Zscaler & Zero Trust operations glossary ยท Policy hygiene & operations

What is Browser Isolation?

Definition

Browser Isolation does not load risky or hard-to-classify web content directly on the endpoint. It renders that content in a separate cloud environment instead. The user sees only a safe, interactive image of the page, while the actual page code never runs on the local device. Even if a website carries malicious code, the endpoint stays untouched, because only screen content is transmitted, never active code. That makes Browser Isolation particularly effective against threats that classic URL filtering alone cannot reliably classify.

Browser Isolation in detail

Technically, a cloud instance renders the requested web page and sends the endpoint only a visual, interactive representation, roughly comparable to a video stream of the page. Clicks, scrolling and input still work normally for the user, but the actual page code stays entirely inside the isolated environment.

Isolation is usually applied selectively rather than to all traffic, for example to higher-risk categories, newly registered domains, or access from unmanaged devices. The policy in place decides which cases get isolated.

Why Browser Isolation matters in Zscaler operations

Not every risky site fits cleanly into one category or can be blocked outright without getting in the way of legitimate work. Isolation offers a middle path. Access stays possible, and the risk to the endpoint still drops significantly. That matters most for borderline cases, where neither blocking nor unrestricted access would be ideal.

As with sandboxing, isolation is often part of the licence you already hold, but it is not switched on everywhere. An unused security feature means unused protection that the company has already paid for.

Common sources of error

Browser Isolation in practice: what CentaurNexus contributes

As part of the licence health check, Policy Health Saga shows whether Browser Isolation is configured and active for the risk categories that matter, instead of leaving a paid protection feature unused. That makes it easy to target the areas with the biggest security gain. More on feature usage in the guide Getting more from your Zscaler licence.

See in the live demo which protection features your licence already covers.Watch the live demo

Related terms

Frequently asked questions about Browser Isolation

Does the user notice that a page is shown in isolation?

That depends on the configured mode. Zscaler offers two display options. In Native Browser Experience, the isolation menu and controls stay hidden by default, so browsing feels close to normal. In Browser-in-Browser Experience, the isolated session sits visibly inside its own editable address bar. Small differences, for example around file downloads, can still show up in either mode.

Which sites is Browser Isolation typically used for?

Most often for higher-risk categories, such as newly registered or hard-to-classify domains, and for access from personal or unmanaged devices. The policy in place decides the exact scope; not all traffic runs isolated by default.

Does Browser Isolation replace a Cloud Sandbox?

No, the two address different attack paths. Cloud Sandbox checks files through behavioural analysis before delivery, while Browser Isolation stops web content from ever making direct contact with the endpoint. In practice, the two mechanisms complement each other.

Does Browser Isolation work on personal devices too?

This is one of the typical use cases, because classic endpoint security has no reach on unmanaged devices. Since only a safe image of the page gets transmitted, the device itself stays untouched by malicious code on the website.

Does Browser Isolation cost performance?

Because content is rendered and transmitted through a cloud environment, connection quality can bring noticeable but usually small delays. That is why isolation is normally switched on for risk-bearing categories specifically, rather than for all traffic.

Sources & further reading:

Note: CentaurNexus is an independent product of SourcingBlox GmbH and not an offering of Zscaler, Inc. Product and brand names belong to their respective owners.