Skip to main content

Does any one know if there is a way to build Real time access policies based on the referer site? I have a use case where a user is using a web app and trying to upload a document to an S3 bucket and unfortunately it's not pulling any instance information so it's going to a generic url we aren't comfortable with whitelisting but if we could base the access on the referer or the page site that would be something we'd be a little more comfortable with. 

@rfletcher yes, you can.  take a look at the HTTP Header Profile below.  It's a recent feature, so if you do not see it available in your tenant, please contact your customer success manager to enable it.  Once you do, you should be able to use this a finer-grainer control in your policy


 



Reply