# Configure plugin settings for web content filtering on Mac

This document helps you configure macOS content filter plugin settings from the Hexnode UEM console.

Web content filtering is an effective tool for regulating access to specific websites from end-users’ devices that could potentially expose them to any risks or harmful content. It can also enhance productivity and improve the user experience by restricting unwanted sites or inappropriate content, thus contributing to a safer and more focused environment.

Hexnode UEM offers the feature to use third-party plug-ins (for example, Forcepoint or Crowdstrike) for advanced content filtering of the web and network data traffic from browsers and sockets on Macs.

 Note:Plug-ins are compatible with devices running **macOS 10.15** or later.

 

Setting up plug-ins on macOS devices
------------------------------------

Follow the steps below to set up plug-ins on your devices,

1. Log in to your **Hexnode UEM** portal.
2. Navigate to the **Policies** tab.
3. Click on **New Policy** to create a new policy and enter the policy name and description (optional) in the provided fields. You can also choose an existing policy.
4. Select **Plug-ins** from **macOS > Web Content Filtering**. Click **Configure**.

 Note:If a System Extensions policy has been configured, the plug-in must be explicitly approved (by specifying the plug-in’s Bundle ID and Team Identifier) in the ***System Extensions*** policy. Failure to do so may result in the plugin being blocked, causing it to not operate as intended.

 

[![Configuring plug-ins for macOS devices in Hexnode UEM.](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2024/03/Plug-In-policy-configuration-1024x770.png)](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2024/03/Plug-In-policy-configuration.png)

Here’s an overview of the plug-in settings and how you can configure them on Mac:

Plug-In Settings DescriptionFilter name Enter a filter name for it to be displayed on the device. Plug-In Bundle ID Select the bundle ID of the plug-in. You can either select the bundle ID from **Select Apps** or specify it explicitly under **Specify Bundle ID**. Server Address Enter the server address for the plug-in which can be provided as an IP address, hostname, or URL. OrganizationEnter the organization name that is associated with the plug-in. UsernameEnter the username of the device user.  Note:Supports the use of wildcards **%name%, %username%, %email%** and **%alternateemail%**.

 

 PasswordEnter the password associated with the user.Certificate Choose the certificate for authentication of the user.Filter browsers Select this option to filter all network traffic transmitted through WebKit-based browsers. Filter socketsSelect this option to filter all network traffic through sockets. The following fields are to be filled,

- ***Socket Bundle ID*** : Enter the bundle ID of the socket filter provider system extension.
- ***Socket designated requirement*** : Enter the designated requirement string of the socket filter provider system extension.

Filter network packetsSelect this option to filter network packets and decide whether to block, allow or delay the packets. The following fields are to be filled,

- ***Packet bundle ID*** : Enter the bundle ID of the packet filter provider system extension.
- ***Packet designated requirement*** : Enter the designated requirement string of the packet filter provider system extension.

Filter gradeSelect the filter grade to set the relative order in which the filters will apply on the network traffic. There are two options to choose from – ***Firewall*** and ***Inspector***.
 Note:Filters of **Firewal**l grade will be applied, before filters with grade of **Inspector**.

 

 Additional vendor configurationsAdd additional key/value pairs required by the plug-in filtering service.Associate the policy with macOS devices
---------------------------------------

If you have not saved the policy yet,

1. Go to **Policy Targets > +Add Devices**. Alternatively, you can choose to associate the policy to either device groups, users, user groups or domains from the left pane.
2. Choose the target device/devices.
3. Click **Ok**. Click **Save**.

If you need to add more devices, click on **+Add Devices** again and repeat the above steps. This won’t affect your previous selections.

If you are on a page that lists the policies,

1. Select a policy.
2. From **Manage** drop-down, choose **Associate Targets**.
3. Choose the target devices and click **Associate**.