback in case of any failures. Each upgrade phase is monitored for failures.

* **dope.endpoint:** If a failure requiring rollback is required, the last release is prepared and all tenants are updated to use the last release (at an up-to-date version). If an **individual** endpoint upgrade failure occurs, rollback to the last version occurs automatically.
* **URL Categorization:** If any URLs are incorrectly categorized, the categorization can be corrected and will reflect in different time periods on a device based on the scenario:\
  \- Suspicious/Malicious False Positive (Tier 3): categorization expires after one hour, device will retrieve corrected categorization as soon as it is updated, or not more than one hour later\
  \- Popular Domain Incorrect Categorization (Tier 1): if a highly popular domain is incorrectly categorized, such as facebook.com, our team will push a domain bypass to immediately take effect on devices, or when the device comes back online


# Mac Installer (Old)

### The dope.endpoint is easy to install. You can upgrade your organization’s security in minutes.

{% hint style="success" %}
The dope.endpoint can be installed on the following macOS versions

* macOS 13 — Ventura
* macOS 14 — Sonoma
* macOS 15 — Sequoia
  {% endhint %}


# Windows Installer (old)

### The dope.endpoint is easy to install. You can upgrade your organization’s security in minutes.

{% hint style="success" %}
The dope.endpoint can be installed on the following versions

* Windows 10
* Windows 11
  {% endhint %}


# Release Notes

The dope.endpoint automatically updates when next online.

{% tabs %}
{% tab title="dope.cloud" %}

#### AI Usage Analytics&#x20;

**July 24, 2026**

New AI Usage report in Analytics showing top AI applications, top users, and per-user breakdowns.

***

#### Cloud Application Control: GitHub

**April 30, 2026**

Introduced CAC support for GitHub to ensure secure, enterprise-only access control.

***

#### SassS Security Posture Management (SSPM)

**April 22, 2026**

[SSPM](https://dope.security/post/ai-powered-sspm) delivers visibility and risk insights for third-party apps across Microsoft 365, enabling organizations to monitor access, permissions, and security posture.

***

#### Cloud Application Control: Claude

**March 30, 2026**

Introduced CAC support for Claude to ensure secure, enterprise-only access control.

***

#### Dopamine DLP

**February 16, 2026**\
Dopamine DLP is our endpoint-native data loss prevention solution, built directly into the Fly Direct SWG. Read more at [Dopamine DLP](https://inflight.dope.security/dope.console/dope.swg-policy/dopamine-dlp)

***

#### MS OAuth App Upgrade for improved security and stability

**November 15, 2025**\
Microsoft authentication and user/group imports now use a new Microsoft‑verified OAuth application, improving security, compliance, and reliability; existing customers will be prompted to re‑authorize.

***

#### CAC: Google Gemini Access Control

**October 2, 2025**\
Introduced a new Google CAC policy configuration to explicitly allow or block Gemini access.

***

#### CASB Neural: Direct Links & File Path

**August 27, 2025**\
Direct links in CASB to your publicly exposed files, including the folder path, making it easier for admins to review, track, and manage access. See folder location and Drive owner directly in the details panel.

***

#### SWG: Automatic Recategorization of Unknown Domains and Misc Enhancements

**June 13, 2025**

**Automatic Recategorization of Unknown Domains:** Automatically triggers recategorization requests for “Unknown” domains when configured as Block or Warning, and a violation is generated.

**Comment Support for Custom Bypasses:** Admins can now add comments when creating or editing custom domains and application bypasses. This enhancement improves context clarity and auditability for policy changes.

**ChatGPT Configuration in CAC:** Added support for configuring ChatGPT within the CAC, allowing greater control. Read more at [**dope.security/blog**](https://dope.security/post/blocking-chatgpt-personal)

***

#### CASB Neural: Externally Shared Files

**October 22, 2024**\
Now review Externally Shared Documents for even better DLP coverage! Files that have been shared outside your organization will now appear in your CASB Table. Read more at [CASB DLP](/dope.console/casb-neural/casb-dlp)

***

#### CASB Neural: Review Public Files

**August 06, 2024**\
For files that are safe to remain public, now you can leave a comment to let people know it’s been reviewed for content and intentionally kept public. Read more at [DLP Files Table](/dope.console/casb-neural/casb-dlp/dlp-files-table)

***

#### CASB Neural: Remediation of Public Files

**June 19, 2024**\
Your dope.console now has the capability to change publicly shared files to private. With a click of a button, your file will have the sharing permissions removed from your Microsoft 365 / Google tenant. Once the permissions are removed, your CASB table will update to remove the files from view. These files will now be included in the private file count. Read more at [DLP Files Table](/dope.console/casb-neural/casb-dlp/dlp-files-table)

***

#### CASB Neural: LLM-Powered DLP

**April 30, 2024**\
Your SWG does even more now with CASB Neural. Instantly crawl your OneDrive or Google Drive and extract and classify sensitive public-facing files with no pre-configurations required. Read more at [CASB Neural](/dope.console/casb-neural)

***

#### CAC: Blocking Personal Microsoft 365 & Gmail Uploads

**March 5, 2024**\
CAC Read Only — Allow customizations over CAC access and uploads. Get detailed policy control such as allowing personal access to Microsoft 365 and Google, but blocking from uploading files to an employee’s personal accounts. Read more at [**dope.security/blog**](https://dope.security/post/blocking-personal-uploads-with-cloud-app-controls)

***

#### SWG: New Categories Added

**November 21, 2023**\
6 new categories have been added to the DOPE Categories.

<table><thead><tr><th width="209">Category</th><th width="264">Definition</th><th>Use Case</th></tr></thead><tbody><tr><td><strong>AI/ML Applications</strong></td><td>Sites with generative apps that take user input</td><td>Warn users to not enter company private info</td></tr><tr><td><strong>Alternative Currency</strong> <em>(Parent Category: Business)</em></td><td>Sites related to cryptocurrency, game tokens or other exchangeable digital goods that are not government issued legal tender</td><td>Warn users, or log access for investigations, many small currency exchange sites are difficult to verify legitimacy</td></tr><tr><td><strong>Dynamic DNS</strong> <em>(Parent Category: IT)</em></td><td>Services that offer unique hosts on previously registered domains for personal use, and may regularly change IPs</td><td>Useful for investigations, since Dynamic DNS are often home users running services</td></tr><tr><td><strong>Login/Challenge</strong> <em>(Parent Category: IT)</em></td><td>Sites that have a homepage that is a generic login page or challenge (e.g. CAPTCHA), with no indication of what’s behind</td><td>Instead of these returning unrated, can provide what information we know</td></tr><tr><td><strong>Newly Registered</strong></td><td>Domains registered in last 30 days</td><td>Warn or block access to new unknown sites, or log for investigations</td></tr><tr><td><strong>Promotional Compensation</strong> <em>(Parent Category: Security)</em></td><td>Sites that promise a potential reward for user input or activity</td><td>Warn or block access to sites that gather PII for marketing</td></tr></tbody></table>

***

#### Public APIs

**November 1, 2023**\
API feature launched to allow you the ability to create, modify policy and retrieve dope.endpoint status via public API, rather than solely through the dope.console. For documentation, see: [Broken mention](broken://pages/Fv4IZGn86IncLNyfYRFg)

***

#### SWG: Extended Shadow IT

**September 1, 2023**\
Major upgrades to Shadow IT, including precise email detection with corporate vs personal differentiation and workspace IDs across AWS and Slack. Read more at [**dope.security/blog**](https://dope.security/post/shadow-it-we-made-it-dope-22a80d1cf866)<br>
{% endtab %}

{% tab title="dope.endpoint" %}

#### **`V 1.0.19054`**

**July 8, 2026**

– Stability fix: Resolved an issue where mismatched or invalid ICA certificates could cause agent connectivity problems.

***

#### **`V 1.0.18851`**

**June 10, 2026**

– Shadow IT: Claude.ai detection : Dope endpoint now detects and reports employee usage of Claude.ai as a Shadow IT application, extending coverage alongside existing detections for ChatGPT, Gemini, Grammarly, and others.

– Windows upgrade stability : Fixed critical bug where failed upgrades caused devices to fully uninstall and disappear from the management console

– Security library updates

– Windows CPU performance improved

– Other product stability, code refactoring and performance improvements

***

#### **`V 1.0.18509`**

**April 29, 2026**

– DLP: Gemini support added — DLP policies now extend to Google Gemini, enabling data protection controls for AI prompt activity on Gemini.

– DLP: Google Drive client upload support — Data Loss Prevention policies now apply to file uploads via the Google Drive desktop client, closing a previous coverage gap.

– CAC policies now remain enforceable even with SSL inspection bypass enabled

– Reduced latency on ChatGPT prompts

– Improved Grammarly Shadow IT detection

– Other product stability, code refactoring and performance improvements

***

#### **`V 1.0.18409`**

**April 08, 2026**

– Improved stability on Windows – reduced risk of agent crashes during device shutdown or reboot

– Allow/block rules now support path-level matching in addition to domain, enabling more precise policy control

– Other product stability, code refactoring and performance improvements

***

#### **`V 1.0.18293`**

**March 12, 2026**

– DLP detection for Claude AI

– Regular product stability, code refactoring and performance improvements

***

#### **`V 1.0.18293`**

**January 16, 2026**

– Dopamine DLP support is GA with this version. Dopamine DLP is our endpoint-native data loss prevention solution, built directly into the Fly Direct SWG. Read more at [Dopamine DLP](https://inflight.dope.security/dope.console/dope.swg-policy/dopamine-dlp)

– Regular product stability, code refactoring and performance improvements

***

#### **`V 1.0.17642`**

**November 18, 2025**

– Included Windows ARM support

– Regular product stability, code refactoring and performance improvements

***

#### **`V 1.0.17434`**

**October 10, 2025**

– Regular product stability, code refactoring and performance improvements

***

#### **`V 1.0.17231`**

**September 2, 2025**

– macOS 26: Fixed issue where internet connectivity was blocked after installing the Dope endpoint due to macOS 26 updates

***

#### **`V 1.0.17021`**

**Aug 20, 2025**

– Mac Power Usage Fix: Resolved an issue that caused higher-than-expected power consumption during system sleep on macOS devices\
– Regular product stability, code refactoring and performance improvements

***

#### **`V 1.0.16894`**

**Aug 05, 2025**

– Endpoint Auto-Login: AD/Entra/Hybrid-joined devices will automatically sign in on endpoint installation, without any manual user intervention\
– Regular product stability, code refactoring and performance improvements

***

#### **`V 1.0.16716`**

**July 15, 2025**

– Regular product stability, code refactoring and performance improvements

***

#### **`V 1.0.16330`**

**May 07, 2025**

– Implemented a fix to address battery drain issues\
– We now require MS Visual C++ Redistributable to be version 14.42.34433 or higher on Windows devices. If an older version is present, the device may restart during agent installation.\
– Regular product stability, code refactoring and performance improvements

***

#### **`V 1.0.15939`**

**April 10, 2025**

– Implemented an anti-tampering feature to prevent unauthorised modifications\
– Performance improvements on Mac\
– Regular product stability, code refactoring and performance improvements

***

#### **`V 1.0.14986`**

**Jan 10, 2025**

– WebSocket connectivity-related improvements\
– Resolved one issue where the DS menu list does not appear when clicking on the DS icon after restarting the Windows system\
– Included extra logging for better debugging\
– Regular product stability, code refactoring and performance improvements

***

#### **`V 1.0.14483`**

**Nov 16, 2024**

– Regular product stability and performance improvements

***

#### **`V 1.0.14223`**

**Oct 15, 2024**

– Enhanced stability for handling IPV4 and IPV6\
– Moved local IP bypass to the driver for a better experience\
– Regular product stability and performance improvements

***

#### **`V 1.0.13887`**

**August 12, 2024**

– Fix to handle rare instance where tray icon does not appear\
– Modification to fix Azure login via Cyberark\
– Regular product stability and performance improvements

***

#### **`V 1.0.13632`**

**August 01, 2024**

– Regular product stability and performance improvements

***

#### **`V 1.0.13402`**

**July 09, 2024**

– Enhancements to auto-upgrade feature\
– Enhancements to redirector\
– Improve websocket support\
– Fixed initial driver installation issue occurring in rare instances\
– Regular product stability and performance improvements

