Configure Sophos Protected Browser web policies and data boundaries
Web policies in Sophos Protected Browser control who may access which targets with which device status, and what may happen to downloads, uploads, and data. Evaluation order is crucial: the browser checks active policies by rank and uses the first policy whose conditions match completely. It does not evaluate any remaining policies after that.
For a safe rollout, first create a narrowly scoped pilot policy, place it ahead of more general rules, and test access, file transfers, and data boundaries separately. The base policy contains the default actions used when no other policies exist.
Prerequisites, licensing, and roles
Before configuration, the required Benutzergruppen must already exist in Sophos Central, and Gerätestatus, Anwendungsgruppen, Standortlisten, and Webkategorien must already exist as policy objects. Only previously created users and objects subsequently appear under Bedingungen. An assigned user group must not be empty; it must contain at least one user.
The product sources approved for this guide do not specify a particular licence or administrator role. Do not infer an entitlement from that. Before making a change, therefore check whether Meine Produkte > Protected Browser > Internetrichtlinie is visible and editable in your tenant. If the area is missing or read-only, do not proceed by guessing that a broader role is needed; clarify the tenant’s licensing and role assignment instead.
The required policy objects must be created in Sophos Central beforehand; creating them is outside the scope of this procedure.
Understand policy logic before configuration
A policy has the Gesamtauswirkung Erlauben, Blockieren, or Warnen:
- Erlauben gives the selected user groups and device statuses access to the selected targets.
- Blockieren blocks that access.
- Warnen permits access, but displays a warning first.
User group and device status are joined by UND: if both are specified in the policy, both must match. The target criteria Anwendungsgruppe, Standortliste, and Internet-Kategorie, however, are joined by ODER: one matching target criterion is sufficient.
This means broad sets of targets can take effect quickly. For example, a policy for the user group Finanzen-Pilot, the device status Windows, an application group, and a site list matches when the user and device status match and the target is included in either the application group or the site list. Finanzen-Pilot is merely an illustrative name and must be replaced with an existing, non-empty group in your own tenant.
Handle the base policy deliberately
The Basisrichtlinie contains a Webfilter-Profil and Standardaktionen für Downloads, Uploads und Datengrenzen. These default actions apply unless another policy overrides them. To edit it, open Meine Produkte > Protected Browser > Internetrichtlinie and select Basisrichtlinie.
The base policy can be edited, but it cannot be deleted, cloned, or moved to another rank. Put individual requirements in separate, more narrowly scoped policies. This keeps the base policy as a predictable fallback while allowing exceptions to be controlled through rank and status.
Select download and upload protection
The action profiles are not variations of a single security level. In particular, ohne Scannen erlauben and erlauben, wenn nicht scannbar have a different risk impact from a profile that blocks a file that cannot be scanned.
Download protection
- Alle Downloads blockieren: blocks all file downloads.
- Alle Downloads ohne Scannen erlauben: permits all downloads without scanning files or checking the reputation of their URLs.
- Riskante Downloads scannen und blockieren, wenn nicht scannbar: scans text, Microsoft Office, and PDF files, checks URL reputation, and blocks files that cannot be scanned.
- Riskante Downloads scannen und erlauben, wenn nicht scannbar: performs the same checks but permits files that cannot be scanned.
- Nur ausführbare Downloads scannen: scans binary and executable files, checks URL reputation, and permits files that cannot be scanned.
Upload protection
- Alle Uploads blockieren: blocks all file uploads.
- Alle Uploads ohne Scannen erlauben: permits all uploads without scanning files or checking the reputation of their URLs.
- Riskante Datei-Uploads scannen und blockieren, wenn nicht scannbar: scans text, Microsoft Office, and PDF files, checks URL reputation, and blocks files that cannot be scanned.
- Riskante Datei-Uploads scannen und erlauben, wenn nicht scannbar: performs the same checks but permits files that cannot be scanned.
