Guide
Restrict network destinations and regions
Apply reviewed destination and regional controls at the appropriate policy scope.
Last reviewed September 12, 2026
Choose a regional network policy
Choose All Regions, United States, or European Union on the Global tab to set the default geographic network boundary for applicable unknown scripts. The choice limits supported outbound requests; it does not establish end-to-end data residency for every service involved.
Procedure
- 1.
Open the correct project and page
Use the project selector to choose the website you intend to review, then open Policies in the left navigation. Confirm the organization, project, and monitored domain before interpreting a record or changing a control.
- 2.
Record the effective policy
Inspect Global, Provider, and Resource layers. Capture both the configured value at each layer and the resolved effective state, together with the critical journeys and current working behavior.
- 3.
All
Trace the relationship from the loading resource to the observed destination or capability. Confirm required service endpoints and regional behavior in representative journeys before restricting access.
- 4.
Validate the effective result
Reload the policy view and confirm the resolved effective state. Exercise every affected critical journey and verify required browser access and network requests before expanding the change.
- 5.
Document approval and recovery
Record the policy layer, previous and new effective values, reason, approver, validation journeys, result, monitoring window, and exact recovery action.
Configure a provider network policy
In a provider policy, choose the applicable network region and either Allow All Domains or Restrict Domains. If restricting, build the approved list from confirmed service destinations, save the override, and test every website journey that depends on that provider.