***

#### **`V 1.0.13254`**

**July 05, 2024**

– Regular product stability and performance improvements

***

#### **`V 1.0.12976`**

**June 11, 2024**

– Further improvements in supporting outbound IPv6 connections to IPv4-only VPNs\
– Regular product stability and performance improvements

***

#### **`V 1.0.12743`**

**May 16, 2024**

– Improvements in supporting outbound IPv6 connections to IPv4 only VPNs\
– Regular product stability and performance improvements

***

#### **`V 1.0.12645`**

**May 2, 2024**

– Auto-Upgrader will resume downloads (even with network interruption)\
– Improved Authentication on Windows with a “Toast” reminder message to authenticate (during initial installation)\
– Improved Shadow IT detection for ChatGPT\
– Health Status Reliability Improvements\
– General stability fixes

***

#### **`V 1.0.12365`**

**April 5, 2024**

– Regular product stability and performance improvements

***

#### **`V 1.0.12222`**

**March 20, 2024**

– Regular product stability and performance improvements

***

#### **`V 1.0.12118`**

**March 05, 2024**

– Regular product stability and performance improvements

***

#### **`V 1.0.12100`**

**March 04, 2024**

– Regular product stability and performance improvements

***

#### **`V 1.0.11964`**

**February 29, 2024**

– Cloud Application Control: Allow Blocking Personal Gmail/365 Uploads\
– Regular product stability and performance improvements

***

#### **`V 1.0.11824`**

**February 19, 2024**

– Regular product stability and performance improvements

***

#### **`V 1.0.11798`**

**February 13, 2024**

– Regular product stability and performance improvements

***

#### **`V 1.0.11728`**

**February 9, 2024**

– Improvements to the OIDC workflows\
– Regular product stability and performance improvements

***

#### **`V 1.0.11599`**

**February 1, 2024**

– Regular product stability and performance improvements

***

#### **`V 1.0.11574`**

**January 26, 2024**

– Regular product stability and performance improvements

***

#### **`V 1.0.11418`**

**January 18, 2024**\
– Trust self-signed roots on Mac present in System Keychain (for other enterprise proxies)\
– Improved login process (OIDC) to use local browser to improve compatibility for FIDO2, Passkeys, and Bluetooth authenticators\
– Regular product stability and performance improvements

***

#### **`V 1.0.11082`**

**December 13, 2023**\
– Shadow IT: Added new user login detections for ChatGPT, Grammarly, and GitHub\
– Regular product stability and performance improvements

***

#### **`V 1.0.10863`**

**November 21, 2023**\
– Regular product stability and performance improvements

***

#### **`V 1.0.10603`**

**October 31, 2023**\
– Regular product stability and performance improvements

***

#### **`V 1.0.10084`**

**September 24, 2023**\
– Shadow IT: Added new user login detections for Dropbox, Box, AWS, and Slack\
– Regular product stability and performance improvements

***

#### **`V 1.0.9969`**

**September 18, 2023**\
– Fixed certificate management for Firefox to enable it to use OS cert store\
– Regular product stability and performance improvements

***

#### **`V 1.0.9723`**

**August 24, 2023**\
– Regular product stability and performance improvements

***

#### **`V 1.0.9632`**

**August 18, 2023**\
– Fixed intermittent internet and Wi-Fi connectivity issues\
– Regular product stability and performance improvements

***

#### – Regular product stability and performance improvements<br>

#### **`V 1.0.9435`**

**August 3, 2023**\
– Fixed WebSocket Connectivity issues\
– Fixed specific scenarios where an OIDC pop-up appears on the system restart\
– Regular product stability and performance improvements

***

#### **`V 1.0.8996`**

**June 28, 2023**\
– Fixed Wi-Fi connectivity and Endpoint disabling issues in specific scenarios\
– Regular product stability and performance improvements

***

#### **`V 1.0.8840`**

**June 16, 2023**\
– Fixed problem of block pages not appearing correctly when attempting to access certain social media websites on the Firefox browser\
– Fixed issue where certain features were not working correctly on a few internal websites when accessed through a VPN\
– Regular product stability and performance improvements

***

#### `V 1.0.8666`

**May 29, 2023**\
Regular product stability and performance improvements
{% endtab %}
{% endtabs %}


# Public API Specification

Welcome to the Flightdeck API by `dope.security`. Modify custom categories, get endpoint statuses, and more via API! Stay tuned for upcoming updates that will enhance the capabilities and features of this API.

For details on how to create API client credentials please see [API Client Credentials](/dope.console/settings/api-client-credentials).

## Generate Flightdeck API access token

> Use this API to generate an access token for use with the Flightdeck API. A valid access token returned from\
> this API is required in all other Flightdeck API calls.\
> \
> Token generation is based on the OAuth 2.0 Client Credentials Flow. The returned token is used within the\
> HTTP Authorization header as follows:\
> \
> \`Authorization: Bearer \<access token>\`\
> \
> Note:\
> \- The required \`client\_id\` and \`client\_secret\` are created by an admin via the dope console.\
> \- Returned access tokens are valid for a limited time period. Clients must check the \`expires\_in\` value in\
> the response to generate a new access token before the current one expires.\
> \- The OAuth scopes parameter is not supported and if provided will be ignored. The scopes returned in the access\
> token are set directly by the authorization server.<br>

```json
{"openapi":"3.0.3","info":{"title":"Flightdeck - dope.security - Public API specification","version":"1.0.3"},"tags":[{"name":"Authorization","description":"Everything about authorizing calls to Flightdeck"}],"servers":[{"url":"https://api.flightdeck.dope.security/v1"}],"paths":{"/partner/oauth/token":{"post":{"tags":["Authorization"],"summary":"Generate Flightdeck API access token","description":"Use this API to generate an access token for use with the Flightdeck API. A valid access token returned from\nthis API is required in all other Flightdeck API calls.\n\nToken generation is based on the OAuth 2.0 Client Credentials Flow. The returned token is used within the\nHTTP Authorization header as follows:\n\n`Authorization: Bearer <access token>`\n\nNote:\n- The required `client_id` and `client_secret` are created by an admin via the dope console.\n- Returned access tokens are valid for a limited time period. Clients must check the `expires_in` value in\nthe response to generate a new access token before the current one expires.\n- The OAuth scopes parameter is not supported and if provided will be ignored. The scopes returned in the access\ntoken are set directly by the authorization server.\n","requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"grant_type":{"type":"string","description":"The type of grant requested. You must set this to `client_credentials`","enum":["client_credentials"]},"client_id":{"type":"string","description":"Your application's Client ID."},"client_secret":{"type":"string","description":"Your application's Client Secret."}},"required":["grant_type","client_id","client_secret"]}}}},"responses":{"200":{"description":"OK","content":{"application/json":{"schema":{"type":"object","properties":{"access_token":{"type":"string","description":"The new access token."},"token_type":{"type":"string","enum":["bearer"],"description":"The type of token returned."},"expires_in":{"type":"number","description":"The expiration time of the new access token in seconds."}},"required":["access_token","token_type","expires_in"]}}}},"400":{"description":"Bad request","content":{"application/json":{"schema":{"$ref":"#/components/schemas/OAuthError"}}}},"401":{"description":"Client not authorized","content":{"application/json":{"schema":{"$ref":"#/components/schemas/OAuthError"}}}},"500":{"description":"Internal server error.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/OAuthError"}}}}}}}},"components":{"schemas":{"OAuthError":{"type":"object","description":"The error response related OAuth tokens","properties":{"error":{"type":"string","description":"Specifies the OAuth error code string when the request for a token fails."}},"required":["error"]}}}}
```

## List and Search Endpoints

> Use this API to get a list of all endpoints, or search for those matching a query parameter.\
> \
> Note:\
> \- To return a list of all endpoints do not include any additional parameter.\
> \- Only one of the optional parameters is allowed to be specified per request.\
> \- Results are returned in pages using cursor based pagination and ordered by the \`lastSeen\` property.<br>

```json
{"openapi":"3.0.3","info":{"title":"Flightdeck - dope.security - Public API specification","version":"1.0.3"},"tags":[{"name":"Endpoints","description":"Everything about your endpoints"}],"servers":[{"url":"https://api.flightdeck.dope.security/v1"}],"security":[{"BearerAuth":[]}],"components":{"securitySchemes":{"BearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"JWT"}},"parameters":{"PaginationFirst":{"in":"query","name":"first","description":"An optional pagination param that states the number of records requested from the **start** of the `cursor`. The default value is **50**.","required":false,"schema":{"type":"integer","default":50}},"PaginationAfter":{"in":"query","name":"after","description":"An optional pagination cursor. Pass the `endCursor` from the previous response's `pageInfo` to fetch the next page. Check `hasNextPage` in the previous response's `pageInfo` to determine whether more records are available.","required":false,"schema":{"type":"string"}}},"schemas":{"PaginationResponse":{"type":"object","description":"Information about current and next page for cursor based pagination","properties":{"endCursor":{"type":"string","description":"Opaque string representing a cursor to the last record returned in the response. Used for requesting the next page."},"hasNextPage":{"type":"boolean","description":"indicates if there is another page of data to fetch or not"}},"required":["endCursor","hasNextPage"]},"Endpoint":{"type":"object","properties":{"adminSetState":{"$ref":"#/components/schemas/AdminSetState"},"agentUUID":{"type":"string","format":"uuid","description":"the unique id of the endpoint"},"userUUID":{"type":"string","format":"uuid","description":"the unique id of the active user on the endpoint"},"agentVersion":{"type":"string","description":"the current version of the endpoint"},"binaryType":{"type":"string","description":"type of ISA for computer processors"},"cityName":{"type":"string","description":"the name of the city where the endpoint is located"},"region":{"type":"string","description":"the name of the region where the endpoint is located"},"countryName":{"type":"string","description":"the name of the country where the endpoint is located"},"cpuFamily":{"type":"string","description":"the type of CPU on the device hosting the endpoint"},"debugState":{"type":"string","description":"indicates the debug state of the endpoint. 0 means not in debug, 1 means set to debug, 2 means acknowledged receipt of debug request"},"deviceName":{"type":"string","description":"the name of the device hosting the endpoint"},"disableMode":{"type":"boolean","description":"indicates if the endpoint is disabled or not"},"errorMessage":{"type":"string","description":"additional details regarding an error"},"fallbackMode":{"type":"boolean","description":"indicates if the endpoint is in fallback mode"},"configurationLastUpdated":{"type":"string","format":"date-time","description":"the date and time when the endpoint last updated the configuration"},"osVersion":{"type":"string","description":"Operating System version of the device"},"policyName":{"type":"string","description":"name of the policy that is being used by the endpoint"},"realtimeConnection":{"type":"boolean","description":"indicates if the endpoint has an active web-socket connection"},"status":{"type":"string","description":"the current operational status of the endpoint"},"lastSeen":{"type":"string","format":"date-time","description":"the date and time when the endpoint was last seen"},"userId":{"type":"string","description":"the user id of the user that is using the endpoint. `userId` for OIDC users is usually their email address."},"emailId":{"type":"string","description":"the email of the user that is using the endpoint"}}},"AdminSetState":{"type":"object","properties":{"enabled":{"type":"boolean","description":"Indicates if endpoint is set to enabled or not by the admin"},"timestamp":{"type":"string","format":"date-time","description":"The timestamp when the admin last set the state of the endpoint"}}},"Errors":{"type":"object","description":"Error response containing a list of errors related to 400 and 500 http status","properties":{"errors":{"type":"array","minItems":1,"items":{"type":"object","properties":{"message":{"type":"string","description":"Error message"},"details":{"description":"Optional additional details regarding the error"}},"required":["message"]}}}}}},"paths":{"/endpoints/search":{"get":{"summary":"List and Search Endpoints","description":"Use this API to get a list of all endpoints, or search for those matching a query parameter.\n\nNote:\n- To return a list of all endpoints do not include any additional parameter.\n- Only one of the optional parameters is allowed to be specified per request.\n- Results are returned in pages using cursor based pagination and ordered by the `lastSeen` property.\n","tags":["Endpoints"],"parameters":[{"in":"query","name":"id","description":"Broad search query across endpoints by device, user and email identities that contain this string (case-insensitive)","required":false,"schema":{"type":"string"}},{"in":"query","name":"emailId","description":"Search by email ids that contain this string (case-insensitive)","required":false,"schema":{"type":"string"}},{"in":"query","name":"deviceName","description":"Search by device names that contain this string (case-insensitive)","required":false,"schema":{"type":"string"}},{"in":"query","name":"userId","description":"Search by user ids that contain this string (case-insensitive). `userId` for OIDC users is usually their email address.","required":false,"schema":{"type":"string"}},{"in":"query","name":"osVersion","description":"Filter by this exact device OS version string","required":false,"schema":{"type":"string"}},{"in":"query","name":"status","description":"Filter by this exact set of status'","required":false,"schema":{"type":"array","items":{"type":"string","enum":["healthy","error","dormant","disabled"]}},"explode":false},{"in":"query","name":"debugState","description":"Filter by this exact set of debug states.\n0 means not in debug\n1 means debug request sent to endpoint\n2 means debug request acknowledged by endpoint\n","required":false,"schema":{"type":"array","items":{"type":"string","enum":["0","1","2"]}},"explode":false},{"in":"query","name":"fallbackMode","description":"Filter by the fallback mode","required":false,"schema":{"type":"string","enum":["true","false"]}},{"in":"query","name":"locationId","description":"Filter by this exact location id - with an underscore separating the case sensitive city and country values e.g. \"City_Country\"","required":false,"schema":{"type":"string"}},{"in":"query","name":"agentVersion","description":"Filter by this exact agent version","required":false,"schema":{"type":"string"}},{"$ref":"#/components/parameters/PaginationFirst"},{"$ref":"#/components/parameters/PaginationAfter"},{"in":"query","name":"order","description":"The direction of the sort by the `lastSeen` property. The default is to sort by descending","required":false,"schema":{"type":"string","enum":["desc","asc"]}}],"responses":{"200":{"description":"OK","content":{"application/json":{"schema":{"type":"object","properties":{"data":{"type":"object","properties":{"pageInfo":{"$ref":"#/components/schemas/PaginationResponse"},"endpoints":{"type":"array","items":{"$ref":"#/components/schemas/Endpoint"}}}}}}}}},"400":{"description":"Bad request","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"403":{"description":"Access denied","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"500":{"description":"Internal server error.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}}}}}}}
```

