9.5 Explicit Proxy, Prisma Access Browser & Remote Browser Isolation

Key Takeaways

  • Prisma Access supports five mobile-user connection methods — agentless SAML, agentless Kerberos, Proxy Mode on Agent, Proxy Mode on Remote Networks, and Prisma Browser — and only Proxy Mode on Agent and Prisma Browser carry private application traffic.
  • Explicit Proxy uses HTTP CONNECT driven by a PAC file, supports inline PAC editing, SNI spoofing prevention, and no-default-route branch deployments combining remote networks with Explicit Proxy, and its users appear in Activity Insights as Agentless Proxy Users.
  • The Prisma Access Browser executes web content locally in a managed Chromium browser and enforces last-mile controls over copy, paste, downloads, printing, and screenshots; it requires an add-on Prisma Browser license on top of a Prisma Access enterprise, business premium, or ZTNA license.
  • Remote Browser Isolation loads websites in a protected air-gapped environment and requires a minimum of Prisma Access 5.0 Innovation with a Mobile User or Remote Networks subscription and an RBI license; third-party RBI integrates through CloudBlades using URL categorization and URL rewrite.
  • Secure agentless access to public web applications with RBI requires Prisma Access 6.1 Preferred, PAN-OS dataplane 11.2.7, a Mobile User subscription, an RBI license, and Cloud Identity Engine, and enforces a 30-minute idle timeout and a 3-hour authentication token expiry.
Last updated: September 2026

9.5 Explicit Proxy, Prisma Access Browser & Remote Browser Isolation

Why This Section Exists

Blueprint task 6.2 asks you to "identify and describe the components used to maintain connectivity and security of remote users," and the datasheet's own audience section enumerates them explicitly: client-based, proxy-based, Enterprise Browser, and RBI. Sections 9.1 and 9.2 covered the client-based option, GlobalProtect. This section covers the other three, which is where most study material stops short and where a disproportionate number of Connectivity and Security items live.

The design question the exam keeps asking is: the user is unmanaged, or the device cannot run an agent, or a contractor needs one application for two weeks — now what?


Prisma Access Mobile Users: Five Connection Methods

Prisma Access supports five documented ways for a mobile user's traffic to reach the cloud. Learn the differences, because scenario questions are decided by the columns below.

Agentless SAMLAgentless KerberosProxy Mode on AgentProxy Mode on Remote NetworksPrisma Browser
Requires GlobalProtect appNoNoYes (GP 6.2 or later)NoNo
Transport channel to Prisma AccessHTTP CONNECTHTTP CONNECTHTTP CONNECT inside TLSHTTP CONNECT inside IPSec from branchHTTP CONNECT inside TLS
EnvironmentsWindows, Mac, Linux, ChromeOS, VDIWindows, Mac, Linux, ChromeOS, VDIWindows and MacAny HTTP proxy device with skip authenticationWindows, Mac, Android, iOS
Traffic typeInternet and public SaaS onlyInternet and public SaaS onlyInternet, public SaaS, and private applicationsInternet and public SaaS onlyInternet, public SaaS, and private applications
ProtocolsProxy-aware HTTP/HTTPSProxy-aware HTTP/HTTPSProxy-aware HTTP/HTTPS; all TCP traffic with GlobalProtect 6.3.1Proxy-aware HTTP/HTTPSProxy-aware HTTP/HTTPS
LicensingMobile User unit per userMobile User unit per userMobile User unit per userMobile User unit per user, plus NET units for remote-network bandwidth or site-based licensing for headless devicesPrisma Access enterprise, or business premium, or ZTNA license with the add-on Prisma Browser license

Exam Trap Alert: Only two of the five methods carry private application traffic — Proxy Mode on Agent and Prisma Browser. The three purely proxy-based methods handle internet and public SaaS traffic only. If a scenario needs an unmanaged device to reach an internal application, agentless SAML explicit proxy is the wrong answer.


Explicit Proxy in Detail

Explicit Proxy is the proxy-based option: the endpoint is told, usually by a PAC (proxy auto-config) file, to send web traffic to a Prisma Access proxy endpoint using HTTP CONNECT rather than routing it through a tunnel. It is the natural migration path for organisations that already run an on-premises web proxy, because the client-side configuration model is unchanged.

Why Enterprises Choose It

  • VDI and thin clients where installing and updating an agent per session is impractical.
  • Unmanaged or third-party devices on which you have no right to install software.
  • Linux and ChromeOS fleets that the GlobalProtect agent does not target.
  • Migration from a legacy proxy where PAC files and proxy settings are already deployed and governed.

Documented Capabilities

  • Inline PAC file editing in the cloud-managed interface, so proxy logic is versioned with the tenant rather than in a separate web server.
  • No-default-route branch deployments: sites that have no default route can combine remote networks with Explicit Proxy, so users and servers forward traffic to Prisma Access with the PAC file while security inspection is performed by a remote network Security Processing Node (RN-SPN).
  • SNI spoofing prevention, which protects against attacks where the Server Name Indication domain does not match the domain used in the HTTP request or HTTP CONNECT request.
  • URL filtering category support including Command and Control Domains, Malware Domains, Dynamic DNS Hosted Domains, Grayware Domains, Newly Registered Domains, Parked Domains, Phishing Domains, and Proxy Avoidance and Anonymizers.
  • Best Practice Assessment for Explicit Proxy policies in the cloud-managed interface.

Monitoring

Explicit Proxy users appear under Insights > Activity Insights > Users with the connection method Agentless Proxy Users. If a troubleshooting scenario reports "the user is authenticating but no traffic is logged," that view is the first place to confirm whether Prisma Access ever saw the session.


