Dear Ravinder Makkar,
Group Policy alone cannot enforce website restrictions for users working from home, because once they leave the corporate network the Fortinet firewall rules no longer apply. Windows Server 2022 Active Directory can push policies, but those policies only govern the local machine and cannot filter outbound traffic directly. To achieve the same control remotely, you need to extend your perimeter enforcement through either a secure web gateway or by tunneling all traffic back into the corporate network. The most common approach is to require VPN connectivity, so that all internet traffic from the laptop routes through the Fortinet firewall, where your existing allow‑list rules continue to apply.
If you want enforcement without VPN, you would need to deploy endpoint agents that integrate with Intune or Defender for Endpoint, which can apply web filtering policies locally. Microsoft Defender for Endpoint supports web content filtering that can be configured via Intune and enforced even off‑network. This way, you can define categories or specific URLs that are permitted, and the agent enforces them regardless of the user’s Wi‑Fi. In practice, the best solution is a hybrid: enforce VPN for sensitive work and configure Defender web filtering for broader compliance, ensuring that your seasonal or remote staff remain under the same restrictions as office users.
If my answer is useful for you, please hit Accept the answer to support me.
Thank you,
QQ.