## List Policies

> Use this API to get a paginated list of all your policies, ordered by policy name.\
> \
> Each item includes the policy name, last-modified timestamp, SSL inspection status, and\
> the number of conflicting assignments.\
> \
> The \`sslInspection\` field returns the effective value (\`enabled\` or \`disabled\`). If SSL\
> inspection is not explicitly configured on a policy, the value is inherited from the Base Policy.\
> \
> Results are returned in pages using cursor-based pagination.<br>

```json
{"openapi":"3.0.3","info":{"title":"Flightdeck - dope.security - Public API specification","version":"1.0.3"},"tags":[{"name":"Policies","description":"Everything about your Policies"}],"servers":[{"url":"https://api.flightdeck.dope.security/v1"}],"security":[{"BearerAuth":[]}],"components":{"securitySchemes":{"BearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"JWT"}},"parameters":{"PaginationFirst":{"in":"query","name":"first","description":"An optional pagination param that states the number of records requested from the **start** of the `cursor`. The default value is **50**.","required":false,"schema":{"type":"integer","default":50}},"PaginationAfter":{"in":"query","name":"after","description":"An optional pagination cursor. Pass the `endCursor` from the previous response's `pageInfo` to fetch the next page. Check `hasNextPage` in the previous response's `pageInfo` to determine whether more records are available.","required":false,"schema":{"type":"string"}}},"schemas":{"Policy":{"type":"object","description":"Summary of a policy","properties":{"policyName":{"type":"string","description":"Unique name of the policy within the tenant"},"updatedAt":{"type":"string","format":"date-time","description":"ISO-8601 timestamp of the last policy modification"},"sslInspection":{"type":"string","enum":["enabled","disabled"],"description":"Effective SSL inspection status for this policy.\nIf SSL inspection is not explicitly configured on this policy, the value is\ninherited from the Base Policy.\n"},"clashCount":{"type":"integer","description":"Number of users/groups who have this policy as a conflicting assignment. Not present for the Base Policy."}},"required":["policyName","updatedAt","sslInspection"]},"PaginationResponse":{"type":"object","description":"Information about current and next page for cursor based pagination","properties":{"endCursor":{"type":"string","description":"Opaque string representing a cursor to the last record returned in the response. Used for requesting the next page."},"hasNextPage":{"type":"boolean","description":"indicates if there is another page of data to fetch or not"}},"required":["endCursor","hasNextPage"]},"Errors":{"type":"object","description":"Error response containing a list of errors related to 400 and 500 http status","properties":{"errors":{"type":"array","minItems":1,"items":{"type":"object","properties":{"message":{"type":"string","description":"Error message"},"details":{"description":"Optional additional details regarding the error"}},"required":["message"]}}}}}},"paths":{"/policies":{"get":{"summary":"List Policies","description":"Use this API to get a paginated list of all your policies, ordered by policy name.\n\nEach item includes the policy name, last-modified timestamp, SSL inspection status, and\nthe number of conflicting assignments.\n\nThe `sslInspection` field returns the effective value (`enabled` or `disabled`). If SSL\ninspection is not explicitly configured on a policy, the value is inherited from the Base Policy.\n\nResults are returned in pages using cursor-based pagination.\n","tags":["Policies"],"parameters":[{"$ref":"#/components/parameters/PaginationFirst"},{"$ref":"#/components/parameters/PaginationAfter"},{"in":"query","name":"order","description":"Sort order for policy names. Defaults to `asc`.","required":false,"schema":{"type":"string","enum":["asc","desc"],"default":"asc"}}],"responses":{"200":{"description":"OK","content":{"application/json":{"schema":{"type":"object","properties":{"data":{"type":"object","properties":{"policies":{"type":"array","items":{"$ref":"#/components/schemas/Policy"}},"pageInfo":{"$ref":"#/components/schemas/PaginationResponse"}},"required":["policies","pageInfo"]}},"required":["data"]}}}},"400":{"description":"Bad request","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"403":{"description":"Access denied","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"500":{"description":"Internal server error.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}}}}}}}
```

## Create a Policy

> Use this API to create a new policy.\
> \
> Specify the name of the policy in the path parameter (\`policy\_name\`).\
> \
> If the policy already exists, a \`400\` error is returned.\
> \
> Validation rules for \`policy\_name\`:\
> \- Must not be empty or whitespace-only\
> \- Must not contain leading or trailing whitespace\
> \- Maximum length of 32 characters\
> \- Must not contain any of the following characters: \`# ! @ $ % ^ \* ? . / \\\`<br>

```json
{"openapi":"3.0.3","info":{"title":"Flightdeck - dope.security - Public API specification","version":"1.0.3"},"tags":[{"name":"Policies","description":"Everything about your Policies"}],"servers":[{"url":"https://api.flightdeck.dope.security/v1"}],"security":[{"BearerAuth":[]}],"components":{"securitySchemes":{"BearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"SuccessMessage":{"type":"object","description":"A simple message response indicating a successful operation","properties":{"message":{"type":"string","description":"Simple success message"}},"required":["message"]},"Errors":{"type":"object","description":"Error response containing a list of errors related to 400 and 500 http status","properties":{"errors":{"type":"array","minItems":1,"items":{"type":"object","properties":{"message":{"type":"string","description":"Error message"},"details":{"description":"Optional additional details regarding the error"}},"required":["message"]}}}}}},"paths":{"/policies/{policy_name}":{"post":{"summary":"Create a Policy","description":"Use this API to create a new policy.\n\nSpecify the name of the policy in the path parameter (`policy_name`).\n\nIf the policy already exists, a `400` error is returned.\n\nValidation rules for `policy_name`:\n- Must not be empty or whitespace-only\n- Must not contain leading or trailing whitespace\n- Maximum length of 32 characters\n- Must not contain any of the following characters: `# ! @ $ % ^ * ? . / \\`\n","tags":["Policies"],"parameters":[{"in":"path","name":"policy_name","required":true,"description":"The name of the policy to create","schema":{"type":"string","minLength":1,"maxLength":32,"pattern":"^[^#!@$%^*?./\\\\]+$"}}],"responses":{"200":{"description":"OK","content":{"application/json":{"schema":{"$ref":"#/components/schemas/SuccessMessage"}}}},"400":{"description":"Bad request - invalid policy name or policy already exists","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"403":{"description":"Unauthorized access","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"500":{"description":"Internal server error.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}}}}}}}
```

## Delete a Policy

> Use this API to delete a custom policy by name.\
> This removes the policy and unassigns all users and groups from the policy.\
> \
> The Base Policy cannot be deleted.<br>

```json
{"openapi":"3.0.3","info":{"title":"Flightdeck - dope.security - Public API specification","version":"1.0.3"},"tags":[{"name":"Policies","description":"Everything about your Policies"}],"servers":[{"url":"https://api.flightdeck.dope.security/v1"}],"security":[{"BearerAuth":[]}],"components":{"securitySchemes":{"BearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"SuccessMessage":{"type":"object","description":"A simple message response indicating a successful operation","properties":{"message":{"type":"string","description":"Simple success message"}},"required":["message"]},"Errors":{"type":"object","description":"Error response containing a list of errors related to 400 and 500 http status","properties":{"errors":{"type":"array","minItems":1,"items":{"type":"object","properties":{"message":{"type":"string","description":"Error message"},"details":{"description":"Optional additional details regarding the error"}},"required":["message"]}}}}}},"paths":{"/policies/{policy_name}":{"delete":{"summary":"Delete a Policy","description":"Use this API to delete a custom policy by name.\nThis removes the policy and unassigns all users and groups from the policy.\n\nThe Base Policy cannot be deleted.\n","tags":["Policies"],"parameters":[{"in":"path","name":"policy_name","description":"The name of the policy to delete","required":true,"schema":{"type":"string"}}],"responses":{"200":{"description":"OK","content":{"application/json":{"schema":{"$ref":"#/components/schemas/SuccessMessage"}}}},"400":{"description":"Bad request. Policy not found or attempted to delete Base Policy.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"403":{"description":"Unauthorized access","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"500":{"description":"Internal server error.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}}}}}}}
```

## Get Policy Content

> Use this API to retrieve the entire content of a policy, including\
> categories and custom categories.\
> \
> When a policy inherits from the base policy, \`inheritsFromBase\` will be \`true\`\
> and the content will reflect the base policy's settings.<br>

```json
{"openapi":"3.0.3","info":{"title":"Flightdeck - dope.security - Public API specification","version":"1.0.3"},"tags":[{"name":"Policies","description":"Everything about your Policies"}],"servers":[{"url":"https://api.flightdeck.dope.security/v1"}],"security":[{"BearerAuth":[]}],"components":{"securitySchemes":{"BearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"PolicyContentResponse":{"type":"object","properties":{"data":{"type":"object","properties":{"categories":{"$ref":"#/components/schemas/CategoryBlock"},"customCategories":{"$ref":"#/components/schemas/CustomCategoryBlock"}},"required":["categories","customCategories"]}},"required":["data"]},"CategoryBlock":{"type":"object","description":"Wrapper for category data with inheritance flag","properties":{"inheritsFromBase":{"type":"boolean","description":"Whether the categories are inherited from the base policy"},"restrictions":{"type":"object","description":"Category restrictions keyed by category name","additionalProperties":{"$ref":"#/components/schemas/CategorySettings"}}},"required":["inheritsFromBase","restrictions"]},"CategorySettings":{"type":"object","description":"Settings for a dope category","properties":{"restriction":{"type":"string","enum":["ALLOW","BLOCK","WARNING"],"description":"The action applied when the category is matched"},"page":{"type":"string","description":"Optional block/warning page identifier"},"description":{"type":"string","description":"Category description"},"exceptions":{"type":"object","description":"Per-entity overrides keyed by entity identifier","additionalProperties":{"$ref":"#/components/schemas/CategoryException"}}},"required":["restriction"]},"CategoryException":{"type":"object","description":"Per-entity override of a category restriction","properties":{"restriction":{"type":"string","enum":["ALLOW","BLOCK","WARNING"],"description":"The action applied for this entity"},"page":{"type":"string","description":"Optional block/warning page identifier"},"name":{"type":"string","description":"Human-readable entity name (returned on read APIs)"},"type":{"type":"string","enum":["users","groups"],"description":"Entity type (returned on read APIs)"}},"required":["restriction"]},"CustomCategoryBlock":{"type":"object","description":"Wrapper for custom category data with inheritance flag","properties":{"inheritsFromBase":{"type":"boolean","description":"Whether the custom categories are inherited from the base policy"},"restrictions":{"type":"object","description":"Custom category restrictions keyed by custom category name","additionalProperties":{"$ref":"#/components/schemas/CustomCategorySettings"}}},"required":["inheritsFromBase","restrictions"]},"CustomCategorySettings":{"type":"object","description":"Settings for a custom category","properties":{"restriction":{"type":"string","enum":["ALLOW","BLOCK","WARNING","IGNORE"],"description":"The action applied when the custom category is matched"},"page":{"type":"string","description":"Optional block/warning page identifier"},"exceptions":{"type":"object","description":"Per-entity overrides keyed by entity identifier","additionalProperties":{"$ref":"#/components/schemas/CategoryException"}}},"required":["restriction"]},"Errors":{"type":"object","description":"Error response containing a list of errors related to 400 and 500 http status","properties":{"errors":{"type":"array","minItems":1,"items":{"type":"object","properties":{"message":{"type":"string","description":"Error message"},"details":{"description":"Optional additional details regarding the error"}},"required":["message"]}}}}}},"paths":{"/policies/{policy_name}/content":{"get":{"summary":"Get Policy Content","description":"Use this API to retrieve the entire content of a policy, including\ncategories and custom categories.\n\nWhen a policy inherits from the base policy, `inheritsFromBase` will be `true`\nand the content will reflect the base policy's settings.\n","tags":["Policies"],"parameters":[{"in":"path","name":"policy_name","required":true,"description":"The name of the policy to retrieve content for","schema":{"type":"string"}}],"responses":{"200":{"description":"OK","content":{"application/json":{"schema":{"$ref":"#/components/schemas/PolicyContentResponse"}}}},"400":{"description":"Bad request","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"403":{"description":"Unauthorized access","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"500":{"description":"Internal server error.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}}}}}}}
```