- Dokument- und Text-Uploads blockieren, andere Dateitypen scannen: blocks document and text files, scans other file types including a URL check, and permits files that cannot be scanned.
Protected Browser assesses file reputation with the Sophos Extensible List (SXL). In certain cases, Sophos Intellix scans and analyses specific files. Before the pilot test, clarify data classification and whether cloud analysis is permitted. Tenant-wide privacy and data-sharing decisions remain separate from the product-specific policy profiles described here.
Choose data boundaries correctly
Data boundaries control Bildschirmaufnahme, Teilen und Aufzeichnen, Drucken, Seite speichern, and Ausschneiden, kopieren, einfügen. Clipboard boundaries explicitly do not apply to the browser address bar. A successful clipboard test in page content therefore does not prove that the address bar is controlled.
Allow all
This profile permits screen capture, sharing and recording, printing, saving the page, and cutting, copying and pasting. It imposes none of the data boundaries described.
Keep data within the targets of this policy
Screen capture, sharing and recording, printing, and Seite speichern are blocked. Cut, copy, and paste work within the selected targets, but text cannot be pasted outside those targets. Pasting from external sources is not allowed, nor is a temporary bypass of the protection against screen capture, sharing, and recording.
This profile is suitable when data may flow between applications covered by the same policy but must not leave this set of targets. For example, if Jira and Salesforce are in the selected application group, the clipboard remains available between these targets.
Keep data within the targets — allow and log bypass
The clipboard remains restricted to the selected targets, and pasting from external sources is not allowed. Cut, copy, and paste actions are logged. Screen capture, sharing, and recording are blocked by default, but end users may temporarily bypass this protection. Drucken and Seite speichern are permitted after a warning.
This profile is less strict than the option without bypass. Use it only when a legitimate exception requirement justifies the permitted bypass and warning-based releases.
Keep data within the targets — allow pasting from outside
Screen capture, sharing and recording, printing, and Seite speichern are blocked. Cutting and copying are also blocked, while pasting is permitted. This allows data to be brought into protected targets from outside without allowing content to be copied out of them. A temporary bypass of the protection against screen capture, sharing, and recording is not available.
Keep data within Protected Browser
Screen capture, sharing and recording, printing, and Seite speichern are blocked. Cut, copy, and paste are possible only within Protected Browser; text from outside may be pasted into the browser. A temporary bypass of the protection against screen capture, sharing, and recording is not available.
The distinction from a target-based boundary is important: this profile creates a boundary around the entire Protected Browser, not just the targets covered by the same policy.
Configure a pilot policy
- Open Meine Produkte > Protected Browser > Internetrichtlinie and, under Richtlinien, select Richtlinie hinzufügen.
- Enter a unique Namen, such as
PB-Finanzen-Pilot, and a Beschreibung stating the purpose and responsible person. The example name is freely selectable; it does not replace an existing user group. - Under Gesamtauswirkung, select Erlauben, Blockieren, or Warnen. A policy with file and data-boundary actions must use Erlauben or Warnen.
- Under Bedingungen > Benutzergruppe, select Bearbeiten. Under Benutzergruppen bearbeiten > Verfügbar, select the existing pilot group and move it to Zugewiesen. Confirm that the group contains at least one user, then select Speichern.
- Select one or more Gerätestatus values. Then choose the required targets through Anwendungsgruppe, Standortliste, and/or Internet-Kategorie. Select Beliebig only if the condition is deliberately not to be limited to a particular user group or policy object.
- Under Aktionen, select the profiles for Download-Schutz, Upload-Schutz, and Datengrenzen. This area is relevant to the overall effects Erlauben and Warnen.
- If resources must open exclusively in the full Protected Browser, enable Nutzung des vollständigen Browsers erzwingen. When they are accessed, the affected websites or resources then open automatically in the full Protected Browser.
- Select Speichern.
- In the policy table, open Auf Position # verschieben from the three-dot menu, use the arrow to move the pilot policy to the required position, and select Anwenden. A lower rank number is evaluated earlier; rank 1 comes first.
