Configure Safe AI Controls with Sophos Protected Browser
Safe AI Controls set two distinct boundaries: Protected-Browser-Internetrichtlinien control which generative AI applications a user group can use and which data actions are permitted in them. DNS Protection for Endpoints blocks selected GenAI domains across all browsers on managed endpoints. This lets you allow approved services selectively and block unapproved services either in Protected Browser only or in all browsers.
Decide on the outcome before configuring
First choose the outcome you need. The four options do not automatically build on one another:
- Block unauthorised GenAI apps in Protected Browser only: An application group containing the unwanted apps is assigned a web policy with Blockieren.
- Block unauthorised GenAI apps in all browsers: DNS Protection for endpoints uses a custom domain list with the Blockieren action.
- Allow authorised GenAI apps but prevent uploads and copying: The web policy uses Alle Uploads blockieren and Daten innerhalb der Ziele dieser Richtlinie halten.
- Use authorised GenAI apps with uploads and pasting, but prevent copying out: The web policy uses Daten innerhalb der Ziele dieser Richtlinie behalten – Einfügen von außen erlauben.
Start with a small, clearly named user group. This makes it clear who is testing the new boundary before you assign more groups.
Requirements, licensing and roles
No specific licence, administrator role, platform, identity, certificate or agent requirement is documented for this procedure. Before making a change, therefore, check that the required areas and objects are available:
- Meine Produkte > Protected Browser > Richtlinienobjekte and Meine Produkte > Protected Browser > Internetrichtlinie are accessible if you are implementing a Protected Browser option.
- Meine Produkte > DNS Protection > Richtlinien and Meine Produkte > DNS Protection > Domänenlisten are accessible if you want to block across all browsers.
- The intended user group can be selected under Verfügbar.
- The GenAI apps you want to control appear under Generative KI, or you know their domains or URLs for the DNS list.
If any of these elements is missing or a change cannot be saved, stop at this point. The documented procedure does not specify which licence or role must be added, nor does it describe an alternative setup method. Ask the responsible Sophos administrator to clarify permissions or product provisioning rather than guessing at settings in a different product area.
Option 1: Block GenAI apps in Protected Browser
Create an application group
Create an application group for GenAI apps.
- Open Meine Produkte > Protected Browser > Richtlinienobjekte.
- Select Objekt hinzufügen, then select Anwendungsgruppe.
- Enter a name for the application group. For example:
Blocked Gen AI Apps. - Expand Generative KI and select the unauthorised GenAI apps.
- Select Speichern.
You can choose any name. However, a descriptive name helps prevent the block group from later being confused with a group for approved apps.
Create a blocking web policy
- Open Meine Produkte > Protected Browser > Internetrichtlinie.
- Under Richtlinien, select Richtlinie hinzufügen.
- Enter a name, for example
Blockierte Gen AI-Apps. - Select Blockieren as the Richtlinienmaßnahme.
- Under Benutzergruppe, select Bearbeiten.
- Under Verfügbar, first select the pilot group, move it to Zugewiesen, then select Speichern.
- Under Anwendungsgruppe, select the group containing the unauthorised GenAI apps that you created previously.
- Select Speichern.
Option 2: Allow authorised GenAI apps with strict data boundaries
This option allows access, but blocks file uploads and prevents data from being moved out of the policy’s destinations.
Create an application group for authorised GenAI apps
- Open Meine Produkte > Protected Browser > Richtlinienobjekte.
- Select Objekt hinzufügen.
- Select Anwendungsgruppe and give it a unique name, for example
Authorized Gen AI Apps. - Expand Generative KI and select only the approved apps.
- Select Speichern.
Create a web policy with restrictions
- Open Meine Produkte > Protected Browser > Internetrichtlinie and select Richtlinie hinzufügen.
- Enter a name and select Erlauben as the Maßnahme der Richtlinie.
- Select Edit. Under Verfügbar, select the pilot group, move it to Zugewiesen, then select Speichern.
- Under Anwendungsgruppe, select the group containing the authorised GenAI apps.
- Under Upload-Schutz, select Alle Uploads blockieren.
- Under Datengrenzen, select Daten innerhalb der Ziele dieser Richtlinie halten.
- Select Speichern.
The expected result is deliberately restrictive: assigned users can open the selected apps, but cannot upload files to them or copy data out of the policy’s destinations.
Option 3: Allow uploads and pasting, but prevent copying out
Use this option only if users are permitted to send files to an approved GenAI app and paste data from outside. Data from these apps must still be prevented from leaving the policy’s destinations through copying.
Create the application group as described in Option 2. Then configure the web policy in this order:
- Open Meine Produkte > Protected Browser > Internetrichtlinie and select Richtlinie hinzufügen.
- Enter a name and select Erlauben as the Maßnahme der Richtlinie.
