Deploy and keep Sophos Protected Browser up to date
Sophos Protected Browser can be installed on individual Windows and Mac devices or deployed with Microsoft Intune or Jamf Pro. Managed users can also receive an email invitation containing a download link. Whichever route is chosen, the rollout should start small and the installed version should be checked: new browser releases alternate every two weeks, Chromium security fixes are distributed automatically and rapidly, and a release is supported for no more than four months.
This guide covers deployment, version control and the lifecycle of the full Sophos Protected Browser. The separate extension for existing browsers has its own installation path and is not deployed here.
Prerequisites, licence and roles
Before downloading, check:
- Tenant and product: My Products > Protected Browser and the Protected Browser section under My Environment > Installers are available in the intended Sophos Central tenant. Workspace Protection includes Protected Browser as one of its components. However, the mere visibility of a menu must not be taken as proof of a specific licence or role entitlement; neither a separate Browser SKU nor a general Central administrator role is documented for the routes described here.
- Windows: 64-bit devices running Windows 10 or Windows 11 and servers running Windows Server 2016 or later are supported. The CPU must support SSE3; Intel Pentium 4 and later are specified. At least 4 GB RAM is required, 8 GB is recommended, together with 20 GB of free storage.
- macOS: macOS Sonoma 14, Sequoia 15 and Tahoe 26 are supported on Intel (
x86) and Apple (arm64) chips. The same memory and storage requirements apply: at least 4 GB RAM, 8 GB recommended, and 20 GB of free storage. - Storage planning: 20 GB is the starting point. Multiple browser profiles or intensive profile use may require more storage.
- Local installation: Local administrator rights may be required for
.exeor.pkgfiles. - Jamf Pro: Bulk installation requires a Jamf Pro administrator account and a Sophos Central administrator account.
- Microsoft Intune: A Microsoft Intune account, a Sophos Central account and, for the Windows package, a Windows account for installation on the target devices are required.
- Email invitation: The invited user must have at least the Read-only role. Without this minimum role, an invitation is not a suitable deployment route.
The listed operating systems are the explicitly documented platforms. Other versions are not inferred from similar Endpoint requirements. Before a broad rollout, also use real user profiles to check whether RAM and storage are sufficient for the organisation’s usage.
Prepare the rollout
Before the first installation, define a pilot group that represents both chip architectures and the operating systems in the eventual target group. For each pilot device, record:
- device name and operating system;
- installation route: manual, invitation, Intune or Jamf Pro;
- expected assignment in Intune or Jamf;
- installation time;
- installed Protected Browser and Chromium version;
- result of launch and sign-in with the work account.
Use unambiguous names for packages and policies, for example Sophos Protected Browser – Pilot. The name can be adapted; the product fields and selection values below must, however, exactly match the relevant management interface.
Download the installer from Sophos Central
The download is the same for manual and centrally managed installation:
- In Sophos Central, open My Environment > Installers.
- Go to the Protected Browser section.
- For Windows, select Download installer for Windows (x64 only).
- For macOS, select Download installer for macOS (Universal - Intel and Apple chip).
- Store the downloaded file in a controlled location and use the same verified download for the pilot and the broader wave.
The documented Windows file is named SophosProtectedBrowserSetUpX64.exe; the macOS file is SophosProtectedBrowserX64.pkg. The X64 in the macOS filename does not change the fact that Sophos supplies this installer as universal for Intel and Apple chips.
Install individual Windows devices
- Check again that the device uses 64-bit Windows and meets the CPU, RAM and storage requirements.
- Open the location of
SophosProtectedBrowserSetUpX64.exe. - Double-click the installer and confirm with Yes. If execution is blocked, use an authorised local administrator account and do not bypass device controls.
- Wait for the installation to finish.
- Start Sophos Protected Browser from the Start menu or desktop.
- Sign in with the work account.
Install individual Mac devices
- Check the macOS version, chip, RAM and free storage.
- Open the location of
SophosProtectedBrowserX64.pkg. - Double-click the installer and click Continue.
- Choose whether to install the browser for all users of the device or only the current user. Agree this decision with the device owner and the rollout scope in advance.
- Click Install and enter the local administrator credentials.
- When complete, click Close.
- Open Finder > Applications > Sophos Protected Browser and sign in with the work account.
Deploy with Microsoft Intune
First download the appropriate installer from My Environment > Installers as described above. Create separate Windows and macOS packages so that requirements, detection and assignment remain traceable.
Create the Windows package
- In Microsoft Intune, open Apps > Windows > Add.
- Under App type, select Line-of-business app.
- Under App information, click Select app package file and select the Windows installer from Sophos Central.
- Click OK and set the fields:
- Name: for example
Sophos Protected Browser – Windows – Pilot - Description: specify the internal purpose and pilot group
- Publisher:
Sophos - App install context: Device
- Ignore app version: Yes
- Name: for example
- Click Next.
