Home Admin & Settings

Admin & Settings

By KyberGate
13 articles

Block Page Customization

Block Page Customization When KyberGate blocks a website, students see a branded block page explaining why the site was restricted. You can customize this page to match your district's branding and messaging. Overview The KyberGate block page features a clean cream and coral design with the KyberGate shield logo. Administrators can customize several elements to align the page with district identity and communication standards. What You Can Customize Logo and Branding 1. Navigate to Settings → Block Page in the KyberGate admin dashboard 2. Click Upload Logo to replace the default KyberGate shield with your district's logo 3. Supported formats: PNG, JPG, SVG (recommended size: 200×200px) 4. The logo appears centered at the top of the block page Block Message 1. In the Message field, enter the text students will see when a site is blocked 2. Default message: "This website has been blocked by your school's internet filter." 3. You can include the reason for blocking using the {category} variable 4. Example: "This site is blocked under the {category} policy. Contact your teacher if you need access." 5. Maximum message length: 500 characters Colors 1. Background Color — The page background (default: cream #FFF8F0) 2. Accent Color — Used for borders and the banner stripe (default: coral #FF6B6B) 3. Text Color — Primary message text color (default: dark gray #333333) 4. Use the color picker or enter hex values directly Request Access Button 1. Toggle Enable Request Access to show or hide the button 2. When enabled, students can click Request Access to submit a request to their teacher or admin 3. Requests appear in Activity → Access Requests in the dashboard 4. Set the Request Recipient to route requests to specific admin emails 5. Configure Auto-Expire to automatically deny pending requests after a set period (default: 24 hours) Previewing Changes Before saving, click Preview Block Page to see exactly what students will see. The preview opens in a new tab with your current customizations applied. Tips - Keep messages student-friendly — Use clear, non-technical language that students can understand - Include contact info — Tell students who to ask if they need a site unblocked - Test on devices — Preview the block page on an iPad and Chromebook to ensure your logo and colors render correctly on all screen sizes - Use SVG logos — They scale perfectly on all devices and screen resolutions - Request Access workflow — Enable email notifications so admins are alerted immediately when a student requests access Troubleshooting | Issue | Solution | |-------|----------| | Logo appears blurry | Use an SVG file or a PNG at least 400×400px | | Block page shows default branding | Clear the browser cache on the device and reload | | Request Access button not appearing | Ensure the toggle is enabled and save changes | | Colors not updating | Hard-refresh the block page (Ctrl+Shift+R / Cmd+Shift+R) | | Students see a certificate error instead of block page | The KyberGate CA certificate is not installed — see "Certificate Installation Issues" | Related Articles - Managing Content Filtering Policies - Certificate Installation Issues - Device Enrollment and PAC Configuration

Last updated on Apr 17, 2026

Billing and Subscription Management

Billing and Subscription Management KyberGate offers flexible per-device annual subscriptions managed through Stripe. This guide covers available plans, how to manage your subscription, and how to handle upgrades or downgrades. Available Plans KyberGate offers three subscription tiers, all billed per device per year: | Plan | Price | Features | |------|-------|----------| | Basic | $5/device/year | Web filtering, block page, basic reporting, PAC-based proxy filtering | | Pro | $9/device/year | Everything in Basic + advanced analytics, ClassLink/Clever SSO, custom block page branding, Chrome extension support | | Enterprise | $15/device/year | Everything in Pro + priority support, custom integrations, SLA guarantees, dedicated account manager, multi-region proxy routing | All plans include CIPA-compliant filtering, SSL inspection via the KyberGate CA certificate, and HTTPS traffic visibility. Managing Your Subscription Accessing the Billing Portal 1. Log in to the KyberGate Admin Dashboard 2. Navigate to Settings → Billing 3. Click Manage Subscription to open the Stripe Customer Portal 4. From the Stripe portal, you can: - View your current plan and billing cycle - Update your payment method (credit card, ACH) - Download invoices and receipts - View payment history - Cancel your subscription Updating Payment Information 1. In the Stripe portal, click Payment Methods 2. Click Add Payment Method to add a new card or bank account 3. Set the new method as default 4. Remove outdated payment methods if needed Downloading Invoices 1. In the Stripe portal, click Billing History 2. Each invoice has a Download link for PDF format 3. Invoices include line-item details showing device count and per-device pricing 4. Use these for purchase orders and district accounting Upgrading Your Plan 1. Go to Settings → Billing → Manage Subscription 2. Click Update Plan 3. Select your new plan tier (e.g., Basic → Pro) 4. The upgrade takes effect immediately 5. You'll be charged a prorated amount for the remainder of your current billing cycle 6. New features (analytics, SSO, etc.) become available within minutes Downgrading Your Plan 1. Go to Settings → Billing → Manage Subscription 2. Click Update Plan 3. Select the lower-tier plan 4. The downgrade takes effect at the end of your current billing cycle 5. You retain access to higher-tier features until the cycle ends 6. Features not included in the new plan will be disabled automatically Adding or Removing Devices - Your subscription is based on active device count - When you enroll a new device, it is automatically added to your subscription - When you remove a device from the dashboard, your next invoice reflects the reduced count - Prorated credits are applied for devices removed mid-cycle Tips - Budget planning — Use the Pro plan for most districts; it covers SSO and analytics which are essential for CIPA compliance reporting - Purchase orders — Contact support@kybergate.com to arrange PO-based billing for districts that cannot pay by credit card - Volume discounts — Districts with 500+ devices should contact sales for custom Enterprise pricing - Annual billing — All plans are billed annually; there is no monthly option at this time - Tax exemption — Provide your tax-exempt certificate to support@kybergate.com to remove tax from future invoices Troubleshooting | Issue | Solution | |-------|----------| | Payment failed | Update your payment method in the Stripe portal and retry | | Invoice not received | Check your spam folder; invoices are sent from Stripe directly | | Device count seems wrong | Go to Devices → Active and verify the count matches your subscription | | Cannot access billing portal | Ensure you have Admin role — only admins can manage billing | | Need a refund | Contact support@kybergate.com within 30 days of payment | Related Articles - Getting Started with KyberGate - Device Enrollment and PAC Configuration - Managing Users and Roles