## Update Policy Content Restrictions

> Use this API to update restrictions on dope and custom categories for a policy.\
> \
> A single call may update restrictions on any combination of dope\
> and custom categories. Only submitted categories will be updated -\
> any category not included in the request will be left unchanged.\
> \
> This API also resets categories back to inheriting from base.\
> Both dope categories and custom categories inherit from base\
> (and are reset) as a whole by sending \`{inheritsFromBase:true}\` in the payload.<br>

```json
{"openapi":"3.0.3","info":{"title":"Flightdeck - dope.security - Public API specification","version":"1.0.3"},"tags":[{"name":"Policies","description":"Everything about your Policies"}],"servers":[{"url":"https://api.flightdeck.dope.security/v1"}],"security":[{"BearerAuth":[]}],"components":{"securitySchemes":{"BearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"PolicyContentRestrictionsRequest":{"type":"object","description":"Request body for updating restrictions on dope and custom categories","properties":{"data":{"type":"object","properties":{"categories":{"oneOf":[{"type":"object","additionalProperties":{"$ref":"#/components/schemas/CategoryRestrictionUpdate"}},{"$ref":"#/components/schemas/BaseInheritance"}],"description":"Restriction updates keyed by category name, or BaseInheritance to reset to base."},"customCategories":{"oneOf":[{"type":"object","additionalProperties":{"$ref":"#/components/schemas/CustomCategoryRestrictionUpdate"}},{"$ref":"#/components/schemas/BaseInheritance"}],"description":"Restriction updates keyed by custom category name, or BaseInheritance to reset to base."}}}},"required":["data"]},"CategoryRestrictionUpdate":{"type":"object","description":"Category restriction settings used in write operations","properties":{"restriction":{"type":"string","enum":["ALLOW","BLOCK","WARNING"],"description":"Action applied when the category is matched"},"page":{"type":"string","description":"Optional page identifier. Use with BLOCK and WARNING restrictions."}},"required":["restriction"]},"BaseInheritance":{"type":"object","description":"Signals that settings are inherited from the base policy","properties":{"inheritsFromBase":{"type":"boolean","enum":[true],"description":"Always `true`. Signals that settings are inherited from the base policy."}},"required":["inheritsFromBase"]},"CustomCategoryRestrictionUpdate":{"type":"object","description":"Custom category restriction settings used in write operations","properties":{"restriction":{"type":"string","enum":["ALLOW","BLOCK","WARNING","IGNORE"],"description":"Custom categories can be ignored, in addition to regular restrictions"},"page":{"type":"string","description":"Optional page identifier. Use with BLOCK and WARNING restrictions."}},"required":["restriction"]},"SuccessMessage":{"type":"object","description":"A simple message response indicating a successful operation","properties":{"message":{"type":"string","description":"Simple success message"}},"required":["message"]},"Errors":{"type":"object","description":"Error response containing a list of errors related to 400 and 500 http status","properties":{"errors":{"type":"array","minItems":1,"items":{"type":"object","properties":{"message":{"type":"string","description":"Error message"},"details":{"description":"Optional additional details regarding the error"}},"required":["message"]}}}}}},"paths":{"/policies/{policy_name}/content/restrictions":{"put":{"summary":"Update Policy Content Restrictions","description":"Use this API to update restrictions on dope and custom categories for a policy.\n\nA single call may update restrictions on any combination of dope\nand custom categories. Only submitted categories will be updated -\nany category not included in the request will be left unchanged.\n\nThis API also resets categories back to inheriting from base.\nBoth dope categories and custom categories inherit from base\n(and are reset) as a whole by sending `{inheritsFromBase:true}` in the payload.\n","tags":["Policies"],"parameters":[{"in":"path","name":"policy_name","required":true,"description":"The name of the policy to update restrictions for","schema":{"type":"string"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/PolicyContentRestrictionsRequest"}}}},"responses":{"200":{"description":"OK","content":{"application/json":{"schema":{"$ref":"#/components/schemas/SuccessMessage"}}}},"400":{"description":"Bad request","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"403":{"description":"Unauthorized access","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"500":{"description":"Internal server error.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}}}}}}}
```

## Update Policy Content Exceptions

> Use this API to update user/group-level exceptions on dope and custom categories for a policy.\
> \
> Exceptions are per-user/group overrides of a category's restriction.\
> Each exception is keyed by the user or group identifier (e.g. email address) within a category.\
> \
> A single request can update exceptions across multiple dope and custom categories.\
> Categories not included in the request remain unchanged. For each category provided, the submitted\
> exception set is treated as the complete source of truth and fully replaces any existing exceptions.\
> Any existing entries not included in the request for that category will be removed.\
> To remove all exceptions from a category, pass an empty object \`{}\` as its value.\
> \
> All user and group identifiers are validated against the tenant directory.\
> If any identifier cannot be resolved, the request fails with a \`400 Bad Request\`,\
> and the response includes details of the invalid entries.<br>

```json
{"openapi":"3.0.3","info":{"title":"Flightdeck - dope.security - Public API specification","version":"1.0.3"},"tags":[{"name":"Policies","description":"Everything about your Policies"}],"servers":[{"url":"https://api.flightdeck.dope.security/v1"}],"security":[{"BearerAuth":[]}],"components":{"securitySchemes":{"BearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"PolicyContentExceptionsRequest":{"type":"object","description":"Request body for updating user/group exceptions on categories","properties":{"data":{"type":"object","properties":{"categories":{"type":"object","description":"Exception updates keyed first by category name, then by user or group identifier.","additionalProperties":{"type":"object","additionalProperties":{"$ref":"#/components/schemas/CategoryExceptionUpdate"}}},"customCategories":{"type":"object","description":"Exception updates keyed first by custom category name, then by user or group identifier.","additionalProperties":{"type":"object","additionalProperties":{"$ref":"#/components/schemas/CategoryExceptionUpdate"}}}}}},"required":["data"]},"CategoryExceptionUpdate":{"type":"object","description":"Exception settings used in write operations","properties":{"restriction":{"type":"string","enum":["ALLOW","BLOCK","WARNING"],"description":"The action applied for this user or group"},"page":{"type":"string","description":"Optional page identifier. Use with BLOCK and WARNING restrictions."}},"required":["restriction"]},"SuccessMessage":{"type":"object","description":"A simple message response indicating a successful operation","properties":{"message":{"type":"string","description":"Simple success message"}},"required":["message"]},"Errors":{"type":"object","description":"Error response containing a list of errors related to 400 and 500 http status","properties":{"errors":{"type":"array","minItems":1,"items":{"type":"object","properties":{"message":{"type":"string","description":"Error message"},"details":{"description":"Optional additional details regarding the error"}},"required":["message"]}}}}}},"paths":{"/policies/{policy_name}/content/exceptions":{"put":{"summary":"Update Policy Content Exceptions","description":"Use this API to update user/group-level exceptions on dope and custom categories for a policy.\n\nExceptions are per-user/group overrides of a category's restriction.\nEach exception is keyed by the user or group identifier (e.g. email address) within a category.\n\nA single request can update exceptions across multiple dope and custom categories.\nCategories not included in the request remain unchanged. For each category provided, the submitted\nexception set is treated as the complete source of truth and fully replaces any existing exceptions.\nAny existing entries not included in the request for that category will be removed.\nTo remove all exceptions from a category, pass an empty object `{}` as its value.\n\nAll user and group identifiers are validated against the tenant directory.\nIf any identifier cannot be resolved, the request fails with a `400 Bad Request`,\nand the response includes details of the invalid entries.\n","tags":["Policies"],"parameters":[{"in":"path","name":"policy_name","required":true,"description":"The name of the policy to update exceptions for","schema":{"type":"string"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"$ref":"#/components/schemas/PolicyContentExceptionsRequest"}}}},"responses":{"200":{"description":"OK","content":{"application/json":{"schema":{"$ref":"#/components/schemas/SuccessMessage"}}}},"400":{"description":"Bad request","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"403":{"description":"Unauthorized access","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"500":{"description":"Internal server error.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}}}}}}}
```

## Get Policy Assignments

> Use this API to get the users and groups assigned to a policy.<br>

```json
{"openapi":"3.0.3","info":{"title":"Flightdeck - dope.security - Public API specification","version":"1.0.3"},"tags":[{"name":"Policies","description":"Everything about your Policies"}],"servers":[{"url":"https://api.flightdeck.dope.security/v1"}],"security":[{"BearerAuth":[]}],"components":{"securitySchemes":{"BearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"AssignedUser":{"type":"object","description":"A user assigned to a policy","properties":{"email":{"type":"string","description":"Email address of the assigned user"},"name":{"type":"string","description":"Display name of the assigned user"}},"required":["email","name"]},"AssignedGroup":{"type":"object","description":"A group assigned to a policy","properties":{"email":{"type":"string","description":"Email address of the assigned group"},"name":{"type":"string","description":"Display name of the assigned group"},"membersCount":{"type":"integer","description":"Number of members in the group"}},"required":["email","name","membersCount"]},"Errors":{"type":"object","description":"Error response containing a list of errors related to 400 and 500 http status","properties":{"errors":{"type":"array","minItems":1,"items":{"type":"object","properties":{"message":{"type":"string","description":"Error message"},"details":{"description":"Optional additional details regarding the error"}},"required":["message"]}}}}}},"paths":{"/policies/{policy_name}/assignments":{"get":{"summary":"Get Policy Assignments","description":"Use this API to get the users and groups assigned to a policy.\n","tags":["Policies"],"parameters":[{"in":"path","name":"policy_name","required":true,"description":"The name of the policy to get assignments for","schema":{"type":"string"}}],"responses":{"200":{"description":"OK","content":{"application/json":{"schema":{"type":"object","properties":{"data":{"type":"object","properties":{"users":{"type":"array","items":{"$ref":"#/components/schemas/AssignedUser"}},"groups":{"type":"array","items":{"$ref":"#/components/schemas/AssignedGroup"}}},"required":["users","groups"]}},"required":["data"]}}}},"400":{"description":"Bad request","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"403":{"description":"Access denied","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"500":{"description":"Internal server error.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}}}}}}}
```