Prisma Access Browser (Enterprise Browser)

The enterprise browser is a managed Chromium-based browser that becomes the security enforcement point itself. Instead of securing the network path to an application, it secures the last mile inside the browser, where the data actually lands.

Because the controls execute in the rendering engine, the browser can enforce actions the network never sees:

Control classExamples
Data egressBlock or watermark screenshots, restrict copy/paste out of a corporate web app, block printing, block downloads
Data ingressRestrict uploads and paste into unsanctioned sites and generative-AI prompts
SessionDevice posture gating before the session opens, session recording, forced re-authentication
AccessReach both internet/SaaS and private applications without a VPN agent

The archetypal use cases are BYOD and third-party contractor access: the contractor installs the browser, gets scoped access to the two applications they need, and the organisation retains control of copy, download, and screenshot behaviour without managing the endpoint. Licensing, as the table above shows, requires an add-on Prisma Browser license on top of a Prisma Access enterprise, business premium, or ZTNA license.

Prisma Access can also integrate a third-party enterprise browser with Explicit Proxy, for organisations standardised on another vendor's browser.


Remote Browser Isolation (RBI)

RBI protects managed users through isolation: websites load in a protected, air-gapped environment rather than on the endpoint, and only a safe rendering of the page reaches the user. Active web content never executes on the corporate device, which neutralises browser-based exploitation, malicious scripts, and drive-by downloads from categories you cannot simply block.

Two Integration Models

ModelHow it worksRequirements
Native Palo Alto Networks RBIConfigured in Strata Cloud Manager under Configuration > NGFW and Prisma Access > Configuration Scope > Global > Setup > Remote Browser Isolation; traffic in selected URL categories is redirected into the isolation serviceMinimum Prisma Access version 5.0 Innovation, a Prisma Access license with a Mobile User or Remote Networks subscription, and an RBI license
Third-party RBI via CloudBladeIntegrates with third-party RBI clouds by leveraging existing NGFW URL categorization and URL rewrite features to forward selected or all internet-bound traffic to the RBI cloud; Proofpoint is a documented technology partner using URL response page redirectPrisma Access with the relevant CloudBlade and a third-party RBI subscription

The selective model is the one worth understanding architecturally: unknown or high-risk categories are forwarded to RBI for additional inspection while the remaining traffic is inspected by Prisma Access and egresses directly to the internet. You are not isolating the whole internet, only the part where the risk-to-productivity trade-off justifies it.

Secure Agentless Access to Public Web Applications

RBI also underpins agentless access to public web applications, and the documented requirements are specific:

  • Minimum Prisma Access version 6.1 Preferred and minimum PAN-OS dataplane version 11.2.7.
  • A Prisma Access license with a Mobile User subscription.
  • An RBI license for data controls on SaaS applications.
  • Cloud Identity Engine (CIE) for user authentication (see section 6.2).
  • A Network Administrator or Superuser role to configure it.

Session behaviour is bounded by two timeouts: an idle timeout of 30 minutes, after which the session is cleaned up, an alert is generated, and the user must re-authenticate; and an authentication token expiration of 3 hours, after which re-authentication is required for new application access.

Documented Limitations

These appear in the RBI known-issues list and are exactly the kind of detail a scenario question turns on:

  • IPv6-enabled endpoints cannot browse in isolation after traffic is redirected. The workaround is to disable IPv6 on the device or network so traffic uses IPv4.
  • OAuth-based authentication is not fully supported in isolation; single sign-on that appears in a pop-up requires additional user input to complete.
  • On RBI running on Prisma Access 5.2.1 Preferred (PAN-OS 10.2.10 dataplane) or earlier, users and groups derived from on-premises Active Directory are not supported — only users and groups based on Cloud Identity Engine work as expected.

Choosing Between Them

Is the device managed and can it run an agent?
    YES -> GlobalProtect (client-based)              [sections 9.1, 9.2]
    NO  -> Does the user need PRIVATE applications?
              YES -> Prisma Access Browser (enterprise browser)
              NO  -> Is a proxy configuration deployable (PAC/system proxy)?
                        YES -> Explicit Proxy (agentless SAML or Kerberos)
                        NO  -> Branch-side: Proxy Mode on Remote Networks

Independently: is the destination risky, unknown, or uncategorised?
    -> Layer Remote Browser Isolation on top of whichever method above applies

RBI is not an alternative to the other three; it is an inspection disposition applied to a subset of destinations, and it composes with any of them.

Exam Trap Alert: Do not confuse the enterprise browser with RBI. The enterprise browser executes web content locally inside a managed, instrumented browser and enforces last-mile data controls. RBI executes web content remotely in an air-gapped environment and streams a safe rendering to whatever browser the user already has. One is about controlling a trusted user's actions; the other is about never letting untrusted code touch the endpoint.

Test Your Knowledge

A manufacturer must give 200 third-party contractors access to two internal web applications for a six-month project. The contractors use their own unmanaged laptops, and the manufacturer cannot install software it will have to support or uninstall. Copy, download, and screenshot activity must be controlled. Which option meets all the requirements?

A
B
C
D
Test Your Knowledge

An administrator has enabled native Remote Browser Isolation for high-risk URL categories. Several users report that isolated pages never load, and all of them are on a network segment where IPv6 was recently enabled. What is the documented cause and workaround?

A
B
C
D
Test Your Knowledge

Which statement correctly distinguishes an enterprise browser from Remote Browser Isolation?

A
B
C
D