Optional managed Guardian module

Stop malicious destinations at the DNS layer.

Guardian DNS Protection applies managed filtering policy and presents blocked, allowed and monitored activity through participant, business and provider-safe views.

What the service does

Prevent access to known malicious and unwanted destinations before a connection is established.

Guardian DNS Protection combines managed DNS security policy with customer-safe activity, user and device context, operational review and accountable follow-up.

The underlying filtering technology remains a connector. Customers work through Guardian rather than being required to interpret a raw vendor console.

01

Protect

Apply agreed malicious-domain, phishing, command-and-control and category policy at the DNS layer.

02

Understand

Show blocked and allowed activity with available domain, category, user and device context.

03

Respond

Investigate material activity and connect required follow-up to Guardian actions and reporting.

Operational inclusions

Managed DNS protection with practical visibility.

DP

DNS-layer policy

Managed filtering policy for approved users, devices, networks and customer scope.

MB

Malicious-domain blocking

Block known malicious, phishing and command-and-control destinations according to the selected policy and threat intelligence.

CP

Category controls

Apply agreed content and risk-category controls where required by the customer policy.

EV

Event visibility

Search and review blocked, allowed and monitored events using customer-safe fields.

UD

User and device context

Use available identity and device mapping to explain who or what generated an event without exposing unrelated tenant data.

PR

Provider reporting

Providers can review authorised customer activity and status through provider-scoped views.

IN

Investigation support

Material events can be assessed alongside endpoint, dark web, vulnerability, learning and Security Operations context.

AC

Action follow-up

Required policy, user, device or remediation work can be tracked through Guardian All Actions.

RP

Customer-safe reporting

Summaries and activity records support customer reporting without exposing credentials or raw connector data.

Participant, business and provider delivery

Scoped visibility for the people operating or receiving the service.

Participants can review activity attributed to their approved identity and devices without seeing other users or customer data.

Business customers receive organisation-scoped protection status, activity and follow-up information.

Providers can review their own and authorised child-customer DNS Protection activity using provider-safe filtering and drilldowns.

Commercial quantity and deployment design may be based on protected users, devices, sites or an agreed customer estate. The applicable package schedule records the approved model.

Service boundary

DNS Protection depends on approved routing, identity and policy scope.

Protection applies only where DNS traffic is routed through the approved service or the supported endpoint deployment is active. It does not inspect every application payload and is not represented as a replacement for endpoint security, firewalling or Security Operations.

Category policy, exclusions, roaming-device coverage, identity attribution and retention are confirmed before activation. No claim is made that every malicious domain or event will be detected.

Managed DNS security

Define the protected users, devices, sites and policy.

We will confirm deployment, policy categories, exclusions, reporting, retention and operational follow-up for the selected scope.