Remote browser isolation (RBI) is a web security technique in which web pages are loaded and run in a browser on a remote server, usually in a provider’s cloud, rather than on the user’s device. The user sees and interacts with a safe rendering of the page, while the page’s scripts and active content run on the remote side. If a site is malicious, the code runs in a disposable remote environment instead of on the laptop that holds company data and sign-in sessions.
At a glance
- For isolated sessions, a site’s scripts and active content run remotely, not on the user’s device.
- It is usually a feature of a secure web gateway or SSE service rather than a standalone purchase.
- Many organizations isolate selectively, such as uncategorized, newly registered or risky sites and links in email, because isolating everything adds cost and latency.
- Policy can control downloads, uploads, copy and paste, and typing into forms in isolated sessions.
- It reduces web-borne malware and browser exploit risk; it doesn’t stop users entering passwords on phishing pages unless the service restricts input.
What problem it solves
Web filtering works by deciding whether a site is safe. It struggles with sites it hasn’t seen before: newly registered domains, legitimate sites that were compromised yesterday, or pages exploiting a browser flaw nobody has patched yet (a zero-day). Blocking every unknown site frustrates users; allowing them lets risky code run on the device.
RBI offers a middle path. Unknown or risky sites can be opened, but they run remotely, and the remote browser environment is discarded at the end of the session. Users keep working, and a drive-by download or exploit has a much harder time reaching the device. The same approach helps when contractors or personal devices need web access to business tools, because less of the session touches the device.
How it works
- Policy decides. When a user requests a page, the secure web gateway or SSE policy decides whether it loads normally, is blocked, or is isolated, often based on category, risk score, user group or whether the link came from email.
- A remote browser loads the page. The service starts a browser instance in one of its points of presence, loads the page and runs its scripts there.
- A safe rendering is sent. Services use one of two broad methods, sometimes both: pixel streaming, which sends what the page looks like as an image or video stream, or sending a rebuilt, cleaned-up version of the page with dangerous content removed. Pixel streaming keeps more page code off the device; the rebuilt approach usually feels more like normal browsing but relies on the cleaning being thorough.
- Controls apply. Policy decides whether users can download files (blocked, allowed or sanitized), upload, copy and paste, print or type into forms in the isolated session.
- The session is discarded. When the session ends, the remote browser environment is thrown away.
When it matters for buyers
- When evaluating SWG or SSE. Isolation is often an add-on license; check what it covers and how much of your traffic it can handle.
- When phishing links are a recurring problem. Opening email links in isolation is a common first use.
- When high-risk roles need open internet access. Finance, executives and researchers often visit unfamiliar sites as part of their work.
- When contractors or BYOD users need web apps. Isolation can limit what reaches or leaves an unmanaged device, often alongside data loss prevention controls.
- After a browser-based incident. A peer’s or your own web-borne infection is a common trigger for adding isolation for uncategorized sites.
Questions to ask vendors
- Is isolation included in our SWG or SSE license, or priced separately, and is it per user or capped by usage?
- Which rendering method do you use, and how do complex web apps, video and collaboration tools behave in isolation?
- How do you handle downloads: block, allow, or sanitize, and for which file types?
- Can you restrict typing passwords into unknown or uncategorized sites?
- Where are your isolation points of presence, and what latency should our users expect?
- What works without an agent, and what needs one?
How it differs from an enterprise browser
An enterprise browser is a browser that runs locally on the user’s device and is centrally managed to control what users can do with business apps and data, such as copying, downloading or printing. RBI runs the browsing session remotely and streams a safe rendering, and its main job is protecting the device from malicious sites. The two can overlap: some enterprise browsers hand risky sites to an isolation service, and some isolation products add data controls. A secure web gateway is different again, filtering traffic in the network path; it is also a common place to find RBI as a feature. For how isolation fits into a wider rollout, see our Security Service Edge (SSE) overview.