A narrow policy must appear before a more general policy that already completely matches the same user and target conditions. Otherwise, the general policy takes precedence and the pilot policy is not evaluated at all.
Validation and expected result
Use a test user from exactly the assigned, non-empty pilot group, a matching device status, and an unambiguously assigned target for acceptance testing. Test with non-sensitive files and content.
- In the policy table, check Rang, Name, Zugriff, and Status. The pilot policy must be Aktiv and precede every broader policy that also matches.
- Test a target that meets the conditions. Access must be possible with Erlauben, possible after the warning with Warnen, and impossible with Blockieren.
- Test one download and one upload scenario that the chosen profile permits and one that it blocks. With a block if it cannot be scanned profile, this decision is also part of the success criterion; with a permit if it cannot be scanned profile, the opposite result is expected.
- Test each aspect of the selected data boundary separately: screen capture or sharing, printing, Seite speichern, copying between two covered targets, copying outside, and pasting from outside. Expect exactly the combination defined by the selected profile.
- If Nutzung des vollständigen Browsers erzwingen is active, initiate access to a covered resource and confirm that it opens in the full Protected Browser.
- Run one test in which only one target criterion matches, and another in which the user group or device status does not match. This verifies the targets’ OR relationship separately from the AND relationship between user and device conditions.
Troubleshoot by symptom
The policy does not take effect
First check Status and Rang. A Nicht aktive policy is not evaluated. If a higher-ranked active policy already matches completely, evaluation stops there. Move the narrower policy ahead of the broader rule using Auf Position # verschieben > Anwenden, then test again.
Next, check the condition logic: user group and device status must match together; for application group, site list, and web category, one matching target is sufficient. If a value is unavailable for selection, the user or policy object might not have been created yet.
A user group cannot be assigned usefully
Check that the group contains at least one user. An empty assigned user group is not permitted. First add users to the group, then save the policy again and repeat the test with a member of that group.
File actions or data boundaries appear to be ignored
Check the Gesamtauswirkung. With Blockieren, the additional download protection, upload protection, and data-boundary actions do not apply. With Erlauben or Warnen, then check whether a higher-priority policy matched first and which action profile was actually selected in that policy.
Do not use the address bar as the test surface for clipboard checks: the documented clipboard boundaries do not apply there. If the result in page content still differs from the selected profile matrix, do not roll out the change more broadly. Document the test case, rank, conditions, and profile, and escalate to Sophos Support.
Safe rollback and offboarding
Before making a change, record the affected policy’s Rang, Status, conditions, and action profiles. For a reversible rollback, deactivate the new pilot policy and then select Aktualisieren. An inactive policy is not evaluated; a new test must therefore show that the next matching policy or the base policy takes effect again.
Only consider deletion after this rollback is confirmed. Separate policies can be removed from the three-dot menu with Löschen or used as the starting point for a new variant with Klonen. The base policy cannot be deleted, cloned, or moved to another rank. Therefore, do not delete a policy while its conditions, rank, or intended replacement effect remain unclear.
When offboarding a user group or policy object, first review every policy that uses it as a condition. Then adjust the assignment, confirm the effect with a limited test, and only afterwards deal with the object that is no longer required in its designated area.
Operations and regular review
Review policies whenever user groups, device statuses, or target objects change, and regularly check their Rang, Status, Zugriff, and assigned action profiles. Pay particular attention to rules with Beliebig, profiles that permit files that cannot be scanned, Alle Downloads/Uploads ohne Scannen erlauben, and data boundaries with a temporary bypass.
First clone a change or build it as a new pilot policy with a small target group. Expand its scope deliberately after successful acceptance testing. Independently of these policy checks, verify migration deadlines and product retirement or EOL dates against official product notices.
Related guide
Sophos Fusion: control privacy and data sharing provides context for sharing files with Sophos services and tenant-wide privacy decisions.