So we have a client that we currently have Facebook blocked with via DNS on the domain controller. Facebook.com just redirects to the IP of the server. Each workstation points to the IP of the DC for it's DNS so that works out well. (If they really wanted to, they could change the DNS servers, but that would make their logins slow and most if not all the users would even know how to do that.) We have had this setup for about a year, and the owners of the business are happy with it and how's it working. They now have a Facebook page that they want to update at work, but obviously they can't get on Facebook. (We told them to do it at home, but "apparently" it doesn't work there. Whatever.) It's only one computer that needs access or one user I guess, but preferably computer. Is there a way, maybe through GPO or the DNS server itself that would allow only the specific computer and none others through? The server is running Server 2003 and the clients are XP pro with maybe one or two 7 machines. Any ideas?