Palo Alto NetworksSecure Access Service Edge (SASE)

    Remote Browser Isolation

    Executes web content away from the endpoint so threats never reach it.

    Palo Alto Networks Remote Browser Isolation (RBI) safely executes potentially malicious web content in an isolated cloud environment, blocking threats before they reach the endpoint while giving users a seamless browsing experience. Part of the Prisma SASE platform, it protects users from risky and unknown websites without blocking access outright. Faltrox deploys and operates it as an isolation layer of web defence.

    Overview

    What Remote Browser Isolation is

    Some websites are too risky to allow directly but too useful or ambiguous to block outright — and web-based threats increasingly reach users through the browser. Remote Browser Isolation solves this by executing web content in an isolated cloud environment and streaming only a safe rendering to the user, so malicious code never touches the endpoint.

    Modern RBI avoids the poor experience of older pixel-pushing approaches, safely executing malicious content away from the device, blocking threats, and providing visibility into risky browsing — while keeping the user experience seamless. As part of Prisma SASE and integrated with Prisma Access, it adds an isolation layer for risky and unknown sites without an all-or-nothing block. Faltrox deploys it, sets the isolation policy, and operates it as part of managed web defence.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Risky & Unknown Sites

    Isolates access to risky, uncategorised, and unknown websites without blocking them outright.

    02

    Web-Based Threats

    Blocks malicious web content before it can reach the endpoint.

    03

    The Endpoint

    Keeps the endpoint safe by executing web content away from the device.

    04

    Data Interaction

    Controls interaction with isolated pages to prevent data leakage.

    05

    Browsing Visibility

    Provides visibility into risky browsing activity.

    06

    Seamless Experience

    Delivers a seamless user experience without the lag of legacy isolation.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Route

      Access to risky, unknown, or policy-selected sites is routed to the isolation service rather than the endpoint.

    2. 02

      Isolate

      The web content is executed in an isolated cloud environment away from the device.

    3. 03

      Render

      Only a safe rendering of the page is streamed to the user, so malicious code never reaches the endpoint.

    4. 04

      Control

      Interaction with the isolated page — data entry, downloads — is controlled to prevent leakage and threats.

    5. 05

      Operate

      Faltrox sets the isolation policy and operates it as part of managed web defence.

    Capabilities

    Key capabilities

    Safe Content Execution

    Executes potentially malicious web content in an isolated cloud environment, away from the endpoint.

    Threat Blocking

    Blocks malicious web content before it can reach or infect the device.

    Seamless Experience

    Delivers a smooth browsing experience without the lag of legacy pixel-pushing isolation.

    Access Without Blocking

    Lets users reach risky or unknown sites safely instead of blocking them outright.

    Data Interaction Control

    Controls data entry, downloads, and interaction with isolated pages to prevent leakage.

    Browsing Visibility

    Provides visibility into risky browsing activity for security teams.

    Part of Prisma SASE

    Integrates with Prisma Access as an isolation layer of the SASE platform.

    Policy-Driven Isolation

    Applies isolation selectively by category, reputation, and risk.

    Works with

    Part of the platform

    Palo Alto Networks products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Palo Alto Networks Remote Browser Isolation for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01What problem does Remote Browser Isolation solve?

    The dilemma of risky-but-useful websites — too dangerous to allow directly but too ambiguous to block outright. RBI lets users reach them safely by executing the web content in an isolated cloud environment and streaming only a safe rendering, so malicious code never touches the endpoint.

    02Does it degrade the browsing experience?

    Modern RBI avoids the poor experience of older pixel-pushing approaches that rendered everything as images. It safely executes content away from the device while keeping the user experience seamless, so security does not come at the cost of usability.

    03How is it different from just blocking the site?

    Blocking is all-or-nothing and frustrates users when a site is legitimate; isolation lets them access risky and unknown sites safely instead of blocking them. It is applied selectively by category, reputation, and risk, so you isolate the grey area rather than blocking it.

    04How does it fit with URL filtering?

    They work together: Advanced URL Filtering blocks known-bad sites, and RBI isolates the risky, unknown, or uncategorised grey area rather than blocking it — a layered approach to web defence. Faltrox designs the policy across both.

    05How does Faltrox operate it?

    We integrate RBI with Prisma Access and URL filtering, set the isolation policy by category and risk, and operate it — delivering browser isolation as part of the managed web defence we run.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us