Last updated on Apr 17, 2026

ClassLink Integration

ClassLink Integration KyberGate integrates with ClassLink using the OneRoster 1.1 standard to automatically sync your district's roster data — students, teachers, classes, and schools. This eliminates manual user management and keeps KyberGate in sync with your SIS. Overview The ClassLink integration provides: - OneRoster 1.1 Sync — Automatic import of users, classes, schools, and enrollments - SSO (Single Sign-On) — Students and staff log in to KyberGate using their ClassLink credentials - Automated Roster Sync — Daily automatic sync keeps user data current as students enroll, transfer, or graduate Prerequisites Before setting up ClassLink integration, ensure you have: 1. A KyberGate Pro or Enterprise subscription (SSO is not available on Basic) 2. ClassLink admin access to your district's ClassLink tenant 3. OneRoster 1.1 API credentials from ClassLink (Client ID and Secret) 4. The KyberGate app registered in your ClassLink LaunchPad Setting Up OneRoster 1.1 Sync Step 1: Enable OneRoster in ClassLink 1. Log in to your ClassLink Admin Console 2. Navigate to Roster Server → Applications 3. Click Add Application and search for KyberGate 4. If KyberGate is not listed, click Add Custom Application - Application Name: KyberGate - OneRoster Version: 1.1 5. Generate API credentials (Client ID and Client Secret) 6. Copy the Base URL, Client ID, and Client Secret Step 2: Configure in KyberGate 1. In the KyberGate admin dashboard, go to Settings → Integrations → ClassLink 2. Enter the following from ClassLink: - OneRoster Base URL (e.g., https://example.oneroster.com/ims/oneroster/v1p1) - Client ID - Client Secret 3. Click Test Connection to verify the credentials 4. A green checkmark confirms successful connection Step 3: Configure Sync Options 1. Select Schools — Choose which schools to sync (or select all) 2. User Types — Select which roles to import: Students, Teachers, Staff, Administrators 3. Sync Schedule — Set the automatic sync frequency: - Every 6 hours (recommended) - Every 12 hours - Every 24 hours - Manual only 4. Conflict Resolution — Choose how to handle conflicts: - ClassLink wins (recommended) — ClassLink data overwrites local changes - KyberGate wins — Local changes are preserved 5. Click Save & Run Initial Sync Step 4: Run Initial Sync 1. The initial sync imports all selected users, classes, and enrollments 2. Progress is shown in real-time with a count of imported records 3. A summary report shows: users created, updated, skipped, and any errors 4. Review the error log for any issues (usually duplicate emails or missing fields) Setting Up SSO Enable ClassLink SSO 1. Go to Settings → Authentication → SSO 2. Select ClassLink as the SSO provider 3. The integration uses your existing OneRoster credentials 4. Toggle Enable SSO Login to activate 5. Optionally, toggle Disable Password Login to force SSO-only authentication Add KyberGate to ClassLink LaunchPad 1. In the ClassLink Admin Console, go to App Library 2. Search for KyberGate or add a custom SSO app 3. Configure the SAML/OAuth redirect URL provided in KyberGate settings 4. Assign the app to the appropriate user groups Monitoring Sync Status 1. Go to Settings → Integrations → ClassLink → Sync History 2. Each sync shows: timestamp, duration, records processed, errors 3. Click on any sync entry to see detailed logs 4. Enable email notifications to receive alerts when a sync fails Tips - Start with one school — Test the sync with a single school before enabling district-wide - Review before enabling SSO — Ensure all users synced correctly before switching to SSO-only login - Check data quality — Common sync issues stem from missing email addresses or duplicate records in the SIS - Sync timing — Schedule syncs for off-hours (e.g., 2 AM) to avoid any performance impact - Role mapping — KyberGate maps ClassLink roles automatically: Teacher → Staff, Student → Student, Administrator → Admin Troubleshooting | Issue | Solution | |-------|----------| | Connection test fails | Verify Base URL, Client ID, and Secret are correct; check for trailing slashes in the URL | | Users not importing | Ensure the selected schools have active enrollments in ClassLink | | Duplicate users after sync | Check for duplicate email addresses in your SIS data | | SSO login fails | Verify the redirect URL in ClassLink matches the URL shown in KyberGate settings | | Sync runs but no new users appear | Check the user type filters — you may have deselected the relevant role | | Stale data after sync | ClassLink may be caching old SIS data — trigger a fresh export in your SIS | Related Articles - Clever Integration Guide - Managing Users and Roles - Billing and Subscription Management

Last updated on Apr 17, 2026

Managing Team Members and Roles

Managing Team Members and Roles Collaborate effectively by inviting team members to your KyberGate dashboard with role-based access controls. Assign the right permissions so teachers, administrators, and IT staff each see only what they need. Before You Begin - You must have Admin or Owner role to manage team members - Each team member needs a valid email address - Review available roles before sending invitations Understanding Roles KyberGate offers four permission levels: | Role | Access | |------|--------| | Owner | Full access including billing, integrations, and team management | | Admin | Manage devices, policies, users, reports, and settings | | Teacher | KyberClassroom, screen view, activity logs for assigned groups | | Viewer | Read-only access to dashboards and reports | How to Invite Team Members 1. Navigate to Settings → Team Members in your dashboard 2. Click Invite Member 3. Enter the team member's email address 4. Select the appropriate role from the dropdown 5. Optionally assign them to specific device groups or schools (for multi-site organizations) 6. Click Send Invitation 7. The team member receives an email with a link to create their account Managing Existing Members - Change role: Click the member's name → select new role from the dropdown → click Save - Remove member: Click the ⋮ menu next to their name → select Remove → confirm - Resend invitation: For pending invitations, click Resend next to the email Tips - Use the Teacher role for classroom staff — it limits access to classroom tools without exposing administrative settings - Assign teachers to specific device groups so they only see their students' devices in KyberClassroom - Review team members quarterly and remove accounts for staff who have left your organization Troubleshooting - Invitation email not received: Check the recipient's spam folder. If still missing, try resending from Settings → Team Members - Cannot change own role: You cannot modify your own permissions — another Admin or Owner must make the change - Login issues after invitation: Ensure the team member is using the exact email address the invitation was sent to Related Articles - Getting Started with KyberClassroom - Understanding the KyberGate Dashboard - Managing Device Groups and Assignments

