Skip to content
Notifications
Clear all

Help: Need to exclude our CEO's laptop from all browsing filters. How do I do that safely?

1 Posts
1 Users
0 Reactions
0 Views
(@crm_hopper_2025)
Estimable Member
Joined: 2 months ago
Posts: 113
Topic starter   [#10186]

Okay, I need to tap into the collective wisdom here because I'm in a classic "C-suite exception" pickle, and my usual CRM migration chaos has nothing on this networking stuff. 😅

We just rolled out Cloudflare One for the whole company, moving from our old janky proxy setup (good riddance). The Gateway policies are fantastic for the sales and support teamsβ€”blocking distractions, tightening security, the usual. But, as the title says, our CEO needs a total hall pass. No filtering, no blocking, just a clean pipe out to the internet. The request is equal parts "I need unfettered access for due diligence" and "I don't want my news sites or, ahem, *certain hobbyist forums* getting flagged."

I get the *why*, but the *how* is making me nervous. I can't just turn off DNS filtering for his device willy-nilly. My brain, scarred by a thousand Salesforce-to-Hubspot migration nightmares, is screaming about creating a security blind spot.

Here's what I'm thinking, but I'd love a sanity check from people who've actually done this:

* I know I can create a **Zero Trust policy using his device's serial number or a client certificate** as the selector. That feels more solid than just an IP address, especially since he's always on the move.
* The plan is to put him in his own **Gateway configuration profile** that has all filtering disabled. Then, a rule that says "If device serial number matches CEO laptop, use this No-Filter profile."
* But what about **logging**? I still need *some* visibility for audit purposes, even if we're not blocking. Can I set it to log all sessions, just not apply any policies?
* Has anyone set up something similar? What were the **unintended consequences**?
* Is there a way to still apply **malware or phishing protection** at the DNS level while stripping out the content/category filtering? Or is that an all-or-nothing per profile?

I'm trying to balance "keep the boss happy" with "don't get us breached." My RevOps heart knows data migration is painful, but at least the rules are clear. This feels like a different kind of risk.

Any real-world workflow reports would be a lifesaver. What policies did you craft? Did you have to explain this to auditors later?



   
Quote