## Update Policy Assignments

> Use this API to update the users and groups assigned to a policy.\
> \
> Each provided field fully replaces that assignment list. Omitted fields are preserved.\
> Send an empty array to unassign all users or groups.\
> \
> All submitted users/groups must be valid and not assigned to any policy currently. The\
> API will reject such requests and list the invalid or conflicting entries in the response.<br>

```json
{"openapi":"3.0.3","info":{"title":"Flightdeck - dope.security - Public API specification","version":"1.0.3"},"tags":[{"name":"Policies","description":"Everything about your Policies"}],"servers":[{"url":"https://api.flightdeck.dope.security/v1"}],"security":[{"BearerAuth":[]}],"components":{"securitySchemes":{"BearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"SuccessMessage":{"type":"object","description":"A simple message response indicating a successful operation","properties":{"message":{"type":"string","description":"Simple success message"}},"required":["message"]},"Errors":{"type":"object","description":"Error response containing a list of errors related to 400 and 500 http status","properties":{"errors":{"type":"array","minItems":1,"items":{"type":"object","properties":{"message":{"type":"string","description":"Error message"},"details":{"description":"Optional additional details regarding the error"}},"required":["message"]}}}}}},"paths":{"/policies/{policy_name}/assignments":{"put":{"summary":"Update Policy Assignments","description":"Use this API to update the users and groups assigned to a policy.\n\nEach provided field fully replaces that assignment list. Omitted fields are preserved.\nSend an empty array to unassign all users or groups.\n\nAll submitted users/groups must be valid and not assigned to any policy currently. The\nAPI will reject such requests and list the invalid or conflicting entries in the response.\n","tags":["Policies"],"parameters":[{"in":"path","name":"policy_name","required":true,"description":"The name of the policy to update assignments for","schema":{"type":"string"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"users":{"type":"array","description":"User emails to assign. Omit to leave unchanged, send [] to unassign all.","items":{"type":"string"}},"groups":{"type":"array","description":"Group emails to assign. Omit to leave unchanged, send [] to unassign all.","items":{"type":"string"}}}}}}},"responses":{"200":{"description":"OK","content":{"application/json":{"schema":{"$ref":"#/components/schemas/SuccessMessage"}}}},"400":{"description":"Bad request","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"403":{"description":"Access denied","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"500":{"description":"Internal server error.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}}}}}}}
```

## Get URL Bypass

> Use this API to get the URL bypass entries for a policy.\
> \
> The response contains both admin-defined \`custom\` entries and dope-provided\
> \`default\` entries with their per-entry toggle state.\
> \
> When a policy inherits from the base policy, \`inheritsFromBase\` will be \`true\`\
> and the \`custom\` and \`default\` entries will reflect the base policy's settings.<br>

```json
{"openapi":"3.0.3","info":{"title":"Flightdeck - dope.security - Public API specification","version":"1.0.3"},"tags":[{"name":"Policies","description":"Everything about your Policies"}],"servers":[{"url":"https://api.flightdeck.dope.security/v1"}],"security":[{"BearerAuth":[]}],"components":{"securitySchemes":{"BearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"CustomBypassItem":{"type":"object","description":"A custom application bypass entry defined by the admin","properties":{"name":{"type":"string","description":"The application name being bypassed"},"note":{"type":"string","maxLength":256,"description":"Note about this bypass entry"},"updatedBy":{"type":"string","description":"The user who last updated this entry"},"updatedAt":{"type":"string","format":"date-time","description":"ISO-8601 timestamp when this entry was last updated"}},"required":["name","note"]},"DefaultBypassItem":{"type":"object","description":"A read-only bypass entry pre-configured by Dope Security. Default entries cannot be\ncreated or deleted, but partners can set their state to ignored to prevent them from\nbeing enforced.\n","properties":{"name":{"type":"string","description":"The name of the default bypass entry (application name or URL pattern)"},"state":{"type":"string","enum":["applied","ignored"],"description":"Whether this default entry is applied or ignored for the policy"}},"required":["name","state"]},"Errors":{"type":"object","description":"Error response containing a list of errors related to 400 and 500 http status","properties":{"errors":{"type":"array","minItems":1,"items":{"type":"object","properties":{"message":{"type":"string","description":"Error message"},"details":{"description":"Optional additional details regarding the error"}},"required":["message"]}}}}}},"paths":{"/policies/{policy_name}/bypass/urls":{"get":{"summary":"Get URL Bypass","description":"Use this API to get the URL bypass entries for a policy.\n\nThe response contains both admin-defined `custom` entries and dope-provided\n`default` entries with their per-entry toggle state.\n\nWhen a policy inherits from the base policy, `inheritsFromBase` will be `true`\nand the `custom` and `default` entries will reflect the base policy's settings.\n","tags":["Policies"],"parameters":[{"in":"path","name":"policy_name","required":true,"description":"The name of the policy to retrieve the URL bypass for","schema":{"type":"string"}}],"responses":{"200":{"description":"OK","content":{"application/json":{"schema":{"type":"object","properties":{"data":{"type":"object","properties":{"inheritsFromBase":{"type":"boolean","description":"Whether the URL bypass configuration is inherited from the base policy"},"custom":{"type":"array","description":"Custom URL bypass entries defined by the admin","items":{"$ref":"#/components/schemas/CustomBypassItem"}},"default":{"type":"array","description":"Default URL bypass entries with their toggle states","items":{"$ref":"#/components/schemas/DefaultBypassItem"}}},"required":["inheritsFromBase","custom","default"]}},"required":["data"]}}}},"400":{"description":"Bad request","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"403":{"description":"Access denied","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"500":{"description":"Internal server error.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}}}}}}}
```

## Upsert URL Bypass

> Upsert custom URL bypass entries and/or update default URL bypass states for a policy.\
> \
> \*\*Custom entries\*\* are matched by name: matching names are overwritten, unknown names are added.\
> Unmentioned custom entries are preserved.\
> \
> \*\*Default entries\*\* are matched by name: set \`state\` to \`ignored\` to suppress a default entry,\
> or \`applied\` to re-enable it. Unknown default entry names are silently ignored.\
> \
> Pass \`inheritsFromBase: true\` as the entire \`data\` payload to reset the policy to inherit\
> all URL bypass configuration from the base policy (this drops all custom entries and default\
> overrides for this policy).\
> \
> \*\*Detaching from Base\*\*: If a policy inherits from the Base Policy (\`inheritsFromBase: true\`),\
> sending \`custom\` or \`default\` entries will detach it. Base entries are not copied — include any\
> you want to keep in the request. Once detached, further Base Policy changes will no longer\
> propagate to this policy.<br>

```json
{"openapi":"3.0.3","info":{"title":"Flightdeck - dope.security - Public API specification","version":"1.0.3"},"tags":[{"name":"Policies","description":"Everything about your Policies"}],"servers":[{"url":"https://api.flightdeck.dope.security/v1"}],"security":[{"BearerAuth":[]}],"components":{"securitySchemes":{"BearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"BaseInheritance":{"type":"object","description":"Signals that settings are inherited from the base policy","properties":{"inheritsFromBase":{"type":"boolean","enum":[true],"description":"Always `true`. Signals that settings are inherited from the base policy."}},"required":["inheritsFromBase"]},"UrlBypassUpdateBody":{"type":"object","description":"Payload for upserting URL bypass entries. At least one of `custom` or `default` must be provided. Unmentioned custom entries are preserved. Unknown default entry names are silently ignored.\n","properties":{"custom":{"type":"array","description":"Custom URL entries to upsert (matched by name).","items":{"$ref":"#/components/schemas/CustomBypassRequestItem"}},"default":{"type":"array","description":"Default URL entries with updated toggle states (matched by name).","items":{"$ref":"#/components/schemas/DefaultBypassItem"}}}},"CustomBypassRequestItem":{"type":"object","description":"A custom bypass entry for write operations.","properties":{"name":{"type":"string","maxLength":256,"description":"The name of the entity to bypass (application name or URL pattern)"},"note":{"type":"string","maxLength":256,"description":"Optional note about this bypass entry"}},"required":["name"]},"DefaultBypassItem":{"type":"object","description":"A read-only bypass entry pre-configured by Dope Security. Default entries cannot be\ncreated or deleted, but partners can set their state to ignored to prevent them from\nbeing enforced.\n","properties":{"name":{"type":"string","description":"The name of the default bypass entry (application name or URL pattern)"},"state":{"type":"string","enum":["applied","ignored"],"description":"Whether this default entry is applied or ignored for the policy"}},"required":["name","state"]},"SuccessMessage":{"type":"object","description":"A simple message response indicating a successful operation","properties":{"message":{"type":"string","description":"Simple success message"}},"required":["message"]},"Errors":{"type":"object","description":"Error response containing a list of errors related to 400 and 500 http status","properties":{"errors":{"type":"array","minItems":1,"items":{"type":"object","properties":{"message":{"type":"string","description":"Error message"},"details":{"description":"Optional additional details regarding the error"}},"required":["message"]}}}}}},"paths":{"/policies/{policy_name}/bypass/urls":{"put":{"summary":"Upsert URL Bypass","description":"Upsert custom URL bypass entries and/or update default URL bypass states for a policy.\n\n**Custom entries** are matched by name: matching names are overwritten, unknown names are added.\nUnmentioned custom entries are preserved.\n\n**Default entries** are matched by name: set `state` to `ignored` to suppress a default entry,\nor `applied` to re-enable it. Unknown default entry names are silently ignored.\n\nPass `inheritsFromBase: true` as the entire `data` payload to reset the policy to inherit\nall URL bypass configuration from the base policy (this drops all custom entries and default\noverrides for this policy).\n\n**Detaching from Base**: If a policy inherits from the Base Policy (`inheritsFromBase: true`),\nsending `custom` or `default` entries will detach it. Base entries are not copied — include any\nyou want to keep in the request. Once detached, further Base Policy changes will no longer\npropagate to this policy.\n","operationId":"upsertUrlBypass","tags":["Policies"],"parameters":[{"in":"path","name":"policy_name","required":true,"description":"The name of the policy to update URL bypass entries for","schema":{"type":"string"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","required":["data"],"properties":{"data":{"oneOf":[{"$ref":"#/components/schemas/BaseInheritance"},{"$ref":"#/components/schemas/UrlBypassUpdateBody"}]}}}}}},"responses":{"200":{"description":"URL bypass updated successfully","content":{"application/json":{"schema":{"$ref":"#/components/schemas/SuccessMessage"}}}},"400":{"description":"Bad request or policy not found","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"401":{"description":"Unauthorized — missing or invalid bearer token","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"500":{"description":"Internal server error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}}}}}}}
```

## Delete Custom URL Bypass Entries

> Use this API to delete custom URL bypass entries from a policy by name.\
> \
> The operation is idempotent — names that do not exist are silently ignored.\
> \
> Policies that inherit URL bypass from the Base Policy cannot have custom URLs deleted.<br>

```json
{"openapi":"3.0.3","info":{"title":"Flightdeck - dope.security - Public API specification","version":"1.0.3"},"tags":[{"name":"Policies","description":"Everything about your Policies"}],"servers":[{"url":"https://api.flightdeck.dope.security/v1"}],"security":[{"BearerAuth":[]}],"components":{"securitySchemes":{"BearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"SuccessMessage":{"type":"object","description":"A simple message response indicating a successful operation","properties":{"message":{"type":"string","description":"Simple success message"}},"required":["message"]},"Errors":{"type":"object","description":"Error response containing a list of errors related to 400 and 500 http status","properties":{"errors":{"type":"array","minItems":1,"items":{"type":"object","properties":{"message":{"type":"string","description":"Error message"},"details":{"description":"Optional additional details regarding the error"}},"required":["message"]}}}}}},"paths":{"/policies/{policy_name}/bypass/urls":{"delete":{"summary":"Delete Custom URL Bypass Entries","description":"Use this API to delete custom URL bypass entries from a policy by name.\n\nThe operation is idempotent — names that do not exist are silently ignored.\n\nPolicies that inherit URL bypass from the Base Policy cannot have custom URLs deleted.\n","tags":["Policies"],"parameters":[{"in":"path","name":"policy_name","required":true,"description":"The name of the policy to delete URL bypass entries from","schema":{"type":"string"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"data":{"type":"object","properties":{"custom":{"type":"object","properties":{"urls":{"type":"array","items":{"type":"string"},"description":"List of URL names to delete"}},"required":["urls"]}},"required":["custom"]}},"required":["data"]}}}},"responses":{"200":{"description":"OK","content":{"application/json":{"schema":{"$ref":"#/components/schemas/SuccessMessage"}}}},"400":{"description":"Bad request. Policy not found or policy inherits URL bypass from Base Policy.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"403":{"description":"Access denied","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"500":{"description":"Internal server error.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}}}}}}}
```