Last updated on Apr 17, 2026

Configuring School Schedule

Configuring School Schedule Set up your school's operating schedule in KyberGate to automatically apply different filtering policies during school hours, after hours, and on weekends. Schedule-based policies ensure students have appropriate access levels throughout the day. Before You Begin - You need Admin role or higher - Know your school's bell schedule including start/end times and any period breaks - Decide on your after-hours filtering approach (relaxed, same as school hours, or fully blocked) Setting Up Your Schedule 1. Navigate to Settings → School Schedule in your dashboard 2. Click Edit Schedule 3. Set your school start time and end time for each day of the week 4. Toggle days on/off — disable weekends or teacher workdays as needed 5. Click Save Schedule Configuring Schedule-Based Policies Once your schedule is set, you can create policies that activate based on time: 1. Go to Policies → Create Policy (or edit an existing one) 2. Under Schedule, select when the policy should be active: - During school hours — applies only within your configured schedule - After hours — applies outside school hours - Always — applies 24/7 regardless of schedule 3. Set your filtering rules for that time period 4. Click Save Policy Example Setup - School hours (8:00 AM – 3:00 PM): Strict filtering — block social media, gaming, streaming - After hours (3:00 PM – 8:00 AM): Relaxed filtering — allow social media, keep adult content blocked - Weekends: Minimal filtering — safety categories only (adult, malware, weapons) Tips - Set your schedule 15 minutes before the first bell to ensure filtering is active when students arrive - Create a separate Testing schedule during exam periods with stricter policies - Use Schedule Override in KyberClassroom for temporary changes during class (e.g., allowing a blocked site for a specific lesson) - Schedule changes take effect within 60 seconds across all devices Troubleshooting - Policies not switching at the right time: Verify your timezone is set correctly in Settings → General → Timezone - Weekend policies applying on weekdays: Check that you haven't accidentally toggled weekday checkboxes off - Schedule not saving: Ensure end time is later than start time for each enabled day Related Articles - Creating and Managing Filtering Policies - Understanding Content Categories - Focus Mode and URL Push

Last updated on Apr 17, 2026

Network and Proxy Settings

Network and Proxy Settings KyberGate uses a cloud-based proxy architecture to filter web traffic. Understanding the network configuration helps ensure reliable filtering across all devices in your school. Before You Begin - You need Admin role or higher - Access to your school's network equipment (firewall, router) or your IT team - Know your MDM platform for deploying proxy settings to devices How KyberGate Proxy Works KyberGate routes web traffic through its cloud proxy network using a PAC (Proxy Auto-Configuration) file. This approach: - Enables SSL/HTTPS inspection for full content filtering - Works across all platforms (iPad, Chromebook, Windows, macOS) - Uses smart geo-routing across 8 regional proxy servers for optimal speed - Requires no on-premise hardware Proxy Regions KyberGate automatically routes traffic to the nearest proxy: - East Coast (NYC) — Primary - Southeast (Atlanta) - Midwest (Chicago) - Central (Dallas) - Northwest (San Francisco) - West Coast (Los Angeles) - Canada (Toronto) - Europe (London) Deploying Proxy Settings via MDM For iPads (Jamf, Mosyle, Kandji) 1. In your MDM, create a Global HTTP Proxy configuration profile 2. Set the proxy type to Auto (PAC) 3. Enter your organization's PAC file URL (found in Settings → Network in your dashboard) 4. Deploy the profile to your device groups For Chromebooks (Google Admin) 1. In Google Admin Console, go to Devices → Chrome → Settings 2. Under Network → Proxy, select Use proxy auto-config 3. Paste your PAC file URL 4. Apply to the appropriate OUs For Windows/macOS 1. The KyberGate agent automatically configures proxy settings during installation 2. No manual proxy configuration needed 3. Verify in Settings → Network that the agent is reporting proxy status as active Firewall Recommendations Ensure these are allowed through your school firewall: - Outbound ports: 443 (HTTPS), 80 (HTTP), 8080 (proxy) - Domains: *.kybergate.com, proxy.kybergate.com - Optionally block direct internet access (bypass proxy) by restricting outbound 443/80 to only KyberGate proxy IPs Tips - Use the Network Health Score on your dashboard to monitor proxy connectivity across devices - The PAC file URL is unique per organization — do not share it publicly - If your school uses a firewall with SSL inspection, add KyberGate proxy domains to the bypass list to avoid certificate conflicts Troubleshooting - Devices not routing through proxy: Verify the PAC file URL is correctly deployed via MDM. Check Devices → [device name] → Network for proxy status - Slow browsing: Check the Network Health Score. If a specific region shows high latency, contact support - Certificate errors: Ensure the KyberGate root certificate is installed on all devices (see Certificate Installation guide) Related Articles - How Web Filtering Works in KyberGate - Enrolling iPads via Jamf Pro - Enrolling Chromebooks via Google Admin - System Requirements and Supported Devices