- Under Assignments, initially select only the pilot devices.
- Click Next, check Review + create, then click Create.
Intune displays a notification once the package has been created; it is then installed on the selected devices. This notification confirms package creation, not successful launch or sign-in on every target device.
Create the macOS package
- In Microsoft Intune, open Apps > macOS > Add.
- Under App type, select macOS app (.pkg) and click Select.
- Under App information, open Select app package file, select the macOS installer from Sophos Central and click OK.
- Set Name to an unambiguous package name and Publisher to
Sophos. - Under Requirements > Minimum operating system, select the operating-system version of the managed Macs.
- Under Detection rules, enter:
- Ignore app version: Yes
- App bundle ID: the bundle ID determined for Protected Browser
- App version: the version to be installed
- Click Next, select the pilot devices under Assignments, then click Next again.
- Check Review + create and click Create.
An App bundle ID is required for the detection rule, but no fixed value is documented. Do not enter a guessed value. Determine and verify the identifier from the package actually downloaded, using the macOS packaging process employed in the organisation. If that is not possible, stop before assignment and clarify the detection rule with the Intune or Sophos owner.
Deploy to Macs with Jamf Pro
Create the installation package
- Download the universal macOS installer under My Environment > Installers > Protected Browser.
- In Jamf Pro, open Settings > Computer Management > Packages.
- Under General, enter an unambiguous name.
- Under Category, select Browser.
- Under Filename, upload the macOS installer obtained from Sophos Central.
- Click Save.
Create the policy for the pilot group
- Open Computers > Policies.
- Under General, enter an unambiguous policy name.
- Under Category, select Browser again.
- Under Trigger, select the required event. The documented Recurring Check-in example starts the policy when the device next checks in with the Jamf Pro server.
- Under Packages, select the Protected Browser package created earlier.
- Under Scope, limit the first assignment to the pilot devices.
- Click Save.
Invite users by email
The invitation suits managed users who will install the browser themselves from the supplied link. The user follows the email, completes installation and then signs in with the work account.
Invitation from the user list
- Open My Environment > Users & Groups, then the Users tab.
- Select the user and click Email setup link.
- Under Protected Browser, enable Invite user to install Sophos Protected Browser.
- Click Save.
Invitation while editing the user
- Open My Environment > Users & Groups > Users and click the required user.
- Click Edit.
- Under Edit user, open Email setup link.
- Under Protected Browser, enable Invite user to install Sophos Protected Browser.
- Click Save.
In both cases, the expected result is an email containing a browser download link. If it does not arrive, first check the minimum Read-only role, the selected person and the enabled Protected Browser option before sending it again.
Validate installation and version
A deployment platform alone does not provide a complete functional test. For each pilot platform, check:
- Installation: Sophos Protected Browser is present on the target device.
- Launch: The browser opens.
- Sign-in: Sign-in with the intended work account succeeds.
- Version in the browser: Open the three-dot menu at the top right and select About Sophos Protected Browser. The page shows the current version and whether it is up to date.
- Windows cross-check: Open Settings > Apps > Installed apps and search for Sophos Protected Browser.
- Mac cross-check: Open Apple menu > About > General > System Report, expand Software, open Applications and search for Sophos Protected Browser.
In the browser, the display follows this pattern:
Version [Protected Browser_generation].[Protected Browser_major].[Protected Browser_minor] Chromium [Chromium_major].[Chromium_minor].[Chromium_patch].[Chromium_build] ([build_type]) ([processor])
A documented example is Version 1.86.23 Chromium 145.0.7632.160 (Official Build) (64-bit). At device level, Windows and macOS show four groups following [Chromium_major].[Protected Browser_generation].[Protected Browser_major].[Protected Browser_minor], for example 145.1.86.23. Compare values according to this structure; the device display should not be considered newer merely because it begins with the Chromium major version.
Only expand the assignment after installation, launch, sign-in and the version display have succeeded on all representative pilot devices.
Plan updates and lifecycle
Protected Browser uses an alternating two-week release cycle:
- At the start of the month, a release provides the latest Chromium major version and new Protected Browser features.
- Two weeks later, a release updates only the Protected Browser engine; the Chromium major version remains unchanged.
- Two weeks after that, the next cycle starts with a new Chromium major version.
The documented 30-day example moves from Protected Browser 1.50.x with Chromium 129 to 1.51.x with the same Chromium major version, and then to 1.52.x with Chromium 130. These numbers explain the scheme and are not target versions for the organisation’s tenant.
Chromium security fixes are made available automatically within 24 hours or less of publication by the Chromium team. Sophos then rolls out the updated version in stages over a further 12 to 24 hours; total deployment time is no more than 48 hours. A short-lived difference between two pilot devices can therefore be part of the staged rollout. It must not, however, remain unchecked beyond the documented period.
