What Is RBI (Remote Browser Isolation)?

Related problems: Users clicking links to new or unknown sites that filters haven't categorized yet; Browser exploits and malicious downloads reaching laptops; Contractors and personal devices need web access we can't control; Need to let people visit risky sites without blocking them outright

Remote browser isolation (RBI) is a web security technique in which web pages are loaded and run in a browser on a remote server, usually in a provider’s cloud, rather than on the user’s device. The user sees and interacts with a safe rendering of the page, while the page’s scripts and active content run on the remote side. If a site is malicious, the code runs in a disposable remote environment instead of on the laptop that holds company data and sign-in sessions.

At a glance

  • For isolated sessions, a site’s scripts and active content run remotely, not on the user’s device.
  • It is usually a feature of a secure web gateway or SSE service rather than a standalone purchase.
  • Many organizations isolate selectively, such as uncategorized, newly registered or risky sites and links in email, because isolating everything adds cost and latency.
  • Policy can control downloads, uploads, copy and paste, and typing into forms in isolated sessions.
  • It reduces web-borne malware and browser exploit risk; it doesn’t stop users entering passwords on phishing pages unless the service restricts input.

What problem it solves

Web filtering works by deciding whether a site is safe. It struggles with sites it hasn’t seen before: newly registered domains, legitimate sites that were compromised yesterday, or pages exploiting a browser flaw nobody has patched yet (a zero-day). Blocking every unknown site frustrates users; allowing them lets risky code run on the device.

RBI offers a middle path. Unknown or risky sites can be opened, but they run remotely, and the remote browser environment is discarded at the end of the session. Users keep working, and a drive-by download or exploit has a much harder time reaching the device. The same approach helps when contractors or personal devices need web access to business tools, because less of the session touches the device.

How it works

  1. Policy decides. When a user requests a page, the secure web gateway or SSE policy decides whether it loads normally, is blocked, or is isolated, often based on category, risk score, user group or whether the link came from email.
  2. A remote browser loads the page. The service starts a browser instance in one of its points of presence, loads the page and runs its scripts there.
  3. A safe rendering is sent. Services use one of two broad methods, sometimes both: pixel streaming, which sends what the page looks like as an image or video stream, or sending a rebuilt, cleaned-up version of the page with dangerous content removed. Pixel streaming keeps more page code off the device; the rebuilt approach usually feels more like normal browsing but relies on the cleaning being thorough.
  4. Controls apply. Policy decides whether users can download files (blocked, allowed or sanitized), upload, copy and paste, print or type into forms in the isolated session.
  5. The session is discarded. When the session ends, the remote browser environment is thrown away.

When it matters for buyers

  • When evaluating SWG or SSE. Isolation is often an add-on license; check what it covers and how much of your traffic it can handle.
  • When phishing links are a recurring problem. Opening email links in isolation is a common first use.
  • When high-risk roles need open internet access. Finance, executives and researchers often visit unfamiliar sites as part of their work.
  • When contractors or BYOD users need web apps. Isolation can limit what reaches or leaves an unmanaged device, often alongside data loss prevention controls.
  • After a browser-based incident. A peer’s or your own web-borne infection is a common trigger for adding isolation for uncategorized sites.

Questions to ask vendors

  • Is isolation included in our SWG or SSE license, or priced separately, and is it per user or capped by usage?
  • Which rendering method do you use, and how do complex web apps, video and collaboration tools behave in isolation?
  • How do you handle downloads: block, allow, or sanitize, and for which file types?
  • Can you restrict typing passwords into unknown or uncategorized sites?
  • Where are your isolation points of presence, and what latency should our users expect?
  • What works without an agent, and what needs one?

How it differs from an enterprise browser

An enterprise browser is a browser that runs locally on the user’s device and is centrally managed to control what users can do with business apps and data, such as copying, downloading or printing. RBI runs the browsing session remotely and streams a safe rendering, and its main job is protecting the device from malicious sites. The two can overlap: some enterprise browsers hand risky sites to an isolation service, and some isolation products add data controls. A secure web gateway is different again, filtering traffic in the network path; it is also a common place to find RBI as a feature. For how isolation fits into a wider rollout, see our Security Service Edge (SSE) overview.

Frequently Asked Questions

Is remote browser isolation the same as a secure web gateway?
No. A secure web gateway decides whether web traffic is allowed and inspects it. Remote browser isolation changes where the page runs: on a remote server instead of on the device. Many secure web gateway and SSE services include isolation as a feature and use it for sites that are uncategorized or risky rather than blocking them.
Will RBI slow users down?
It can. Pages are loaded remotely and then streamed, so there is some added latency, and rich or highly interactive sites may behave differently. Many organizations limit isolation to unknown, uncategorized or risky sites and let trusted business apps load normally, then test the experience with real users.
Can users still download files from isolated sites?
That depends on policy. Downloads can usually be blocked, allowed or passed through file sanitization (content disarm and reconstruction), which rebuilds documents without active content such as macros. Any file allowed through unchanged can still carry risk to the device.
Do we need an agent on devices to use RBI?
Not always. Some services work through a proxy setting or by rewriting links, for example in email, while others rely on an endpoint agent that also handles other SSE functions. Agentless options are useful for unmanaged devices but are usually easier for users to bypass.
Does RBI make devices immune to web threats?
No. It runs page scripts and active content remotely for isolated sessions, but sites that aren't isolated, files users are allowed to download, and phishing pages where users type their passwords can still cause harm. Some services add controls such as blocking typing into unknown sites for that last case.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.