Filter › Setup and get started
Offboarding Securly Filter: How to Remove Filter from Your District
This guide walks through how to cleanly remove Securly Filter from your environment when your district is discontinuing the product. The steps are the reverse of the standard onboarding process: you undo the deployment from devices first, then unwind policies and roster connections, and finish by confirming account deactivation with Securly. Working in this order keeps devices online and avoids leaving orphaned certificates or filtering profiles behind.
Before you begin: back up and plan
- Export your reports and audit data. If you need a record of past browsing activity or flagged events for compliance (for example, CIPA records), export what you need from Managing Activity Reports before the account is deactivated. Data is no longer accessible once the account is turned off.
- Note your admin users and current policies. Capture a list of Filter admins and your current policy configuration in case you need it for records or for a future re-deployment.
- Plan for a filtering gap. Once Filter is removed, devices will no longer be filtered by Securly. If you are required to maintain CIPA-compliant filtering, have your replacement solution ready before you start.
- Coordinate with Securly. Contact your account team or the Securly support team so the deactivation is scheduled and any contractual offboarding is handled correctly.
Step 1: Remove the Filter deployment from all devices
Start by removing whichever filtering method(s) you deployed during onboarding. This is the most important step—removing the deployment is what actually stops filtering and prevents SSL or connectivity errors on devices.
Chrome / Edge browser extension
In the Google Admin Console, go to Devices > Chrome > Apps and extensions > Users & browsers, select the OU where the Securly extension was force-installed, and either remove the extension entry or set its installation policy to Block / Do not allow. Save your changes. If you deployed the extension with Microsoft Intune or GPO instead, remove the corresponding assignment or policy there.
SmartPAC (Windows and Mac)
Uninstall SmartPAC using the same management tool you used to deploy it (Intune, JAMF, Meraki, Mosyle, Airwatch, GPO, or a manual/standalone install). Remove the deployment assignment or run the uninstaller so the PAC configuration is cleared from each device.
SmartDNS and Guest DNS
Remove any SmartDNS profiles you pushed to iOS, Mac, or Windows Server devices, and revert any Guest Network DNS filtering changes on your network equipment back to your own DNS resolvers.
Step 2: Remove the Securly SSL certificate
Devices that used SmartPAC or SmartDNS had the Securly SSL certificate installed so HTTPS sites could be filtered without SSL errors. After removing the deployment, remove the Securly SSL certificate from those devices (via your MDM, GPO, Google Admin Console, or the certificate store on standalone devices). This step is not needed for Chromebooks that used only the extension, or for guest-network DNS, since those methods do not require the certificate.
Step 3: Unassign filtering policies
In Filter's Policy Editor / Policy Map, unassign the policies you mapped to your Google OUs, Microsoft Entra (Azure AD) units, and Securly Sync Units during onboarding. Because unassigned OUs fall back to the Default Policy, policy enforcement effectively ends once the deployment (Steps 1–2) is removed—so this step is primarily housekeeping and record-keeping. Export or note any custom policies first if you want them for your records.
Step 4: Disconnect roster and OU syncing
Unwind the roster connections you set up during onboarding so Securly stops pulling your organizational data:
- Google Org Units: stop the Google OU sync in Roster Integration / Org. unit Management.
- Microsoft Security Groups / Entra (Azure AD): remove the Microsoft directory connection used to import security groups.
- Securly Sync: if your district connected an SIS through Securly Sync, disconnect that data source. Note that Securly Sync may also feed other Securly products (Pass, Flex, Home, Classroom)—only disconnect it if Filter was the only product using it. If other products still rely on Securly Sync, leave the connection in place.
Step 5: Remove admin access and confirm deactivation
Finally, reverse the first onboarding step—logging in and administering the account:
- Remove or downgrade Filter admin users under Managing Users if you want to revoke access before deactivation.
- Confirm with your Securly account team or Securly support that the Filter account has been deactivated on Securly's side. Securly completes the final service shutoff; the steps above ensure your devices and directory are cleanly disconnected first.
Offboarding checklist (reverse of onboarding)
- Export reports/audit data and plan for a filtering gap.
- Remove the deployment: extension, SmartPAC, and/or SmartDNS/Guest DNS.
- Remove the Securly SSL certificate from devices that used it.
- Unassign filtering policies from OUs / Securly Sync Units.
- Disconnect Google OU, Microsoft Security Group, and Securly Sync roster syncing.
- Remove admin users and confirm account deactivation with Securly.
Getting help
If you are unsure which filtering methods your district deployed, or you want Securly to help sequence the removal, contact your account team or the Securly support team before you begin.