Last updated on Apr 17, 2026

Google Workspace Integration

Google Workspace Integration Connect KyberGate to your school's Google Workspace to automatically sync students, teachers, and organizational units. This integration eliminates manual user management and keeps your KyberGate roster in sync with your directory. Before You Begin - You need Google Workspace Super Admin access - You need Admin role or higher in KyberGate - Your school must have Google Workspace for Education Setting Up the Integration 1. In your KyberGate dashboard, navigate to Settings → Integrations 2. Click Connect Google Workspace 3. Click Authorize — you'll be redirected to Google's OAuth consent screen 4. Sign in with your Google Workspace Super Admin account 5. Review the requested permissions and click Allow: - Read user directory (names, emails, OUs) - Read classroom rosters (for KyberClassroom groups) - Read user profile information 6. Once authorized, you'll be redirected back to KyberGate Configuring Sync Settings After connecting, configure what gets synced: 1. Select Organizational Units (OUs): Choose which OUs to import (e.g., /Students, /Students/Grade 5) 2. User Type Mapping: Map Google Workspace user types to KyberGate roles (students, teachers, staff) 3. Sync Frequency: Choose automatic sync interval (every 1, 6, 12, or 24 hours) 4. Google Classroom Integration: Optionally sync Google Classroom rosters to auto-create KyberClassroom groups 5. Click Save & Sync Now to run the initial import What Gets Synced - User accounts: Name, email, OU, status (active/suspended) - Organizational units: Full OU hierarchy for grouping - Classroom rosters: Teacher-to-student assignments (optional) - New users: Automatically added when created in Google Workspace - Removed users: Flagged as inactive (not automatically deleted) Tips - Start by syncing a single OU to verify everything works before importing your entire directory - Google Classroom sync is especially useful for KyberClassroom — teachers automatically see their class rosters - The initial sync may take a few minutes for large directories (1,000+ users) - Changes in Google Workspace typically reflect in KyberGate within one sync cycle Troubleshooting - Authorization fails: Ensure you're signing in with a Super Admin account, not a regular teacher or student account - Missing users after sync: Check that the correct OUs are selected in sync settings. Suspended Google accounts are imported but marked inactive - Classroom rosters not appearing: Verify Google Classroom sync is enabled and that teachers have active Google Classrooms with enrolled students - Sync errors: Check Settings → Integrations → Sync Log for detailed error messages Related Articles - Clever SSO Integration - Managing Team Members and Roles - Managing Device Groups and Assignments

Last updated on Apr 17, 2026

Clever SSO Integration

Clever SSO Integration Connect KyberGate with Clever to enable single sign-on (SSO) and automatic roster syncing for your district. Clever integration lets students and teachers log in with their existing school credentials and keeps user data synchronized. Before You Begin - Your district must have an active Clever account - You need District Admin access in Clever - You need Admin role or higher in KyberGate - Know which schools and sections you want to sync Setting Up Clever SSO Step 1: Connect in KyberGate 1. Navigate to Settings → Integrations in your KyberGate dashboard 2. Click Connect Clever 3. You'll be redirected to Clever's authorization page Step 2: Authorize in Clever 1. Sign in with your Clever District Admin credentials 2. Review the data KyberGate is requesting access to: - Student names, emails, and school assignments - Teacher names, emails, and sections - School and district information 3. Click Approve to grant access Step 3: Configure Data Sharing 1. In your Clever dashboard, go to Applications → KyberGate 2. Select which schools to share data with KyberGate 3. Choose data sharing rules: - Students: Share all or selected grades - Teachers: Share all or selected roles - Staff: Optional — share district admins and school staff 4. Click Save Step 4: Verify in KyberGate 1. Return to Settings → Integrations in KyberGate 2. Click Sync Now to pull data from Clever 3. Verify users and schools appear in your Users section How SSO Login Works Once connected, users can log in to KyberGate using Clever: 1. On the KyberGate login page, click Log in with Clever 2. If already signed into Clever, the user is automatically authenticated 3. If not, they'll sign in through Clever's portal first 4. KyberGate maps their Clever role (student/teacher/admin) to the appropriate KyberGate permissions Tips - Clever syncs data automatically — roster changes in your SIS flow through Clever to KyberGate within 24 hours - Use Clever's Secure Sync for the most reliable data sharing (vs. CSV upload) - Test with a single school before rolling out district-wide - Clever events (enrollment changes, new students) are processed automatically Troubleshooting - Authorization denied: Ensure you're signing in with a District Admin account. School-level admins cannot approve applications - Missing students or teachers: Check Clever's data sharing rules — the school or grade may not be shared with KyberGate - SSO login redirect fails: Verify the redirect URI is correctly configured in your Clever app settings. Contact KyberGate support if the issue persists - Stale data: Force a manual sync from Settings → Integrations → Clever → Sync Now Related Articles - Google Workspace Integration - Managing Team Members and Roles - Quick Start Guide: Setting Up KyberGate for Your School

Last updated on Apr 17, 2026

E-Rate Funding for KyberGate

E-Rate Funding for KyberGate KyberGate is an E-Rate eligible solution under the federal Universal Service Fund. Schools and libraries can use E-Rate Category 2 funding to offset the cost of KyberGate's web filtering, content security, and student safety tools. Before You Begin - Your school or district must be registered with USAC (Universal Service Administrative Company) - You need an active E-Rate application (Form 470/471) or be preparing one - Familiarize yourself with Category 2 budget guidelines for your funding year KyberGate E-Rate Eligibility KyberGate qualifies under E-Rate Category 2: Internal Connections as a content filtering and network security solution. Eligible components include: - KyberFilter — AI-powered web content filtering - KyberPulse — Student safety monitoring and alerts - SSL/HTTPS inspection — Deep packet inspection for encrypted traffic - Proxy infrastructure — Cloud-based filtering proxy service KyberGate E-Rate Details - SPIN Number: 143055219 - Service Provider: Kyber Systems LLC - Service Type: Internet Content Filtering / Network Security - Category: Category 2 — Internal Connections - Available on: Form 470 Item 21 — Basic Maintenance of Internal Connections How to Apply for E-Rate with KyberGate Step 1: File Form 470 1. Log in to the EPC Portal at https://forms.universalservice.org 2. File a Form 470 for Category 2 services 3. Include "Content Filtering" and "Network Security" in your service descriptions 4. Post the form and wait the required 28-day competitive bidding period Step 2: Request a Quote from KyberGate 1. Contact KyberGate sales at sales@kybergate.com or through your dashboard 2. Provide your Billed Entity Number (BEN), Form 470 number, and device count 3. KyberGate will provide an E-Rate compliant quote referencing SPIN 143055219 Step 3: File Form 471 1. After the 28-day window, file Form 471 in the EPC Portal 2. Enter KyberGate's SPIN number: 143055219 3. Attach the KyberGate quote as supporting documentation 4. Submit for USAC review Step 4: Receive Funding Decision 1. USAC reviews your application (typically 3-6 months) 2. Once approved, you receive a Funding Commitment Decision Letter (FCDL) 3. Proceed with KyberGate deployment 4. File Form 486 to confirm services have started Tips - File your Form 470 early in the E-Rate filing window (usually opens in January) - KyberGate's per-device pricing model aligns well with Category 2 budgets - Keep records of all quotes, contracts, and correspondence for USAC audits - E-Rate discounts range from 20% to 90% based on your school's free/reduced lunch percentage - Multi-year contracts (up to 3 years) can be filed on a single Form 471 Troubleshooting - Can't find KyberGate in USAC search: Search by SPIN number 143055219 or company name "Kyber Systems LLC" - Quote format questions: KyberGate provides E-Rate compliant quotes with all required fields (SPIN, service dates, per-unit pricing) - Need CIPA compliance documentation: KyberGate includes a CIPA compliance letter upon request — contact support Related Articles - How Web Filtering Works in KyberGate - Network and Proxy Settings - System Requirements and Supported Devices

