On-Device Content Filter - Jamf Safe Internet Documentation

Jamf Safe Internet Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

While gateway-based filtering evaluates network traffic on the cloud, the on-device content filter (ODCF) evaluates network traffic directly on the device. The ODCF is deployed via configuration profile manually or through MDM alongside Secure DNS, and offers more comprehensive filtering options by analyzing traffic at the socket level. It relies less on proxy and DNS resolvers, resulting in low latency.

The ODCF offers greater privacy by inspecting traffic and stripping sensitive data by default before it is reported. It uses Apple's NEFilterProvider, a network framework that uses two extensions, one of which is in a very restrictive sandbox, to pass information. For more information, see NEFilterProvider from the Apple Developer website.

The ODCF supports the following Jamf Protect features, in addition to the features offered by Secure DNS:
  • App blocking

  • IP address-based content filtering and threat prevention

  • Domain and full URL-based content filtering

  • Port and protocol-based content filtering

  • Compatibility with third-party VPN or proxy services, with no possibility of bypass

  • Post-TLS content inspection

  • Identification of traffic source app and app metadata

Compatibility

The ODCF is available for supervised devices using iOS and iPadOS. All devices must have the Jamf Trust app installed.

The ODCF can enforce Jamf Safe Internet policies alongside VPN, proxy, or DNS services from manufacturers other than Jamf. VPN and proxy services do not require any additional configuration. However, to be compatible with a DNS service from another manufacturer, you must first disable the Prohibit Disablement feature. To do this, before pushing the configuration profile to your devices, locate <key>ProhibitDisablement</key> in the configuration profile, and change it from <true/> to <false/>. The most recently deployed DNS service on the device will become the default, unless the DNS service has Prohibit Disablement enabled.
Note:

When you deploy a VPN, proxy, or DNS service from a different manufacturer alongside Jamf Safe Internet ODCF, search rules cannot be enforced and any blocking rules set by the on-device content filter take precedence over those set by the other service.

On-device content filtering can be deployed without Secure DNS using network compatibility mode. For more information, see Activation Profiles in Safe Internet.

ODCF Emergency Controls

Disable ODCF to avoid system disruption when the ODCF extension is not working or your MDM is unavailable. When ODCF is disabled, Jamf Safe Internet delivers the instruction via Apple Push Notification service, bypassing the filter entirely. While ODCF is disabled, content filtering is inactive and users have unrestricted access to all content. Emergency controls apply to devices using ODCF traffic vectoring and with version 11.47 or later of the Jamf Trust app installed.
Note:

Use this only when standard management options are unavailable. If a device does not respond, retry after fifteen minutes.

To disable or enable ODCF, navigate to Devices > Device groups in your Jamf Safe Internet portal.
  • For all devices, select Disable ODCF for all devices or Enable ODCF for all devices from the More actions menu.

  • For an individual group, select Disable ODCF or Enable ODCF from the Manage group menu.

To view the number of devices in a group that have ODCF disabled, select ODCF status from the Manage group menu.