Sophos Firewall (XG): Allow Blocked URLs for Specific Users
- Web > Categories > Add: create a custom category (for example Allowed-for-IT) and add the URLs or domains you want to allow for some users.
- Web > URL groups: create a URL group with the URLs that must stay blocked for everybody else, and block it in the policy.
- Web > Policies: edit (or create) the web policy and add a rule at the top with the users or groups to allow, the custom category and action Allow.
Rules are evaluated top-down, so the allow rule must be above the block rule.
Check: the firewall rule must use this web policy and have user identification (authentication) working. Otherwise user-based web rules never match.
More info.