Last updated on Apr 17, 2026

Setting Up DNS Filtering

Setting Up DNS Filtering DNS filtering is the fastest way to add KyberGate protection to an entire network — including devices you don't manage (guest Wi-Fi, BYOD, staff laptops, smart boards). Instead of installing anything on each device, you point your network's DNS at KyberGate's filtering resolvers. This guide walks through the full setup, in order. Do not skip Step 2 — it's the step most people miss, and without it none of your devices will be able to browse. Before You Begin - You need the Admin role or higher in KyberGate - Access to your firewall, router, or DHCP server (or your networking team) - Five minutes to test on a single network segment before rolling out widely How KyberGate DNS Filtering Works When a device on your network looks up a website, the request goes to KyberGate's DNS resolvers. KyberGate: - Returns the real address for allowed sites - Returns a block page for sites in categories you've blocked - Enforces SafeSearch on Google, Bing, and YouTube automatically Because filtering happens at the network level, it covers every device on that network — managed or not. This makes it ideal for guest networks and mixed-device environments. Important: KyberGate's DNS resolvers only answer requests coming from IP addresses you've registered to your organization. This prevents anyone else on the internet from using your filtering as an open resolver. If your network's public IP isn't registered, KyberGate will refuse every request and your devices will show errors like DNS_PROBE_FINISHED_BAD_CONFIG or "server IP address could not be found." Step 2 registers that IP. Step 1: Get Your KyberGate DNS Server Addresses In your dashboard, go to Settings → Network. Your organization's KyberGate DNS resolver addresses are listed there. You'll enter these into your firewall/router in Step 3. Step 2: Register Your Public IP (Required) This is the step that makes everything work. KyberGate needs to know which networks belong to you. 1. From the network you're going to filter, open a browser and visit whatismyip.com 2. Copy the public IPv4 address it shows 3. In your dashboard, go to Settings → Network → Campus Network IPs 4. Paste the IP, add a label (e.g. "Guest Network"), and click Add IP (or press Enter) You can add multiple IPs — for example, one for your main network and one for your guest network — if they leave your building through different public addresses. Tip: If you filter more than one network segment and they use different internet connections, register each segment's public IP separately. If they share one internet connection, one IP covers them all. Step 3: Point Your Network at KyberGate DNS Set your KyberGate DNS resolver addresses (from Step 1) as the DNS servers on the network you want to filter. Where you do this depends on your equipment: On a firewall (Meraki, FortiGate, SonicWall, etc.) 1. Open your DHCP or DNS settings for the network/VLAN you want to filter 2. Replace the existing DNS servers with your KyberGate resolver addresses 3. Save and apply On a router or Wi-Fi controller 1. Find the DHCP settings for the SSID or network 2. Set the DNS servers to your KyberGate resolver addresses 3. Save Devices pick up the new DNS when they reconnect or renew their DHCP lease. Reboot a test device to apply it immediately. Step 4: Test on One Network First Don't switch your whole school at once. Start with your guest network or a single test VLAN. 1. Connect a test device to the filtered network 2. Confirm the KyberGate DNS servers appear in the device's network settings 3. Browse to a normal site (e.g. wikipedia.org) — it should load 4. Browse to a site in a blocked category — you should see the KyberGate block page 5. Try a Google search — it should be locked to SafeSearch If normal sites don't load and you see a DNS error, the most common cause is that this network's public IP hasn't been registered yet — go back to Step 2. Troubleshooting "server IP address could not be found" / DNS_PROBE_FINISHED_BAD_CONFIG Your network's public IP isn't registered under Settings → Network → Campus Network IPs, so KyberGate is refusing the requests. Confirm the public IP (whatismyip.com from that network) is added. If your ISP changed your public IP, re-check and update it. Some sites load, others don't This is usually a blocked category, not a DNS problem — check your policy under Filtering. Sites in blocked categories are supposed to return the block page. Nothing changed after updating DNS Devices may still be holding the old DNS. Reboot the test device or renew its DHCP lease. Some devices (and some browsers) cache DNS aggressively. I want to filter managed devices with more detail DNS filtering sets a strong network-wide baseline. For per-user policies, screen viewing, and full HTTPS content inspection on managed devices, deploy the KyberGate proxy or agent as well (see Network and Proxy Settings). DNS filtering and proxy/agent filtering work together. When to Use DNS Filtering - Guest networks — protect visitors and BYOD without installing anything - Unmanaged / mixed-device networks — smart boards, IoT, personal devices - A network-wide safety baseline — layered under your managed-device filtering For 1:1 managed fleets where you want per-student policies and monitoring, pair DNS filtering with the proxy or device agent. Why Blocked HTTPS Sites Show a Browser Error (Not the Block Page) With DNS filtering, sites in a blocked category (gambling, adult, etc.) will usually show the browser's own "This site can't be reached" error instead of KyberGate's branded block page. This is expected — the site is blocked. Here's why: nearly all modern sites use HTTPS. To display a custom block page over an HTTPS connection, the device has to trust KyberGate's inspection certificate — and that only happens with the proxy or device agent methods, which decrypt and inspect traffic. DNS filtering blocks the site at the lookup stage without decrypting it, so it can't render a page on that HTTPS connection. Bottom line: a browser "can't be reached" error on a gambling/adult site means DNS filtering is working. If you want a branded block page on HTTPS for managed devices, deploy the proxy or agent alongside DNS filtering.

