Skip to main content

Agent DoH — devices

The simplest way to filter laptops: let the DashX agent do it. Each device runs a local DoH proxy and points itself at DashX automatically — no DHCP change, no manual resolver setup, and every device gets its own identity so blocks name the exact machine.

Turn it on

  1. Go to Secure Access → DNS Filtering → Agent DoH.
  2. Click the toggle in the header — it flips between Disabled and Enabled.
  3. You get "Agent DoH enabled — devices with the DashX agent switch over within a few minutes."

Devices appear in the list on their own as they check in. Each row shows the device name, an active / off status badge, a policy select and when it was last seen.

Turning the toggle back off restores each device's original resolver.

Assign a policy per device

Use the select on the device row. Default (auto) means the device follows the org default or whatever User & Group Policy resolves for the signed-in user — which is usually what you want. Pick a named policy only when the machine itself needs different rules regardless of who uses it (a kiosk, a lab box, a server).

Nothing shows up?

MessageWhat it means
"Enable Agent DoH, then devices with the DashX agent appear here automatically."The toggle is still off
"No devices have checked in yet — install/enable the DashX agent on a device."The toggle is on, but no agent has reported. Confirm the agent is online in Fleet

Give it a few minutes — agents pick the change up on their next check-in, not instantly.

Agent DoH vs. network endpoints

  • Agent DoH covers anything with the DashX agent, wherever it is — office, home, hotel Wi-Fi. Per-device identity, per-user attribution. This is the default choice for laptops and servers.
  • Endpoints cover things you cannot install an agent on — printers, cameras, guest Wi-Fi, an entire branch. See Endpoints.

Most organizations run both.

tip

Encrypted DoH also means the filtering decision cannot be stripped by the local network. Pair it with the Filter bypass category on the Policy tab so users cannot switch their browser to a public DoH resolver and walk around the whole thing.