## Get Application Bypass

> Use this API to get the application bypass entries for a policy.\
> \
> The response contains both admin-defined \`custom\` entries and dope-provided\
> \`default\` entries with their per-entry toggle state, split per platform\
> (\`mac\` and \`windows\`).\
> \
> When a policy inherits from the base policy, \`inheritsFromBase\` will be \`true\`\
> and the \`custom\` and \`default\` entries will reflect the base policy's settings.<br>

```json
{"openapi":"3.0.3","info":{"title":"Flightdeck - dope.security - Public API specification","version":"1.0.3"},"tags":[{"name":"Policies","description":"Everything about your Policies"}],"servers":[{"url":"https://api.flightdeck.dope.security/v1"}],"security":[{"BearerAuth":[]}],"components":{"securitySchemes":{"BearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"CustomBypassItem":{"type":"object","description":"A custom application bypass entry defined by the admin","properties":{"name":{"type":"string","description":"The application name being bypassed"},"note":{"type":"string","maxLength":256,"description":"Note about this bypass entry"},"updatedBy":{"type":"string","description":"The user who last updated this entry"},"updatedAt":{"type":"string","format":"date-time","description":"ISO-8601 timestamp when this entry was last updated"}},"required":["name","note"]},"DefaultBypassItem":{"type":"object","description":"A read-only bypass entry pre-configured by Dope Security. Default entries cannot be\ncreated or deleted, but partners can set their state to ignored to prevent them from\nbeing enforced.\n","properties":{"name":{"type":"string","description":"The name of the default bypass entry (application name or URL pattern)"},"state":{"type":"string","enum":["applied","ignored"],"description":"Whether this default entry is applied or ignored for the policy"}},"required":["name","state"]},"Errors":{"type":"object","description":"Error response containing a list of errors related to 400 and 500 http status","properties":{"errors":{"type":"array","minItems":1,"items":{"type":"object","properties":{"message":{"type":"string","description":"Error message"},"details":{"description":"Optional additional details regarding the error"}},"required":["message"]}}}}}},"paths":{"/policies/{policy_name}/bypass/applications":{"get":{"summary":"Get Application Bypass","description":"Use this API to get the application bypass entries for a policy.\n\nThe response contains both admin-defined `custom` entries and dope-provided\n`default` entries with their per-entry toggle state, split per platform\n(`mac` and `windows`).\n\nWhen a policy inherits from the base policy, `inheritsFromBase` will be `true`\nand the `custom` and `default` entries will reflect the base policy's settings.\n","tags":["Policies"],"parameters":[{"in":"path","name":"policy_name","required":true,"description":"The name of the policy to retrieve the application bypass for","schema":{"type":"string"}}],"responses":{"200":{"description":"OK","content":{"application/json":{"schema":{"type":"object","properties":{"data":{"type":"object","properties":{"inheritsFromBase":{"type":"boolean","description":"Whether the application bypass configuration is inherited from the base policy"},"custom":{"type":"object","description":"Custom application bypass entries defined by the admin","properties":{"mac":{"type":"array","description":"Custom bypass apps on macOS","items":{"$ref":"#/components/schemas/CustomBypassItem"}},"windows":{"type":"array","description":"Custom bypass apps on Windows","items":{"$ref":"#/components/schemas/CustomBypassItem"}}},"required":["mac","windows"]},"default":{"type":"object","description":"Default application bypass entries with their toggle states","properties":{"mac":{"type":"array","description":"Default bypass apps on macOS","items":{"$ref":"#/components/schemas/DefaultBypassItem"}},"windows":{"type":"array","description":"Default bypass apps on Windows","items":{"$ref":"#/components/schemas/DefaultBypassItem"}}},"required":["mac","windows"]}},"required":["inheritsFromBase","custom","default"]}},"required":["data"]}}}},"400":{"description":"Bad request","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"403":{"description":"Access denied","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"500":{"description":"Internal server error.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}}}}}}}
```

## Upsert Application Bypass

> Upsert custom application bypass entries and/or update default application bypass states for a policy.\
> \
> \*\*Custom entries\*\* are matched by name: matching names are overwritten, unknown names are added.\
> Unmentioned custom entries are preserved.\
> \
> \*\*Default entries\*\* are matched by name: set \`state\` to \`ignored\` to suppress a default entry,\
> or \`applied\` to re-enable it. Unknown default entry names are silently ignored.\
> \
> Pass \`inheritsFromBase: true\` as the entire \`data\` payload to reset the policy to inherit\
> all application bypass configuration from the base policy (this drops all custom entries and default\
> overrides for this policy).\
> \
> \*\*Detaching from Base\*\*: If a policy inherits from the Base Policy (\`inheritsFromBase: true\`),\
> sending \`custom\` or \`default\` entries will detach it. Base entries are not copied — include any\
> you want to keep in the request. Once detached, further Base Policy changes will no longer\
> propagate to this policy.<br>

```json
{"openapi":"3.0.3","info":{"title":"Flightdeck - dope.security - Public API specification","version":"1.0.3"},"tags":[{"name":"Policies","description":"Everything about your Policies"}],"servers":[{"url":"https://api.flightdeck.dope.security/v1"}],"security":[{"BearerAuth":[]}],"components":{"securitySchemes":{"BearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"BaseInheritance":{"type":"object","description":"Signals that settings are inherited from the base policy","properties":{"inheritsFromBase":{"type":"boolean","enum":[true],"description":"Always `true`. Signals that settings are inherited from the base policy."}},"required":["inheritsFromBase"]},"ApplicationBypassUpdateBody":{"type":"object","description":"Payload for upserting application bypass entries. At least one of `custom` or `default` must be provided. Under each, at least one of `mac` or `windows` must be provided. Unmentioned custom entries are preserved. Unknown default entry names are silently ignored.\n","properties":{"custom":{"type":"object","description":"Custom application entries to upsert (matched by name), keyed by platform.","properties":{"mac":{"type":"array","description":"Custom bypass apps on macOS.","items":{"$ref":"#/components/schemas/CustomBypassRequestItem"}},"windows":{"type":"array","description":"Custom bypass apps on Windows.","items":{"$ref":"#/components/schemas/CustomBypassRequestItem"}}}},"default":{"type":"object","description":"Default application entries with updated toggle states (matched by name), keyed by platform.","properties":{"mac":{"type":"array","description":"Default bypass apps on macOS.","items":{"$ref":"#/components/schemas/DefaultBypassItem"}},"windows":{"type":"array","description":"Default bypass apps on Windows.","items":{"$ref":"#/components/schemas/DefaultBypassItem"}}}}}},"CustomBypassRequestItem":{"type":"object","description":"A custom bypass entry for write operations.","properties":{"name":{"type":"string","maxLength":256,"description":"The name of the entity to bypass (application name or URL pattern)"},"note":{"type":"string","maxLength":256,"description":"Optional note about this bypass entry"}},"required":["name"]},"DefaultBypassItem":{"type":"object","description":"A read-only bypass entry pre-configured by Dope Security. Default entries cannot be\ncreated or deleted, but partners can set their state to ignored to prevent them from\nbeing enforced.\n","properties":{"name":{"type":"string","description":"The name of the default bypass entry (application name or URL pattern)"},"state":{"type":"string","enum":["applied","ignored"],"description":"Whether this default entry is applied or ignored for the policy"}},"required":["name","state"]},"SuccessMessage":{"type":"object","description":"A simple message response indicating a successful operation","properties":{"message":{"type":"string","description":"Simple success message"}},"required":["message"]},"Errors":{"type":"object","description":"Error response containing a list of errors related to 400 and 500 http status","properties":{"errors":{"type":"array","minItems":1,"items":{"type":"object","properties":{"message":{"type":"string","description":"Error message"},"details":{"description":"Optional additional details regarding the error"}},"required":["message"]}}}}}},"paths":{"/policies/{policy_name}/bypass/applications":{"put":{"summary":"Upsert Application Bypass","description":"Upsert custom application bypass entries and/or update default application bypass states for a policy.\n\n**Custom entries** are matched by name: matching names are overwritten, unknown names are added.\nUnmentioned custom entries are preserved.\n\n**Default entries** are matched by name: set `state` to `ignored` to suppress a default entry,\nor `applied` to re-enable it. Unknown default entry names are silently ignored.\n\nPass `inheritsFromBase: true` as the entire `data` payload to reset the policy to inherit\nall application bypass configuration from the base policy (this drops all custom entries and default\noverrides for this policy).\n\n**Detaching from Base**: If a policy inherits from the Base Policy (`inheritsFromBase: true`),\nsending `custom` or `default` entries will detach it. Base entries are not copied — include any\nyou want to keep in the request. Once detached, further Base Policy changes will no longer\npropagate to this policy.\n","operationId":"upsertApplicationBypass","tags":["Policies"],"parameters":[{"in":"path","name":"policy_name","required":true,"description":"The name of the policy to update application bypass entries for","schema":{"type":"string"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","required":["data"],"properties":{"data":{"oneOf":[{"$ref":"#/components/schemas/BaseInheritance"},{"$ref":"#/components/schemas/ApplicationBypassUpdateBody"}]}}}}}},"responses":{"200":{"description":"Application bypass updated successfully","content":{"application/json":{"schema":{"$ref":"#/components/schemas/SuccessMessage"}}}},"400":{"description":"Bad request or policy not found","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"401":{"description":"Unauthorized — missing or invalid bearer token","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"500":{"description":"Internal server error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}}}}}}}
```

## Delete Custom Application Bypass Entries

> Use this API to delete custom application bypass entries from a policy by name.\
> \
> The operation is idempotent — names that do not exist are silently ignored.\
> \
> At least one of \`mac\` or \`windows\` must be provided.\
> \
> Policies that inherit application bypass from the Base Policy cannot have custom applications deleted.<br>

```json
{"openapi":"3.0.3","info":{"title":"Flightdeck - dope.security - Public API specification","version":"1.0.3"},"tags":[{"name":"Policies","description":"Everything about your Policies"}],"servers":[{"url":"https://api.flightdeck.dope.security/v1"}],"security":[{"BearerAuth":[]}],"components":{"securitySchemes":{"BearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"SuccessMessage":{"type":"object","description":"A simple message response indicating a successful operation","properties":{"message":{"type":"string","description":"Simple success message"}},"required":["message"]},"Errors":{"type":"object","description":"Error response containing a list of errors related to 400 and 500 http status","properties":{"errors":{"type":"array","minItems":1,"items":{"type":"object","properties":{"message":{"type":"string","description":"Error message"},"details":{"description":"Optional additional details regarding the error"}},"required":["message"]}}}}}},"paths":{"/policies/{policy_name}/bypass/applications":{"delete":{"summary":"Delete Custom Application Bypass Entries","description":"Use this API to delete custom application bypass entries from a policy by name.\n\nThe operation is idempotent — names that do not exist are silently ignored.\n\nAt least one of `mac` or `windows` must be provided.\n\nPolicies that inherit application bypass from the Base Policy cannot have custom applications deleted.\n","tags":["Policies"],"parameters":[{"in":"path","name":"policy_name","required":true,"description":"The name of the policy to delete application bypass entries from","schema":{"type":"string"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"data":{"type":"object","properties":{"custom":{"type":"object","properties":{"mac":{"type":"array","items":{"type":"string"},"description":"List of macOS application names to delete"},"windows":{"type":"array","items":{"type":"string"},"description":"List of Windows application names to delete"}}}},"required":["custom"]}},"required":["data"]}}}},"responses":{"200":{"description":"OK","content":{"application/json":{"schema":{"$ref":"#/components/schemas/SuccessMessage"}}}},"400":{"description":"Bad request. Policy not found, validation error, or policy inherits application bypass from Base Policy.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"403":{"description":"Access denied","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"500":{"description":"Internal server error.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}}}}}}}
```

