What is a good way to block all users from being able to access certain web sites? This is on a Active Directory network. Since all DNS requests get forwarded through the Windows Server, can the Windows Server machine control which sites the users can access or would each machine need to have software to do that? Unfortunately the router doesn't have a built-in way to restrict sites. Thanks.