Skip to content
Avanet

Sophos Protected Browser: overview and dashboard

Sophos Protected Browser is a secure, policy-based enterprise browser managed in Sophos Fusion. It enforces policies in the browser session, protecting access to SaaS services and internal web applications. For an initial overview, My Products > Protected Browser > Dashboard guides you through setup and then shows users, blocked risky browsing attempts and—if enabled—DNS usage from protected computers.

The most important operational principle is that Protected Browser, ZTNA and DNS Protection are separate products. Protected Browser can use the other two protection layers, but it does not take over all their configuration or reporting.

Prerequisites, roles and licensing

Clarify four points before setup:

  • The tenant has an active Workspace Protection licence. It includes Protected Browser, ZTNA, DNS Protection for endpoints and Sophos Email Monitoring System. The standalone option does not include a full Sophos Endpoint licence; Endpoint is only available separately or in the Sophos Endpoint Plus Workspace Protection bundle.
  • Users or directories exist in Sophos Fusion. Without assignable users, you cannot deploy the web policy meaningfully or assess usage correctly.
  • Plan a web policy before distributing browsers. This lets you validate a pilot with a deliberately limited user group.
  • Choose the deployment model: the full Protected Browser or the extension for a managed Chromium browser.

Licensing

Protected Browser is licensed by unique authenticated users over 30 days; the same user on several devices counts once. For the Workspace Protection bundle, the highest usage of any included product determines the required bundle quantity. A trial licence lasts 30 days. After expiry, the Workspace Protection products are no longer available in Sophos Fusion, but their configuration remains and reappears after renewal. The Sophos Fusion licensing guide covers activation, quantity checks and renewal.

No dedicated minimum role is documented for Protected Browser. The assigned administrative role must permit the intended pages and changes. If My Products > Protected Browser or edit actions are missing despite an active licence, check the account’s permissions first rather than assuming a particular role.

Protected Browser installation options

The full browser offers greater protection depth and is the appropriate choice for critical web applications. It supports Windows on 64-bit devices and macOS on Intel and Apple silicon devices.

The Protected Browser extension adds policies and visibility to existing managed Chromium browsers, including Chrome, Microsoft Edge and Atlas. It requires device management or central browser management such as Microsoft Intune, Jamf, Active Directory GPO or Google Enterprise Core. It is not equivalent to the full browser: agentless RDP and SSH resources, endpoint health assessment, screen recording or screen-sharing controls, and private browsing are not supported by the extension.

Other Sophos products

Protected Browser can use ZTNA and DNS Protection with Sophos Endpoint as additional protection layers. These remain separate products: their configuration and reporting do not take place entirely in the Protected Browser area. For SaaS applications, Sophos can also enforce the full Protected Browser through Conditional Access with Entra ID or Okta. Authentication then uses a selected ZTNA data-plane region. This is a separate integration decision, not a prerequisite for basic browser operation.

Set up Protected Browser

Under Set up Protected Browser, the dashboard provides links to each task. The reliable sequence is:

  1. Set up users and directories. Select a small, clearly identifiable user group for the pilot.
  2. Configure the web policy. Give the pilot group a comprehensible web policy with known allowed and blocked actions.
  3. Deploy Protected Browser. Distribute either the full browser or the extension. Windows and macOS methods, plus bulk deployment with Microsoft Intune or Jamf Pro, are available for the full browser. Deploy the extension through the appropriate central browser-management service.
  4. Optionally deploy further protection. Add DNS Protection with Sophos Endpoint and ZTNA only when the relevant use case is ready. Their policies, identities, gateways and reports remain in their respective product areas.

This article provides an overview rather than every platform-specific installation procedure. Before a broad rollout, test one pilot user on a supported device. Do not expand the deployment or policy until sign-in, permitted access and an expected block work as intended.

Read the dashboard and make decisions

My Products > Protected Browser > Dashboard provides the setup and operational overview. You cannot configure policies on this page.

Set up Protected Browser

This area shows the required setup tasks and links to each step. If a step remains visible or incomplete, check user assignment, the web policy and deployment in that order. The dashboard does not replace validation on the pilot device.

Protected Browser users

The chart shows the number of Protected Browser users on Windows and macOS devices during the last 28 days. Multiple Platforms identifies users who worked on both Windows and macOS.