## Get SSL Inspection Configuration

> Use this API to get the SSL inspection configuration for a policy.\
> \
> The response returns \`sslInspection\` as an object containing the resolved\
> \`state\` (always \`enabled\` or \`disabled\`) and \`inheritsFromBase\` indicating\
> whether the policy inherits SSL inspection from the Base Policy.<br>

```json
{"openapi":"3.0.3","info":{"title":"Flightdeck - dope.security - Public API specification","version":"1.0.3"},"tags":[{"name":"Policies","description":"Everything about your Policies"}],"servers":[{"url":"https://api.flightdeck.dope.security/v1"}],"security":[{"BearerAuth":[]}],"components":{"securitySchemes":{"BearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"SslInspectionResponse":{"description":"SSL inspection configuration for a policy.","allOf":[{"$ref":"#/components/schemas/SslInspectionStateBody"},{"type":"object","properties":{"inheritsFromBase":{"type":"boolean","description":"Whether SSL inspection is inherited from the Base Policy."}},"required":["inheritsFromBase"]}]},"SslInspectionStateBody":{"type":"object","description":"Set a custom SSL inspection state on a policy.","properties":{"state":{"type":"string","enum":["enabled","disabled"],"description":"The state of SSL inspection for this policy."}},"required":["state"]},"Errors":{"type":"object","description":"Error response containing a list of errors related to 400 and 500 http status","properties":{"errors":{"type":"array","minItems":1,"items":{"type":"object","properties":{"message":{"type":"string","description":"Error message"},"details":{"description":"Optional additional details regarding the error"}},"required":["message"]}}}}}},"paths":{"/policies/{policy_name}/ssl-inspection":{"get":{"summary":"Get SSL Inspection Configuration","description":"Use this API to get the SSL inspection configuration for a policy.\n\nThe response returns `sslInspection` as an object containing the resolved\n`state` (always `enabled` or `disabled`) and `inheritsFromBase` indicating\nwhether the policy inherits SSL inspection from the Base Policy.\n","tags":["Policies"],"parameters":[{"in":"path","name":"policy_name","required":true,"description":"The name of the policy to retrieve SSL inspection for","schema":{"type":"string"}}],"responses":{"200":{"description":"OK","content":{"application/json":{"schema":{"type":"object","properties":{"data":{"type":"object","properties":{"sslInspection":{"$ref":"#/components/schemas/SslInspectionResponse"}},"required":["sslInspection"]}},"required":["data"]}}}},"400":{"description":"Bad request","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"403":{"description":"Access denied","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"500":{"description":"Internal server error.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}}}}}}}
```

## Update SSL Inspection Configuration

> Use this API to update the SSL inspection configuration for a policy.\
> \
> The request body must be either:\
> \- \`{"state": "enabled" | "disabled"}\` to set a custom state on this policy, OR\
> \- \`{"inheritsFromBase": true}\` to make this policy inherit SSL inspection from the Base Policy.\
> \
> Exactly one of these two shapes is allowed. Anything else (extra fields,\
> both fields, \`inheritsFromBase: false\`) returns \`400\`. The Base Policy\
> cannot inherit from itself; setting \`inheritsFromBase: true\` on the Base\
> Policy returns \`400\`.<br>

```json
{"openapi":"3.0.3","info":{"title":"Flightdeck - dope.security - Public API specification","version":"1.0.3"},"tags":[{"name":"Policies","description":"Everything about your Policies"}],"servers":[{"url":"https://api.flightdeck.dope.security/v1"}],"security":[{"BearerAuth":[]}],"components":{"securitySchemes":{"BearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"SslInspectionStateBody":{"type":"object","description":"Set a custom SSL inspection state on a policy.","properties":{"state":{"type":"string","enum":["enabled","disabled"],"description":"The state of SSL inspection for this policy."}},"required":["state"]},"BaseInheritance":{"type":"object","description":"Signals that settings are inherited from the base policy","properties":{"inheritsFromBase":{"type":"boolean","enum":[true],"description":"Always `true`. Signals that settings are inherited from the base policy."}},"required":["inheritsFromBase"]},"SuccessMessage":{"type":"object","description":"A simple message response indicating a successful operation","properties":{"message":{"type":"string","description":"Simple success message"}},"required":["message"]},"Errors":{"type":"object","description":"Error response containing a list of errors related to 400 and 500 http status","properties":{"errors":{"type":"array","minItems":1,"items":{"type":"object","properties":{"message":{"type":"string","description":"Error message"},"details":{"description":"Optional additional details regarding the error"}},"required":["message"]}}}}}},"paths":{"/policies/{policy_name}/ssl-inspection":{"put":{"summary":"Update SSL Inspection Configuration","description":"Use this API to update the SSL inspection configuration for a policy.\n\nThe request body must be either:\n- `{\"state\": \"enabled\" | \"disabled\"}` to set a custom state on this policy, OR\n- `{\"inheritsFromBase\": true}` to make this policy inherit SSL inspection from the Base Policy.\n\nExactly one of these two shapes is allowed. Anything else (extra fields,\nboth fields, `inheritsFromBase: false`) returns `400`. The Base Policy\ncannot inherit from itself; setting `inheritsFromBase: true` on the Base\nPolicy returns `400`.\n","operationId":"updateSslInspection","tags":["Policies"],"parameters":[{"in":"path","name":"policy_name","required":true,"description":"The name of the policy to update SSL inspection for","schema":{"type":"string"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","required":["data"],"properties":{"data":{"type":"object","properties":{"sslInspection":{"oneOf":[{"$ref":"#/components/schemas/SslInspectionStateBody"},{"$ref":"#/components/schemas/BaseInheritance"}]}},"required":["sslInspection"]}}}}}},"responses":{"200":{"description":"SSL inspection updated successfully","content":{"application/json":{"schema":{"$ref":"#/components/schemas/SuccessMessage"}}}},"400":{"description":"Bad request or policy not found","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"403":{"description":"Access denied","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"500":{"description":"Internal server error.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}}}}}}}
```

## List Custom Categories

> Use this API to get a paginated list of all custom categories.\
> \
> Results are returned in pages using cursor based pagination.<br>

```json
{"openapi":"3.0.3","info":{"title":"Flightdeck - dope.security - Public API specification","version":"1.0.3"},"tags":[{"name":"Custom Categories","description":"Everything about your Custom Categories"}],"servers":[{"url":"https://api.flightdeck.dope.security/v1"}],"security":[{"BearerAuth":[]}],"components":{"securitySchemes":{"BearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"JWT"}},"parameters":{"PaginationFirst":{"in":"query","name":"first","description":"An optional pagination param that states the number of records requested from the **start** of the `cursor`. The default value is **50**.","required":false,"schema":{"type":"integer","default":50}},"PaginationAfter":{"in":"query","name":"after","description":"An optional pagination cursor. Pass the `endCursor` from the previous response's `pageInfo` to fetch the next page. Check `hasNextPage` in the previous response's `pageInfo` to determine whether more records are available.","required":false,"schema":{"type":"string"}}},"schemas":{"PaginationResponse":{"type":"object","description":"Information about current and next page for cursor based pagination","properties":{"endCursor":{"type":"string","description":"Opaque string representing a cursor to the last record returned in the response. Used for requesting the next page."},"hasNextPage":{"type":"boolean","description":"indicates if there is another page of data to fetch or not"}},"required":["endCursor","hasNextPage"]},"Errors":{"type":"object","description":"Error response containing a list of errors related to 400 and 500 http status","properties":{"errors":{"type":"array","minItems":1,"items":{"type":"object","properties":{"message":{"type":"string","description":"Error message"},"details":{"description":"Optional additional details regarding the error"}},"required":["message"]}}}}}},"paths":{"/custom_categories":{"get":{"summary":"List Custom Categories","description":"Use this API to get a paginated list of all custom categories.\n\nResults are returned in pages using cursor based pagination.\n","tags":["Custom Categories"],"parameters":[{"$ref":"#/components/parameters/PaginationFirst"},{"$ref":"#/components/parameters/PaginationAfter"}],"responses":{"200":{"description":"OK","content":{"application/json":{"schema":{"type":"object","properties":{"data":{"type":"object","properties":{"pageInfo":{"$ref":"#/components/schemas/PaginationResponse"},"customCategories":{"type":"array","items":{"type":"string"}}},"required":["pageInfo","customCategories"]}},"required":["data"]}}}},"403":{"description":"Access denied","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"500":{"description":"Internal server error.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}}}}}}}
```

## Create a Custom Category

> Use this API to create a new custom category.\
> \
> Specify the name of the custom category in the path parameter (\`custom\_category\_name\`).\
> \
> If the custom category already exists, a \`400\` error is returned.\
> \
> Validation rules for \`custom\_category\_name\`:\
> \- Must not be empty or whitespace-only\
> \- Must not contain leading or trailing whitespace\
> \- Maximum length of 32 characters\
> \- Must not contain any of the following characters: \`# ! @ $ % ^ \* ? . / \\\`<br>

```json
{"openapi":"3.0.3","info":{"title":"Flightdeck - dope.security - Public API specification","version":"1.0.3"},"tags":[{"name":"Custom Categories","description":"Everything about your Custom Categories"}],"servers":[{"url":"https://api.flightdeck.dope.security/v1"}],"security":[{"BearerAuth":[]}],"components":{"securitySchemes":{"BearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"SuccessMessage":{"type":"object","description":"A simple message response indicating a successful operation","properties":{"message":{"type":"string","description":"Simple success message"}},"required":["message"]},"Errors":{"type":"object","description":"Error response containing a list of errors related to 400 and 500 http status","properties":{"errors":{"type":"array","minItems":1,"items":{"type":"object","properties":{"message":{"type":"string","description":"Error message"},"details":{"description":"Optional additional details regarding the error"}},"required":["message"]}}}}}},"paths":{"/custom_categories/{custom_category_name}":{"post":{"summary":"Create a Custom Category","description":"Use this API to create a new custom category.\n\nSpecify the name of the custom category in the path parameter (`custom_category_name`).\n\nIf the custom category already exists, a `400` error is returned.\n\nValidation rules for `custom_category_name`:\n- Must not be empty or whitespace-only\n- Must not contain leading or trailing whitespace\n- Maximum length of 32 characters\n- Must not contain any of the following characters: `# ! @ $ % ^ * ? . / \\`\n","tags":["Custom Categories"],"parameters":[{"in":"path","name":"custom_category_name","required":true,"description":"The name of the custom category to create","schema":{"type":"string","minLength":1,"maxLength":32,"pattern":"^[^#!@$%^*?./\\\\]+$"}}],"responses":{"200":{"description":"OK","content":{"application/json":{"schema":{"$ref":"#/components/schemas/SuccessMessage"}}}},"400":{"description":"Bad request - invalid custom category name or custom category already exists","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"403":{"description":"Unauthorized access","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"500":{"description":"Internal server error.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}}}}}}}
```

## Delete a Custom Category

> Use this API to delete a single custom category by name.\
> This action will remove the custom category and all of its associated data.<br>

```json
{"openapi":"3.0.3","info":{"title":"Flightdeck - dope.security - Public API specification","version":"1.0.3"},"tags":[{"name":"Custom Categories","description":"Everything about your Custom Categories"}],"servers":[{"url":"https://api.flightdeck.dope.security/v1"}],"security":[{"BearerAuth":[]}],"components":{"securitySchemes":{"BearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"SuccessMessage":{"type":"object","description":"A simple message response indicating a successful operation","properties":{"message":{"type":"string","description":"Simple success message"}},"required":["message"]},"Errors":{"type":"object","description":"Error response containing a list of errors related to 400 and 500 http status","properties":{"errors":{"type":"array","minItems":1,"items":{"type":"object","properties":{"message":{"type":"string","description":"Error message"},"details":{"description":"Optional additional details regarding the error"}},"required":["message"]}}}}}},"paths":{"/custom_categories/{custom_category_name}":{"delete":{"summary":"Delete a Custom Category","description":"Use this API to delete a single custom category by name.\nThis action will remove the custom category and all of its associated data.\n","tags":["Custom Categories"],"parameters":[{"in":"path","name":"custom_category_name","description":"The name of the custom category to delete","required":true,"schema":{"type":"string"}}],"responses":{"200":{"description":"OK","content":{"application/json":{"schema":{"$ref":"#/components/schemas/SuccessMessage"}}}},"400":{"description":"Bad request","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"403":{"description":"Unauthorized access","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"500":{"description":"Internal server error.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}}}}}}}
```

## List all URLs of a Custom Category

> Use this API to get all URLs of an existing custom category.<br>

```json
{"openapi":"3.0.3","info":{"title":"Flightdeck - dope.security - Public API specification","version":"1.0.3"},"tags":[{"name":"Custom Categories","description":"Everything about your Custom Categories"}],"servers":[{"url":"https://api.flightdeck.dope.security/v1"}],"security":[{"BearerAuth":[]}],"components":{"securitySchemes":{"BearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"Errors":{"type":"object","description":"Error response containing a list of errors related to 400 and 500 http status","properties":{"errors":{"type":"array","minItems":1,"items":{"type":"object","properties":{"message":{"type":"string","description":"Error message"},"details":{"description":"Optional additional details regarding the error"}},"required":["message"]}}}}}},"paths":{"/custom_categories/{custom_category_name}/urls":{"get":{"summary":"List all URLs of a Custom Category","description":"Use this API to get all URLs of an existing custom category.\n","tags":["Custom Categories"],"parameters":[{"in":"path","name":"custom_category_name","required":true,"description":"The name of the custom category to get URLs from","schema":{"type":"string"}}],"responses":{"200":{"description":"OK","content":{"application/json":{"schema":{"type":"object","properties":{"data":{"type":"object","properties":{"urls":{"type":"array","items":{"type":"string"}}},"required":["urls"]}},"required":["data"]}}}},"400":{"description":"Bad request","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"403":{"description":"Unauthorized access","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"500":{"description":"Internal server error.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}}}}}}}
```