Last updated on Jul 10, 2026

Complete Deployment Guide

Complete Deployment Guide This is the master guide for deploying KyberGate. It covers every deployment method, helps you choose the right one for each part of your environment, and ends with a verification checklist. If you're new to KyberGate, read this page top to bottom once, then follow the linked step-by-step articles for the methods you need. The Big Picture KyberGate filters web traffic three ways. Most schools use a combination, matched to their devices: | Method | Best for | Filters HTTPS content? | Branded block page? | Per-user policies? | |--------|----------|------------------------|---------------------|--------------------| | DNS Filtering | Guest Wi-Fi, unmanaged/BYOD, network-wide baseline | Category-level (by domain) | HTTP only | No (by network) | | Proxy (PAC) | Managed iPads & Chromebooks | Yes (full SSL inspection) | Yes | Yes | | Device Agent | Managed Windows & macOS | Yes (full SSL inspection) | Yes | Yes | Rule of thumb: Use the proxy or agent on devices you manage. Use DNS filtering as a network-wide safety net for everything else. They work well together. Your Organization ID Almost every method needs your Organization ID. Find it under Settings → Workspace → Setup, or on the Devices → Add Device page (it's pre-filled into each platform's steps). It looks like a long string of letters and numbers. Key URLs (per organization) Replace YOUR_ORG_ID with your Organization ID: - PAC (proxy auto-config): https://proxy.kybergate.com/api/pac/YOUR_ORG_ID - Root CA certificate: https://proxy.kybergate.com/api/ca.pem - Apple MDM profile (.mobileconfig): https://proxy.kybergate.com/api/mdm/YOUR_ORG_ID Step 0: Before You Deploy - Confirm you have the Admin role in KyberGate - Know your device inventory (iPads, Chromebooks, Windows, macOS, unmanaged) - Know your MDM (Jamf, Mosyle, Kandji, Google Admin, Intune) and your firewall/router - Always start with a small test group — one OU or one VLAN — before rolling out school-wide Step 1: Set Your Organization Basics In Settings, confirm: 1. School Info — name, contact, logo (shown on your block page) 2. Schedule — school hours and bell schedule (drives time-based policies) 3. Network → Campus Network IPs — add your school's public IP(s). Required for DNS filtering, and used to identify on-campus devices for all methods. Visit whatismyip.com from your network to find your public IP. Step 2: Choose and Deploy Your Filtering Method(s) Path A — DNS Filtering (network-wide, fastest) Best for guest networks, unmanaged devices, and a network-wide baseline. 1. Settings → Network → Campus Network IPs — register the public IP of each network you'll filter (required, or DNS requests are refused) 2. Point that network's DNS at your KyberGate DNS resolvers (on your firewall, router, or DHCP server) 3. Test on one network segment first Full walkthrough: Setting Up DNS Filtering. Blocked HTTPS sites on DNS filtering: Sites in a blocked category (gambling, adult, etc.) will show the browser's own "This site can't be reached" error rather than KyberGate's branded block page. This is expected — the site is blocked. A branded block page over HTTPS requires the device to trust KyberGate's inspection certificate, which happens with the proxy or agent below. On Chromebooks, the KyberGate Chrome extension also shows the branded block page in-browser. Path B — iPads (Proxy via MDM) Best for 1:1 managed iPads. Requires supervised devices (most school-enrolled iPads are supervised by default). 1. Download the configuration profile from Devices → Add Device → iPad, or use the profile URL: https://proxy.kybergate.com/api/mdm/YOUR_ORG_ID. This profile includes the proxy settings, root CA certificate, and anti-bypass restrictions. 2. Upload to your MDM and scope it to your iPads: - Jamf Pro: Devices → Configuration Profiles → + New → Upload → select the .mobileconfig → set Scope → Save - Mosyle: Management → Profiles → + Add new profile → iOS/iPadOS → Upload Custom Profile → assign to device groups → Save - Kandji: Library → Add New → Custom Profile → upload → assign to a Blueprint 3. Confirm the CA certificate is trusted. The MDM-pushed profile trusts it automatically on supervised devices. To verify: Settings → General → About → Certificate Trust Settings — the KyberGate CA toggle should be on. 4. (Optional) Install the KyberGate iOS Agent from the App Store for screen viewing and deeper monitoring. For the full per-MDM walkthrough and dynamic device identification (email/UDID variables in the PAC URL), see Network and Proxy Settings. Path C — Chromebooks (Extension + Proxy via Google Admin) Best for 1:1 managed Chromebooks. This is a three-part setup: extension, certificate, and proxy. 1. Force-install the KyberGate extension (Google Admin → Devices → Chrome → Apps & extensions), set your Org ID in the extension's managed config 2. Upload the Root CA certificate and enable it for Chromebook (Devices → Networks → Certificates) 3. Configure the proxy PAC URL for your student OU's network Full step-by-step: Deploying KyberGate on Chromebooks. Path D — Windows (Device Agent) Best for managed Windows 10/11 laptops and desktops. 1. Download KyberGateAgent.msi from Devices → Add Device → Windows. The installer configures the system proxy, installs the root CA, starts the monitoring service, and registers the device — no manual proxy setup. 2. Deploy using whichever fits your environment (your Org ID is the enrollment code): - Manual: double-click the MSI; if prompted, enter your Org ID. Device appears in ~1 minute, no reboot. - Intune: Apps → Windows → + Add → Line-of-business app → upload MSI → install argument ENROLLMENT_CODE=YOUR_ORG_ID → assign device groups - Group Policy (AD): GPMC → new GPO on the computer OU → Software Installation → assign the MSI (from a network share) → pass ENROLLMENT_CODE via an MST/Advanced properties → installs at next startup (reboot required) - SCCM/MECM: Create Application → MSI → install command msiexec /i KyberGateAgent.msi /qn ENROLLMENT_CODE=YOUR_ORG_ID → deploy to a Device Collection as Required See Enrolling Windows Devices for details. Path E — macOS (Device Agent) Best for managed Macs. 1. Download the KyberGate macOS agent from your dashboard 2. Deploy via your MDM (custom package) or run the installer on the device — it auto-configures the proxy and trusts the inspection certificate 3. Verify the device reports under Fleet See Enrolling macOS Devices with KyberGate Agent. Step 3: Connect Your Roster (Recommended) For per-user policies and student safety monitoring, connect your user directory: - Google Workspace: Settings → Workspace — set your domain, complete domain-wide delegation, and choose which OUs to sync. See Google Workspace Integration. - Clever / ClassLink: See Clever SSO Integration and ClassLink Integration. Once users are synced and signing into devices, KyberGate associates each device with its user and applies that user's policy. Step 4: Configure Your Policies - Filtering — pick a policy template or customize blocked categories - Block Page — customize with your school's name, logo, and contact (Settings → Block Page). See Block Page Customization. - Schedule — apply different rules during vs. after school hours - KyberPulse (optional) — turn on student safety scanning. See Setting Up KyberPulse Notifications. Step 5: Verify Your Deployment Run this on a test device for each method you deployed: - [ ] Device appears under Fleet/Devices (proxy/agent), or resolves through KyberGate DNS (DNS method) - [ ] A normal site (e.g. wikipedia.org) loads - [ ] A blocked-category site is blocked (branded page on proxy/agent/Chromebook extension; browser "can't be reached" on DNS for HTTPS) - [ ] A quick test: tiktok.com should be blocked; khanacademy.org should be allowed - [ ] Google/Bing/YouTube are locked to SafeSearch - [ ] The correct user shows next to the device (if roster is synced) - [ ] Activity appears under Reports within a few minutes Rolling Out School-Wide Once your test group looks right: 1. Expand one OU / VLAN at a time 2. Watch Reports and the Fleet view for coverage gaps 3. Keep DNS filtering on your guest network as a permanent baseline Common First-Day Questions "A blocked HTTPS site shows a browser error, not the KyberGate block page." Expected on DNS filtering — the site is blocked. Use the proxy or agent (or the Chrome extension on Chromebooks) for a branded block page on HTTPS. "My device isn't showing up in the dashboard." See Device Not Appearing in Dashboard. For DNS, confirm your public IP is registered under Settings → Network. "Some HTTPS sites aren't being filtered by content." Confirm the KyberGate certificate is installed and trusted on the device. See Certificate Installation Issues and HTTPS Sites Not Being Filtered. "Can I use more than one method at once?" Yes — that's the recommended setup. DNS filtering as a network baseline, plus proxy/agent on managed devices. Need help with your specific setup? Open the live chat in your dashboard (bottom-right) — it goes to a real person on our team.