- Select Edit, select the pilot group under Verfügbar, and move it to Zugewiesen.
- Select Speichern to apply the user-group assignment.
- Under Anwendungsgruppe, select the group containing the authorised GenAI apps.
- Under Maßnahmen, in Datengrenzen, select Daten innerhalb der Ziele dieser Richtlinie behalten – Einfügen von außen erlauben.
- Select Speichern to save the policy.
Test this option separately from the stricter policy. Its expected result is intentionally different: uploading and pasting work, but copying data out of the authorised app is prevented.
Option 4: Block unauthorised GenAI apps in all browsers
This option is technically part of DNS Protection for endpoints. It supplements the Protected Browser rules rather than using their application groups.
Turn on DNS Protection for endpoints
- Open Meine Produkte > DNS Protection > Richtlinien.
- Select Endpoint-Richtlinien and open Basisrichtlinie – Endpoint DNS Protection.
- Select Einstellungen.
- Turn on Sophos DNS Protection verwenden.
- Select Speichern.
Add a domain list for GenAI apps
- Open Meine Produkte > DNS Protection > Domänenlisten.
- Select Domänenliste hinzufügen.
- Enter a unique name, for example
Blocked Gen AI Domains. - Under Domänen, enter the domains or URLs of the GenAI applications you want to block.
- Select Speichern.
The example name can be changed; the entries under Domänen, however, must match the services your organisation actually wants to block.
Add the domain list to a DNS Protection policy
- Open Meine Produkte > DNS Protection > Richtlinien and select Filterrichtlinien.
- Open a policy that allows traffic and applies to the users or devices you want to manage.
- Select Einstellungen.
- Under Nach benutzerdefinierten Domänenlisten filtern, turn on Domänenlisten beim Filtern einbeziehen.
- Select Liste hinzufügen and choose the GenAI domain list.
- Select Speichern to add the selected domain list.
- For the added list, under Aktionen, select Blockieren.
- Select Speichern again to save the policy.
The expected result is that the entered GenAI domains are blocked on endpoints covered by this DNS Protection policy, regardless of which browser is used.
Verify the effect with a pilot group
Test each configured option with exactly one assigned test user or one test device covered by the DNS policy. Use only non-sensitive test data.
- Open one selected authorised GenAI app and one unauthorised GenAI app.
- For a blocking policy, verify that the app or entered domain cannot be reached.
- For the strict allow policy, verify that the app can be reached but that a file cannot be uploaded and data cannot be copied out of the destination.
- For the option that permits pasting, verify that uploading and pasting work but copying out of the app is prevented.
- Repeat the access test with a user outside the pilot group. Their experience must not be changed by an accidental assignment of the pilot policy.
Troubleshooting by symptom
No product error messages or additional diagnostic tools are documented for these procedures. Therefore, isolate discrepancies using only the following configuration points.
An unauthorised app remains accessible
Check whether the app is selected in the correct Anwendungsgruppe, the blocking policy actually uses Blockieren, and the test group appears under Zugewiesen. For the cross-browser option, check the entry under Domänen, the Domänenlisten beim Filtern einbeziehen setting, the added list, and its Blockieren action instead.
An authorised app cannot be reached
Check whether the app is included in the authorised application group, the web policy uses Erlauben, and the correct user group is assigned. Do not change upload protection and data boundaries at the same time while the access test itself is still failing.
A data action behaves differently than planned
Compare the selected option word for word with the intended setting: Alle Uploads blockieren plus Daten innerhalb der Ziele dieser Richtlinie halten for the strict option, or Daten innerhalb der Ziele dieser Richtlinie behalten – Einfügen von außen erlauben for the option that permits uploading and pasting. If the result is still unclear, stop the rollout. The documented procedure contains no deeper diagnostic or workaround path.
Safe rollback and decommissioning
No procedure for deleting, disabling or decommissioning the objects described here is documented. Before the rollout, therefore, record the previous assignments and values, and expand the pilot group only after a successful test.
If you need to roll back, do not assume an undocumented deletion sequence. Stop the rollout, record the affected policy, application or domain list, and user group in the change log, and ask the responsible Sophos administrator or Sophos Support to confirm the supported modification or removal path. Then test access and data actions again with the pilot user.
Operation and review
The underlying Sophos instructions were updated on 4 September 2026. During ongoing operation, whenever approved services, their domains or the affected user groups change, check the application group, domain list and policy assignment again, and repeat the appropriate pilot test.
Sophos also provides a configuration Video on the official Safe AI use cases overview page. Nevertheless, verify the configuration against the written steps above because they identify the fields used and the expected result directly.
Scope
Licensing, administrator roles, identity management, ZTNA, general DNS administration and Live Discover are separate topics and are not part of this procedure.