9.5 Explicit Proxy, Prisma Access Browser & Remote Browser Isolation
Key Takeaways
- Prisma Access supports five mobile-user connection methods — agentless SAML, agentless Kerberos, Proxy Mode on Agent, Proxy Mode on Remote Networks, and Prisma Browser — and only Proxy Mode on Agent and Prisma Browser carry private application traffic.
- Explicit Proxy uses HTTP CONNECT driven by a PAC file, supports inline PAC editing, SNI spoofing prevention, and no-default-route branch deployments combining remote networks with Explicit Proxy, and its users appear in Activity Insights as Agentless Proxy Users.
- The Prisma Access Browser executes web content locally in a managed Chromium browser and enforces last-mile controls over copy, paste, downloads, printing, and screenshots; it requires an add-on Prisma Browser license on top of a Prisma Access enterprise, business premium, or ZTNA license.
- Remote Browser Isolation loads websites in a protected air-gapped environment and requires a minimum of Prisma Access 5.0 Innovation with a Mobile User or Remote Networks subscription and an RBI license; third-party RBI integrates through CloudBlades using URL categorization and URL rewrite.
- Secure agentless access to public web applications with RBI requires Prisma Access 6.1 Preferred, PAN-OS dataplane 11.2.7, a Mobile User subscription, an RBI license, and Cloud Identity Engine, and enforces a 30-minute idle timeout and a 3-hour authentication token expiry.
9.5 Explicit Proxy, Prisma Access Browser & Remote Browser Isolation
Why This Section Exists
Blueprint task 6.2 asks you to "identify and describe the components used to maintain connectivity and security of remote users," and the datasheet's own audience section enumerates them explicitly: client-based, proxy-based, Enterprise Browser, and RBI. Sections 9.1 and 9.2 covered the client-based option, GlobalProtect. This section covers the other three, which is where most study material stops short and where a disproportionate number of Connectivity and Security items live.
The design question the exam keeps asking is: the user is unmanaged, or the device cannot run an agent, or a contractor needs one application for two weeks — now what?
Prisma Access Mobile Users: Five Connection Methods
Prisma Access supports five documented ways for a mobile user's traffic to reach the cloud. Learn the differences, because scenario questions are decided by the columns below.
| Agentless SAML | Agentless Kerberos | Proxy Mode on Agent | Proxy Mode on Remote Networks | Prisma Browser | |
|---|---|---|---|---|---|
| Requires GlobalProtect app | No | No | Yes (GP 6.2 or later) | No | No |
| Transport channel to Prisma Access | HTTP CONNECT | HTTP CONNECT | HTTP CONNECT inside TLS | HTTP CONNECT inside IPSec from branch | HTTP CONNECT inside TLS |
| Environments | Windows, Mac, Linux, ChromeOS, VDI | Windows, Mac, Linux, ChromeOS, VDI | Windows and Mac | Any HTTP proxy device with skip authentication | Windows, Mac, Android, iOS |
| Traffic type | Internet and public SaaS only | Internet and public SaaS only | Internet, public SaaS, and private applications | Internet and public SaaS only | Internet, public SaaS, and private applications |
| Protocols | Proxy-aware HTTP/HTTPS | Proxy-aware HTTP/HTTPS | Proxy-aware HTTP/HTTPS; all TCP traffic with GlobalProtect 6.3.1 | Proxy-aware HTTP/HTTPS | Proxy-aware HTTP/HTTPS |
| Licensing | Mobile User unit per user | Mobile User unit per user | Mobile User unit per user | Mobile User unit per user, plus NET units for remote-network bandwidth or site-based licensing for headless devices | Prisma Access enterprise, or business premium, or ZTNA license with the add-on Prisma Browser license |
Exam Trap Alert: Only two of the five methods carry private application traffic — Proxy Mode on Agent and Prisma Browser. The three purely proxy-based methods handle internet and public SaaS traffic only. If a scenario needs an unmanaged device to reach an internal application, agentless SAML explicit proxy is the wrong answer.
Explicit Proxy in Detail
Explicit Proxy is the proxy-based option: the endpoint is told, usually by a PAC (proxy auto-config) file, to send web traffic to a Prisma Access proxy endpoint using HTTP CONNECT rather than routing it through a tunnel. It is the natural migration path for organisations that already run an on-premises web proxy, because the client-side configuration model is unchanged.
Why Enterprises Choose It
- VDI and thin clients where installing and updating an agent per session is impractical.
- Unmanaged or third-party devices on which you have no right to install software.
- Linux and ChromeOS fleets that the GlobalProtect agent does not target.
- Migration from a legacy proxy where PAC files and proxy settings are already deployed and governed.
Documented Capabilities
- Inline PAC file editing in the cloud-managed interface, so proxy logic is versioned with the tenant rather than in a separate web server.
- No-default-route branch deployments: sites that have no default route can combine remote networks with Explicit Proxy, so users and servers forward traffic to Prisma Access with the PAC file while security inspection is performed by a remote network Security Processing Node (RN-SPN).
- SNI spoofing prevention, which protects against attacks where the Server Name Indication domain does not match the domain used in the HTTP request or HTTP CONNECT request.
- URL filtering category support including Command and Control Domains, Malware Domains, Dynamic DNS Hosted Domains, Grayware Domains, Newly Registered Domains, Parked Domains, Phishing Domains, and Proxy Avoidance and Anonymizers.
- Best Practice Assessment for Explicit Proxy policies in the cloud-managed interface.