Last updated on Jul 10, 2026

Google Workspace Integration

Google Workspace Integration Connecting Google Workspace lets KyberGate automatically sync your students and staff, apply per-user policies, match devices to the signed-in user, and (optionally) run KyberPulse email and document safety scanning. This guide covers the full setup: connecting your domain, authorizing domain-wide delegation, verifying it, and running your first sync. To limit the sync to specific organizational units, see Managing Users and Syncing Specific OUs. What You Get - Automatic roster sync — students and staff sync from Google Workspace every 6 hours - Per-user policies — a student's policy follows them across devices - Device-to-user matching — Chromebooks and other devices show the signed-in user - OU-based scoping — sync and monitor only the OUs you choose - KyberPulse scanning (optional) — scan student Gmail and Google Docs for safety signals Before You Begin - You need Super Admin in Google Workspace (to authorize delegation) - You need the Admin role in KyberGate - Have your Google Workspace domain ready (e.g. school.edu) and a Workspace admin email to run the sync as Step 1: Connect Your Domain 1. In your dashboard, go to Settings → Workspace (or Integrations → Google Workspace) 2. Enter your Domain (e.g. school.edu) and your Admin Email 3. Click Connect Workspace At this point your domain is saved, but the connection badge will show "Delegation pending" — KyberGate can't read your directory yet. That's expected. The next step authorizes it. Why "Delegation pending"? The badge only turns green ("Connected") once KyberGate can actually read your directory. Saving a domain alone doesn't grant access — you must authorize domain-wide delegation in Google Admin (Step 2). This prevents a misleading "Connected" state where no users can actually sync. Step 2: Authorize Domain-Wide Delegation KyberGate uses manual domain-wide delegation (rather than a one-click OAuth) because it gives you precise control over exactly which permissions you grant. Open the Setup tab on the Workspace page — it shows your organization's exact values with copy buttons. Then: 1. Go to Google Admin → Security → Access and data control → API Controls → Domain-Wide Delegation (Direct link: https://admin.google.com/ac/owl/domainwidedelegation) 2. Click Add new 3. Paste the Client ID: 103445766148940749130 4. Paste the OAuth scopes (comma-separated). It will look like one long line until you click Authorize, which separates them: https://www.googleapis.com/auth/admin.directory.user.readonly,https://www.googleapis.com/auth/admin.directory.orgunit.readonly,https://www.googleapis.com/auth/gmail.readonly,https://www.googleapis.com/auth/drive.readonly 5. Click Authorize What each scope does | Scope | Purpose | Required? | |-------|---------|-----------| | admin.directory.user.readonly | Read users for roster sync | Required | | admin.directory.orgunit.readonly | Read your OU tree (for OU-scoped sync) | Required | | gmail.readonly | KyberPulse email scanning | Optional | | drive.readonly | KyberPulse document scanning | Optional | If you don't plan to use KyberPulse email/document scanning, you can omit the last two scopes. You can always add them later. Step 3: Verify Delegation Back in KyberGate, on the Workspace page: 1. Click Verify Delegation 2. The connection badge turns green ("Connected") once KyberGate confirms it can read your directory 3. If it still shows "Delegation pending," the badge will display the specific error — usually the Client ID or a scope was mistyped, or Google hasn't finished propagating (wait a couple of minutes and try again) Step 4: Sync Your Users 1. Click Sync Now (available once delegation is verified) 2. KyberGate imports your users, their names, roles, and organizational units 3. Users then appear under the Users tab and sync automatically every 6 hours going forward By default, KyberGate syncs your entire organization. To sync only certain OUs (for example, students but not service accounts), see Managing Users and Syncing Specific OUs. Filter Modes Once users are synced, you can apply policies by user, not just by device: - Device-based — policy follows the device - User-based — policy follows the student across devices - Both — device baseline plus per-user overrides (recommended) Set this under Settings → Filtering. KyberPulse Scanning (Optional) If you added the gmail.readonly and drive.readonly scopes, you can enable student safety scanning on the KyberPulse Scanning tab: - Email Scanning — scans student Gmail every 15 minutes for safety signals - Document Scanning — scans Google Docs, Sheets, and Slides every 30 minutes You can limit scanning to specific OUs — see Managing Users and Syncing Specific OUs. Troubleshooting Badge stuck on "Delegation pending" - Recheck the Client ID and scopes in Google Admin — a single wrong character breaks it - Confirm you authorized with a Super Admin account - Wait 1–2 minutes for Google to propagate, then click Verify Delegation again "Sync requires domain-wide delegation" when clicking Sync Now - Delegation isn't verified yet. Complete Step 2 and click Verify Delegation first. Users synced but no OUs show - Confirm the admin.directory.orgunit.readonly scope was included, then click Refresh OU list on the OU Scope tab. Devices show a generic name instead of the student - The device shows the signed-in user once the roster is synced and the user signs in. Confirm the user exists under the Users tab. Related Articles - Managing Users and Syncing Specific OUs - Clever SSO Integration - ClassLink Integration - Setting Up KyberPulse Notifications Need help? Open the live chat in your dashboard (bottom-right) — it goes to a real person on our team.