## Add URLs to a Custom Category

> Use this API to add URLs to an existing custom category.\
> \
> Specify the name of the custom category in the path parameter (\`custom\_category\_name\`)\
> and provide a JSON array of URLs in the request body.\
> \
> Ensure that URLs are properly formatted and included in the array.\
> \
> Please check the docs at <https://inflight.dope.security> for guidelines on URL formatting.\
> \
> If any URL in the list is invalid, the entire request will be rejected.\
> The 400 error response will include the list of invalid URLs in the error details.<br>

```json
{"openapi":"3.0.3","info":{"title":"Flightdeck - dope.security - Public API specification","version":"1.0.3"},"tags":[{"name":"Custom Categories","description":"Everything about your Custom Categories"}],"servers":[{"url":"https://api.flightdeck.dope.security/v1"}],"security":[{"BearerAuth":[]}],"components":{"securitySchemes":{"BearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"SuccessMessage":{"type":"object","description":"A simple message response indicating a successful operation","properties":{"message":{"type":"string","description":"Simple success message"}},"required":["message"]},"Errors":{"type":"object","description":"Error response containing a list of errors related to 400 and 500 http status","properties":{"errors":{"type":"array","minItems":1,"items":{"type":"object","properties":{"message":{"type":"string","description":"Error message"},"details":{"description":"Optional additional details regarding the error"}},"required":["message"]}}}}}},"paths":{"/custom_categories/{custom_category_name}/urls":{"post":{"summary":"Add URLs to a Custom Category","description":"Use this API to add URLs to an existing custom category.\n\nSpecify the name of the custom category in the path parameter (`custom_category_name`)\nand provide a JSON array of URLs in the request body.\n\nEnsure that URLs are properly formatted and included in the array.\n\nPlease check the docs at https://inflight.dope.security for guidelines on URL formatting.\n\nIf any URL in the list is invalid, the entire request will be rejected.\nThe 400 error response will include the list of invalid URLs in the error details.\n","tags":["Custom Categories"],"parameters":[{"in":"path","name":"custom_category_name","required":true,"description":"The name of the custom category to add URLs to","schema":{"type":"string"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"data":{"type":"object","properties":{"urls":{"type":"array","items":{"type":"string"}}}}}}}}},"responses":{"200":{"description":"OK","content":{"application/json":{"schema":{"$ref":"#/components/schemas/SuccessMessage"}}}},"400":{"description":"Bad request","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"403":{"description":"Unauthorized access","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"500":{"description":"Internal server error.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}}}}}}}
```

## Overwrite all URLs of a Custom Category

> Use this API to replace all existing URLs of a custom category with a new list of URLs.\
> \
> Specify the name of the custom category in the path parameter (\`custom\_category\_name\`)\
> and provide a JSON array of URLs in the request body. All existing URLs will be removed\
> and replaced with the provided list.\
> \
> Please check the docs at <https://inflight.dope.security> for guidelines on URL formatting.\
> \
> If any URL in the list is invalid, the entire request will be rejected.\
> The 400 error response will include the list of invalid URLs in the error details.<br>

```json
{"openapi":"3.0.3","info":{"title":"Flightdeck - dope.security - Public API specification","version":"1.0.3"},"tags":[{"name":"Custom Categories","description":"Everything about your Custom Categories"}],"servers":[{"url":"https://api.flightdeck.dope.security/v1"}],"security":[{"BearerAuth":[]}],"components":{"securitySchemes":{"BearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"SuccessMessage":{"type":"object","description":"A simple message response indicating a successful operation","properties":{"message":{"type":"string","description":"Simple success message"}},"required":["message"]},"Errors":{"type":"object","description":"Error response containing a list of errors related to 400 and 500 http status","properties":{"errors":{"type":"array","minItems":1,"items":{"type":"object","properties":{"message":{"type":"string","description":"Error message"},"details":{"description":"Optional additional details regarding the error"}},"required":["message"]}}}}}},"paths":{"/custom_categories/{custom_category_name}/urls":{"put":{"summary":"Overwrite all URLs of a Custom Category","description":"Use this API to replace all existing URLs of a custom category with a new list of URLs.\n\nSpecify the name of the custom category in the path parameter (`custom_category_name`)\nand provide a JSON array of URLs in the request body. All existing URLs will be removed\nand replaced with the provided list.\n\nPlease check the docs at https://inflight.dope.security for guidelines on URL formatting.\n\nIf any URL in the list is invalid, the entire request will be rejected.\nThe 400 error response will include the list of invalid URLs in the error details.\n","tags":["Custom Categories"],"parameters":[{"in":"path","name":"custom_category_name","required":true,"description":"The name of the custom category to overwrite URLs for","schema":{"type":"string"}}],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"data":{"type":"object","properties":{"urls":{"type":"array","items":{"type":"string"}}}}}}}}},"responses":{"200":{"description":"OK","content":{"application/json":{"schema":{"$ref":"#/components/schemas/SuccessMessage"}}}},"400":{"description":"Bad request","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"403":{"description":"Unauthorized access","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"500":{"description":"Internal server error.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}}}}}}}
```

## Delete All URLs from a Custom Category

> Use this API to delete all URLs from an existing custom category.\
> \
> Specify the name of the custom category in the path parameter (\`custom\_category\_name\`).\
> \
> This action will remove all URLs associated with the specified custom category.<br>

```json
{"openapi":"3.0.3","info":{"title":"Flightdeck - dope.security - Public API specification","version":"1.0.3"},"tags":[{"name":"Custom Categories","description":"Everything about your Custom Categories"}],"servers":[{"url":"https://api.flightdeck.dope.security/v1"}],"security":[{"BearerAuth":[]}],"components":{"securitySchemes":{"BearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"SuccessMessage":{"type":"object","description":"A simple message response indicating a successful operation","properties":{"message":{"type":"string","description":"Simple success message"}},"required":["message"]},"Errors":{"type":"object","description":"Error response containing a list of errors related to 400 and 500 http status","properties":{"errors":{"type":"array","minItems":1,"items":{"type":"object","properties":{"message":{"type":"string","description":"Error message"},"details":{"description":"Optional additional details regarding the error"}},"required":["message"]}}}}}},"paths":{"/custom_categories/{custom_category_name}/urls":{"delete":{"summary":"Delete All URLs from a Custom Category","description":"Use this API to delete all URLs from an existing custom category.\n\nSpecify the name of the custom category in the path parameter (`custom_category_name`).\n\nThis action will remove all URLs associated with the specified custom category.\n","tags":["Custom Categories"],"parameters":[{"in":"path","name":"custom_category_name","description":"The name of the custom category to delete all URLs from","required":true,"schema":{"type":"string"}}],"responses":{"200":{"description":"OK","content":{"application/json":{"schema":{"$ref":"#/components/schemas/SuccessMessage"}}}},"400":{"description":"Bad request","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"403":{"description":"Unauthorized access","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"500":{"description":"Internal server error.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}}}}}}}
```

## Delete a specific URL from a Custom Category

> Use this API to delete a specific URL from an existing custom category.\
> \
> Specify the name of the custom category in the path parameter (\`custom\_category\_name\`).\
> \
> Ensure that a given URL is encoded using URL encoding.<br>

```json
{"openapi":"3.0.3","info":{"title":"Flightdeck - dope.security - Public API specification","version":"1.0.3"},"tags":[{"name":"Custom Categories","description":"Everything about your Custom Categories"}],"servers":[{"url":"https://api.flightdeck.dope.security/v1"}],"security":[{"BearerAuth":[]}],"components":{"securitySchemes":{"BearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"SuccessMessage":{"type":"object","description":"A simple message response indicating a successful operation","properties":{"message":{"type":"string","description":"Simple success message"}},"required":["message"]},"Errors":{"type":"object","description":"Error response containing a list of errors related to 400 and 500 http status","properties":{"errors":{"type":"array","minItems":1,"items":{"type":"object","properties":{"message":{"type":"string","description":"Error message"},"details":{"description":"Optional additional details regarding the error"}},"required":["message"]}}}}}},"paths":{"/custom_categories/{custom_category_name}/url/{encoded_url}":{"delete":{"summary":"Delete a specific URL from a Custom Category","description":"Use this API to delete a specific URL from an existing custom category.\n\nSpecify the name of the custom category in the path parameter (`custom_category_name`).\n\nEnsure that a given URL is encoded using URL encoding.\n","tags":["Custom Categories"],"parameters":[{"in":"path","name":"custom_category_name","description":"The name of the custom category to delete given URL from","required":true,"schema":{"type":"string"}},{"in":"path","name":"encoded_url","description":"The URL to be deleted (Ensure that URLs are properly URL-encoded using\nthe UTF8 encoding method)\n","required":true,"schema":{"type":"string"}}],"responses":{"200":{"description":"OK","content":{"application/json":{"schema":{"$ref":"#/components/schemas/SuccessMessage"}}}},"400":{"description":"Bad request","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"403":{"description":"Unauthorized access","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}},"500":{"description":"Internal server error.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Errors"}}}}}}}}}
```

{% file src="/files/v0PwtkhRM3KvlPawPdAq" %}


# msp multi tenant support

Dope Security supports Managed Service Providers (MSPs) that manage security for multiple customers. As an MSP, you can access and manage several customer tenants using a single admin identity, and switch between them without needing separate logins.

## How It Works

Multi-tenant access is achieved by adding your MSP domain email address as an admin to each customer tenant you manage. Once added, that single email can be used to log in and access any tenant it has been granted admin rights to.

## Setting Up a Customer Tenant

To onboard a new customer under your MSP:

{% stepper %}
{% step %}

## Create the tenant using the customer's domain

Each customer tenant must be set up with the customer's own domain — not your MSP domain.
{% endstep %}

{% step %}

## Add your MSP admin email as an admin in the customer's tenant

This grants your MSP admin account access to that tenant, alongside the customer's own admins.
{% endstep %}
{% endstepper %}

Repeat this process for each customer tenant you need to manage.

## Logging In and Switching Between Tenants

When you log into [fly.dope.security](https://fly.dope.security/) using your MSP admin email, you'll be prompted to select which customer tenant you want to access for that session.

If you need to switch tenants during a session:

{% stepper %}
{% step %}

## Select the login icon

Select the login icon in the top-right corner of the screen.
{% endstep %}

{% step %}

## Choose a tenant

Choose the tenant you want to switch to from the list of tenants associated with your MSP admin email.
{% endstep %}
{% endstepper %}

All tenants you've been added to as an admin will appear in this list, letting you move between customer environments without logging out or using multiple credentials.


# msp multi tenant support

Dope Security supports Managed Service Providers (MSPs) that manage security for multiple customers. As an MSP, you can access and manage several customer tenants using a single admin identity, and switch between them without needing separate logins.

## How It Works

Multi-tenant access is achieved by adding your MSP domain email address as an admin to each customer tenant you manage. Once added, that single email can be used to log in and access any tenant it has been granted admin rights to.

## Setting Up a Customer Tenant

To onboard a new customer under your MSP:

1. **Create the tenant using the customer's domain.** Each customer tenant must be set up with the customer's own domain — not your MSP domain.
2. **Add your MSP admin email as an admin in the customer's tenant.** This grants your MSP admin account access to that tenant, alongside the customer's own admins.

Repeat this process for each customer tenant you need to manage.

## Logging In and Switching Between Tenants

When you log into [fly.dope.security](https://fly.dope.security/) using your MSP admin email, you'll be prompted to select which customer tenant you want to access for that session.

If you need to switch tenants during a session:

1. Select the login icon in the top-right corner of the screen.
2. Choose the tenant you want to switch to from the list of tenants associated with your MSP admin email.

All tenants you've been added to as an admin will appear in this list, letting you move between customer environments without logging out or using multiple credentials.