The chart reports users and platforms, not the number of installed browsers. You therefore cannot infer the cause of an installation issue from a missing entry. The different 30-day period is also decisive for licensing; do not interpret the 28-day dashboard chart directly as licence usage.

Risky browsing attempts blocked

This chart shows blocked risky browsing attempts from the last seven days and each user’s email address. For analysis, match the displayed address to the affected user and the seven-day period. The widget neither states why an attempt was blocked nor demonstrably includes every web-policy block. A high, low or absent count therefore proves neither a particular policy assignment nor an installation fault.

DNS usage from protected computers

This area appears only when DNS Protection with Sophos Endpoint is used. For the last seven days, it lists the seven protected computers with the most DNS requests. Each computer shows the username, device name or device ID and the number of processed or blocked requests.

The metrics are divided into three groups:

  • Permitted domains counts requests served for permitted domains. View all opens the report generated from the DNS usage by source template.
  • Security blocks counts requests blocked for security reasons. View all opens the report generated from High risk devices.
  • Policy blocks counts requests blocked by a DNS policy. View all opens the detailed report generated from DNS usage by source.

High DNS usage is not automatically an incident. What matters is whether security or policy blocks increase compared with the normal baseline and whether the user, device and period match expected operation. Because the widget covers only seven top devices and seven days, a device’s absence does not prove that it made no DNS requests.

Validate with a limited pilot

A meaningful acceptance test does not need a broad user group:

  1. Sign in one pilot user on a supported Windows or macOS device and actually use the deployed browser or managed extension.
  2. Open an intentionally permitted application and verify directly in the browser that a block specified in the pilot policy takes effect.
  3. Separately, under My Products > Protected Browser > Dashboard, record whether the user appears in Protected Browser users and whether Risky browsing attempts blocked shows an entry for them.
  4. If DNS Protection with Sophos Endpoint is part of the pilot, check DNS usage from protected computers and use View all to open the relevant detailed report.

Policy acceptance succeeds when the pilot can use the permitted resource and the intended block takes effect directly in the browser. Record dashboard observations separately with their respective periods; a missing entry under Risky browsing attempts blocked does not invalidate the browser behaviour observed directly.

Troubleshoot by symptom

Protected Browser or the dashboard is missing: Check the Workspace Protection licence under the account name. If it is active, test again with an authorised administrator account. If the product area remains absent, contact licensing support or Sophos Support; do not broaden a role on the basis of an assumption.

A pilot user is missing from the 28-day chart: First make sure you are reading the correct 28-day period and expected platform. The chart itself provides no cause for a missing user. For further diagnosis, use Protected Browser troubleshooting or Sophos Support rather than inferring a sign-in, assignment or installation fault from the missing entry.

An expected block is missing from the dashboard: Check the correct user and seven-day period, but do not change the policy solely because a dashboard entry is absent. The direct browser test is decisive. Use Protected Browser troubleshooting or Sophos Support for further root-cause analysis.

DNS usage is entirely absent: The widget requires DNS Protection with Sophos Endpoint. First check whether this separate integration is actually used for the pilot device. A Workspace Protection licence alone does not activate it, and Protected Browser does not replace an Endpoint DNS policy.

The extension cannot perform a function: Agentless RDP/SSH, endpoint health checks, screen controls and private browsing are outside its scope. Rather than continuing to adjust the extension policy, evaluate the full Protected Browser as the deployment model.

Safe rollback and operation

No general switch for safely rolling back a full Protected Browser deployment is documented. Therefore, stop at the pilot before responsible staff remove changes to users, policies or deployment. First record the affected group, active web policy, deployment method and last working state. Then reverse the change through the deployment or policy process actually used. An undocumented deletion path must not form part of decommissioning.

When a licence expires, access to Workspace Protection products disappears from Sophos Fusion; the configuration remains for a later renewal. Expiry is therefore not a clean uninstall or decommissioning method.

The full Protected Browser follows an alternating two-week release cycle: one release delivers the new major Chromium version and browser features; the next, two weeks later, delivers changes to the Protected Browser engine on the same major Chromium version. Chromium security fixes are provided within no more than 24 hours; the staged rollout completes within 48 hours in total. Each browser version is supported for up to four months, after which older versions are considered End of Life.

During operation, regularly check that pilot and production devices receive updates and that no version remains in use beyond four months. Keep dashboard periods distinct: 28 days for browser users, seven days for risky browsing attempts and DNS usage, and 30 days for licence-relevant user consumption.