Last updated on Jul 10, 2026

Managing Users and Syncing Specific OUs

Managing Users and Syncing Specific OUs Once Google Workspace is connected, KyberGate can sync your users automatically. By default it syncs your entire organization — but most schools want to sync only certain organizational units (OUs), for example students and staff but not service accounts, shared mailboxes, or test accounts. This guide covers managing users and scoping both user sync and KyberPulse monitoring to specific OUs. Prerequisite: Google Workspace must be connected and delegation verified. See Google Workspace Integration. OU scoping also requires the admin.directory.orgunit.readonly scope (included in the standard setup). How Users Get Into KyberGate There are three ways users appear in KyberGate: 1. Google Workspace sync (recommended) — automatic, every 6 hours 2. Clever / ClassLink — via SSO roster sync 3. Manual — add users individually under the Users tab Once a user exists in KyberGate and signs into a device, KyberGate matches the device to that user and applies the user's policy. Viewing Synced Users On the Settings → Workspace page, the Users tab lists everyone synced, with their name, email, OU, and role (student / staff / teacher). Use the search box to find a specific user by name, email, or OU. Roles are inferred from the OU path — e.g. a user under /Students is tagged as a student, and one under /Staff or /Teachers as staff. You can adjust role mapping under Role Mapping on the Overview tab. Syncing Only Specific OUs This is the key setting for keeping your user list clean. 1. Go to Settings → Workspace and open the OU Scope tab 2. You'll see a list of your Google Workspace OUs, each with two checkboxes: - Sync users — import users from this OU into KyberGate - Monitor (Pulse) — include this OU in KyberPulse safety scanning 3. Check Sync users for only the OUs you want (e.g. /Students, /Staff) 4. Click Save OU Scope The next sync will import only users in the selected OUs. Existing users outside those OUs are left as-is; new users outside them won't be added. Leave everything unchecked to include all OUs. An empty selection means "sync the entire organization." Checking specific OUs narrows it to just those. How OU matching works (prefix-based) OU selection is prefix-based. Selecting /Students includes every sub-OU beneath it — /Students/Grade 3, /Students/Grade 4, and so on. You don't need to check each grade individually; check the parent and all children are included. If you don't see an OU you expect, click Refresh OU list to pull the latest tree from Google. (This requires verified delegation.) Scoping KyberPulse Monitoring to Specific OUs You often want to sync more users than you monitor. For example, sync all students and staff, but only run KyberPulse safety scanning on students. On the same OU Scope tab, use the Monitor (Pulse) column: 1. Check Monitor (Pulse) for only the OUs you want scanned (e.g. /Students) 2. Leave staff or test OUs unchecked 3. Click Save OU Scope KyberPulse email and document scanning will then only cover users in the selected OUs. As with sync, an empty selection means "monitor all student OUs." Example: Check Sync users on /Students and /Staff, but only check Monitor (Pulse) on /Students. Result: staff and students are both in KyberGate for filtering and reporting, but only students' Gmail/Docs are scanned by KyberPulse. Running a Sync - Click Sync Now on the Workspace page to sync immediately - KyberGate also syncs automatically every 6 hours - After a scoped sync, the result shows how many users were imported and how many were skipped by your OU filter Adding or Removing Users Manually - Add: Users tab → add a user with email, name, and role - Remove: withdrawn users are deactivated automatically on the next sync if they're removed from Google Workspace Troubleshooting OU list is empty - Confirm delegation is verified and the admin.directory.orgunit.readonly scope is authorized - Click Refresh OU list I synced the whole org by accident (service accounts, etc.) - Set the correct OUs under OU Scope → Sync users and Save. Users outside the selected OUs won't be re-added on the next sync. To remove already-imported users, deactivate or delete them on the Users tab. A student's policy isn't following them across devices - Confirm the user is synced (Users tab) and that your filter mode is User-based or Both (Settings → Filtering) KyberPulse is scanning the wrong group - Check the Monitor (Pulse) column on the OU Scope tab — only the checked OUs are scanned (or all student OUs if none are checked) Related Articles - Google Workspace Integration - Setting Up KyberPulse Notifications - Clever SSO Integration - ClassLink Integration Need help? Open the live chat in your dashboard (bottom-right) — it goes to a real person on our team.

Last updated on Jul 10, 2026