Monitoring
Explicit Proxy users appear under Insights > Activity Insights > Users with the connection method Agentless Proxy Users. If a troubleshooting scenario reports "the user is authenticating but no traffic is logged," that view is the first place to confirm whether Prisma Access ever saw the session.
Prisma Access Browser (Enterprise Browser)
The enterprise browser is a managed Chromium-based browser that becomes the security enforcement point itself. Instead of securing the network path to an application, it secures the last mile inside the browser, where the data actually lands.
Because the controls execute in the rendering engine, the browser can enforce actions the network never sees:
| Control class | Examples |
|---|---|
| Data egress | Block or watermark screenshots, restrict copy/paste out of a corporate web app, block printing, block downloads |
| Data ingress | Restrict uploads and paste into unsanctioned sites and generative-AI prompts |
| Session | Device posture gating before the session opens, session recording, forced re-authentication |
| Access | Reach both internet/SaaS and private applications without a VPN agent |
The archetypal use cases are BYOD and third-party contractor access: the contractor installs the browser, gets scoped access to the two applications they need, and the organisation retains control of copy, download, and screenshot behaviour without managing the endpoint. Licensing, as the table above shows, requires an add-on Prisma Browser license on top of a Prisma Access enterprise, business premium, or ZTNA license.
Prisma Access can also integrate a third-party enterprise browser with Explicit Proxy, for organisations standardised on another vendor's browser.
Remote Browser Isolation (RBI)
RBI protects managed users through isolation: websites load in a protected, air-gapped environment rather than on the endpoint, and only a safe rendering of the page reaches the user. Active web content never executes on the corporate device, which neutralises browser-based exploitation, malicious scripts, and drive-by downloads from categories you cannot simply block.
Two Integration Models
| Model | How it works | Requirements |
|---|---|---|
| Native Palo Alto Networks RBI | Configured in Strata Cloud Manager under Configuration > NGFW and Prisma Access > Configuration Scope > Global > Setup > Remote Browser Isolation; traffic in selected URL categories is redirected into the isolation service | Minimum Prisma Access version 5.0 Innovation, a Prisma Access license with a Mobile User or Remote Networks subscription, and an RBI license |
| Third-party RBI via CloudBlade | Integrates with third-party RBI clouds by leveraging existing NGFW URL categorization and URL rewrite features to forward selected or all internet-bound traffic to the RBI cloud; Proofpoint is a documented technology partner using URL response page redirect | Prisma Access with the relevant CloudBlade and a third-party RBI subscription |
The selective model is the one worth understanding architecturally: unknown or high-risk categories are forwarded to RBI for additional inspection while the remaining traffic is inspected by Prisma Access and egresses directly to the internet. You are not isolating the whole internet, only the part where the risk-to-productivity trade-off justifies it.
Secure Agentless Access to Public Web Applications
RBI also underpins agentless access to public web applications, and the documented requirements are specific:
- Minimum Prisma Access version 6.1 Preferred and minimum PAN-OS dataplane version 11.2.7.
- A Prisma Access license with a Mobile User subscription.
- An RBI license for data controls on SaaS applications.
- Cloud Identity Engine (CIE) for user authentication (see section 6.2).
- A Network Administrator or Superuser role to configure it.
Session behaviour is bounded by two timeouts: an idle timeout of 30 minutes, after which the session is cleaned up, an alert is generated, and the user must re-authenticate; and an authentication token expiration of 3 hours, after which re-authentication is required for new application access.
Documented Limitations
These appear in the RBI known-issues list and are exactly the kind of detail a scenario question turns on:
- IPv6-enabled endpoints cannot browse in isolation after traffic is redirected. The workaround is to disable IPv6 on the device or network so traffic uses IPv4.
- OAuth-based authentication is not fully supported in isolation; single sign-on that appears in a pop-up requires additional user input to complete.
- On RBI running on Prisma Access 5.2.1 Preferred (PAN-OS 10.2.10 dataplane) or earlier, users and groups derived from on-premises Active Directory are not supported — only users and groups based on Cloud Identity Engine work as expected.
Choosing Between Them
Is the device managed and can it run an agent?
YES -> GlobalProtect (client-based) [sections 9.1, 9.2]
NO -> Does the user need PRIVATE applications?
YES -> Prisma Access Browser (enterprise browser)
NO -> Is a proxy configuration deployable (PAC/system proxy)?
YES -> Explicit Proxy (agentless SAML or Kerberos)
NO -> Branch-side: Proxy Mode on Remote Networks
Independently: is the destination risky, unknown, or uncategorised?
-> Layer Remote Browser Isolation on top of whichever method above applies
RBI is not an alternative to the other three; it is an inspection disposition applied to a subset of destinations, and it composes with any of them.
Exam Trap Alert: Do not confuse the enterprise browser with RBI. The enterprise browser executes web content locally inside a managed, instrumented browser and enforces last-mile data controls. RBI executes web content remotely in an air-gapped environment and streams a safe rendering to whatever browser the user already has. One is about controlling a trusted user's actions; the other is about never letting untrusted code touch the endpoint.
A manufacturer must give 200 third-party contractors access to two internal web applications for a six-month project. The contractors use their own unmanaged laptops, and the manufacturer cannot install software it will have to support or uninstall. Copy, download, and screenshot activity must be controlled. Which option meets all the requirements?
An administrator has enabled native Remote Browser Isolation for high-risk URL categories. Several users report that isolated pages never load, and all of them are on a network segment where IPv6 was recently enabled. What is the documented cause and workaround?
Which statement correctly distinguishes an enterprise browser from Remote Browser Isolation?