Each browser release is supported for up to four months after its initial publication:
| Phase | Release age | Meaning |
|---|---|---|
| Current release | first two weeks | current version |
| Keep previous release | two weeks to three months | still supported |
| Near end of life | three to four months | prioritise update |
| End of life | more than four months | unsupported release |
Sophos recommends the latest version. Outdated browsers may provide less performance and protection. The operating process should therefore check the version display at least monthly and additionally after every security fix or new major version. No control for holding back browser updates and no downgrade procedure are documented. An old package must therefore not be deployed as a rollback.
Troubleshooting by symptom
Installer or Protected Browser section is missing
Check that the correct tenant is open and that My Products > Protected Browser and My Environment > Installers > Protected Browser are visible. Do not infer an additional role or licence from this. If the section is missing, stop the rollout and have the tenant, licence or role owner check enablement.
Windows installation does not start
First check 64-bit Windows, a supported operating-system version, an SSE3-capable CPU, at least 4 GB RAM and 20 GB free storage. Then check whether the .exe installation requires local administrator rights. Do not use any installer other than Download installer for Windows (x64 only).
Mac installation or launch fails
Compare the device with macOS Sonoma 14, Sequoia 15 or Tahoe 26 and check the Intel or Apple chip, RAM and free storage. Administrator rights may be required for manual installation. After successful installation, launch the browser from Finder > Applications.
Intune reports a created package, but the browser is missing
The creation message proves only that Intune created the package. Check the platform, selected package file and Assignments. For Windows, App install context: Device and Ignore app version: Yes must be set. For macOS, check Minimum operating system, App bundle ID, App version and the pilot assignment. If the bundle ID has not been reliably determined, correct the detection rule before expanding the assignment.
Jamf policy does not run
Under Settings > Computer Management > Packages, check that the correct package is stored. Then compare the Category of Browser, selected Trigger, package and Scope under Computers > Policies. With Recurring Check-in, execution is triggered only at the device’s next check-in with the Jamf Pro server.
Invitation does not arrive
Make sure the user has at least the Read-only role. Under My Environment > Users & Groups > Users, check that the correct user is selected, Email setup link is open and Invite user to install Sophos Protected Browser is enabled. Only then save or invite again.
Version numbers do not appear to match
Do not compare only the number of digit groups. In the browser, the three-part Protected Browser version begins with the generation; on Windows and macOS, the Chromium major version precedes it. Also open About Sophos Protected Browser to see the full Chromium version and the up-to-date indication.
Devices remain on different versions during rollout
First allow for the staged security-fix rollout with a total deployment time of no more than 48 hours. Then check the version display and up to date status on every affected device. If a device is still outdated after this window, do not broaden the assignment. No repair or downgrade process is documented for this case; record the device, operating system, installation route, time and both version displays, then hand the case to Sophos Support.
Safe rollback, removal and rollout stop
There is no product-specific uninstall process documented for Windows, macOS, Intune or Jamf Pro. Nor is there a reliable browser downgrade process. Therefore, do not delete files manually or deploy old packages as a supposed rollback.
For a safe stop before broad deployment:
- Do not expand the Scope or Assignments beyond the pilot group.
- Record the package, policy, trigger, target group and devices already installed.
- Check whether a change in Intune or Jamf unintentionally affects more devices. Remove an assignment only after checking the valid procedure for the relevant management platform.
- Leave existing installations unchanged until a current, verified uninstall route is available. Manually deleting programme files is not a rollback.
- After stopping, validate that no further pilot devices are being installed and escalate any required removal with the documented device and package status.
The same safety principle applies to a problematic new browser version: limit the rollout, preserve versions and times, and escalate the case. A downgrade can reduce protection and support status; no reliable downgrade route is documented.
Operations, review and lifecycle
The operations owner should regularly check:
- supported Windows, Windows Server and macOS versions before every new wave;
- RAM and free storage, particularly with multiple browser profiles;
- Intune assignments or Jamf scope, package and trigger;
- successful launch and sign-in with a work account;
- Protected Browser and Chromium versions through About Sophos Protected Browser;
- device display under Settings > Apps > Installed apps or System Report > Software > Applications;
- release age against the four-month limit;
- deviations after the maximum 48-hour security-update rollout.
A new Chromium major release, a move into the “near end of life” phase or an outdated pilot device triggers another version review.
As non-operational background, product development can be placed in context with five milestones: Protected Browser was introduced as Early Access on 20 January 2026; Workspace Protection became available on 16 March 2026. App category selection and reporting for file uploads and downloads followed on 1 July. The separate Protected Browser extension for existing browsers was announced on 20 July. Guided workflows for zero-trust protection of SaaS applications were added later. This development changes neither the installation route described nor the current version and lifecycle checks.
Related existing guide
Protected Browser has its own installation path. If Sophos Endpoint Protection is also to be rolled out, Deploy Sophos Endpoint Protection covers its installer, device enrolment and validation. Do not mix the two procedures: a successful Endpoint rollout does not prove that Protected Browser is installed or up to date.