Remote Browser Isolation
Executes web content away from the endpoint so threats never reach it.
Palo Alto Networks Remote Browser Isolation (RBI) safely executes potentially malicious web content in an isolated cloud environment, blocking threats before they reach the endpoint while giving users a seamless browsing experience. Part of the Prisma SASE platform, it protects users from risky and unknown websites without blocking access outright. Faltrox deploys and operates it as an isolation layer of web defence.
Overview
What Remote Browser Isolation is
Some websites are too risky to allow directly but too useful or ambiguous to block outright — and web-based threats increasingly reach users through the browser. Remote Browser Isolation solves this by executing web content in an isolated cloud environment and streaming only a safe rendering to the user, so malicious code never touches the endpoint.
Modern RBI avoids the poor experience of older pixel-pushing approaches, safely executing malicious content away from the device, blocking threats, and providing visibility into risky browsing — while keeping the user experience seamless. As part of Prisma SASE and integrated with Prisma Access, it adds an isolation layer for risky and unknown sites without an all-or-nothing block. Faltrox deploys it, sets the isolation policy, and operates it as part of managed web defence.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Risky & Unknown Sites
Isolates access to risky, uncategorised, and unknown websites without blocking them outright.
Web-Based Threats
Blocks malicious web content before it can reach the endpoint.
The Endpoint
Keeps the endpoint safe by executing web content away from the device.
Data Interaction
Controls interaction with isolated pages to prevent data leakage.
Browsing Visibility
Provides visibility into risky browsing activity.
Seamless Experience
Delivers a seamless user experience without the lag of legacy isolation.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Route
Access to risky, unknown, or policy-selected sites is routed to the isolation service rather than the endpoint.
- 02
Isolate
The web content is executed in an isolated cloud environment away from the device.
- 03
Render
Only a safe rendering of the page is streamed to the user, so malicious code never reaches the endpoint.
- 04
Control
Interaction with the isolated page — data entry, downloads — is controlled to prevent leakage and threats.
- 05
Operate
Faltrox sets the isolation policy and operates it as part of managed web defence.
Capabilities
Key capabilities
Safe Content Execution
Executes potentially malicious web content in an isolated cloud environment, away from the endpoint.
Threat Blocking
Blocks malicious web content before it can reach or infect the device.
Seamless Experience
Delivers a smooth browsing experience without the lag of legacy pixel-pushing isolation.
Access Without Blocking
Lets users reach risky or unknown sites safely instead of blocking them outright.
Data Interaction Control
Controls data entry, downloads, and interaction with isolated pages to prevent leakage.
Browsing Visibility
Provides visibility into risky browsing activity for security teams.
Part of Prisma SASE
Integrates with Prisma Access as an isolation layer of the SASE platform.
Policy-Driven Isolation
Applies isolation selectively by category, reputation, and risk.
Works with
Part of the platform
Palo Alto Networks products this pairs with, and the Faltrox services that operate it.
Palo Alto Networks products
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Palo Alto Networks Remote Browser Isolation for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01What problem does Remote Browser Isolation solve?
The dilemma of risky-but-useful websites — too dangerous to allow directly but too ambiguous to block outright. RBI lets users reach them safely by executing the web content in an isolated cloud environment and streaming only a safe rendering, so malicious code never touches the endpoint.
02Does it degrade the browsing experience?
Modern RBI avoids the poor experience of older pixel-pushing approaches that rendered everything as images. It safely executes content away from the device while keeping the user experience seamless, so security does not come at the cost of usability.
03How is it different from just blocking the site?
Blocking is all-or-nothing and frustrates users when a site is legitimate; isolation lets them access risky and unknown sites safely instead of blocking them. It is applied selectively by category, reputation, and risk, so you isolate the grey area rather than blocking it.
04How does it fit with URL filtering?
They work together: Advanced URL Filtering blocks known-bad sites, and RBI isolates the risky, unknown, or uncategorised grey area rather than blocking it — a layered approach to web defence. Faltrox designs the policy across both.
05How does Faltrox operate it?
We integrate RBI with Prisma Access and URL filtering, set the isolation policy by category and risk, and operate it — delivering browser isolation as part of the managed web defence we run.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us