We have a Base Policy for Web Control, that every user picks up.
In the Website Management, we have websites like DropBox added and tagged to block in the policy.
I have tried numerous links and websites including DropBox, and it blocks as expected, we had a user say they could access and now they can't.
I wanted to find out why they would have been able to and now they can't, as they are in the Base Policy?
How is this possible?
I would check the SophosNetFilter.log log file. Hopefully you have logs going back to the time when they could access it. They are under: C:\ProgramData\Sophos\Sophos Network Threat Protection\Logs\