* [Blog](https://origin-researchcenter.paloaltonetworks.com/blog) * [SASE](https://origin-researchcenter.paloaltonetworks.com/blog/sase/) * [Cloud-delivered Security](https://origin-researchcenter.paloaltonetworks.com/blog/sase/category/cloud-delivered-security/) * Palo Alto Networks Native... # Palo Alto Networks Natively Integrates RBI with SASE [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Forigin-researchcenter.paloaltonetworks.com%2Fblog%2Fsase%2Fpalo-alto-networks-natively-integrates-remote-browser-isolation-rbi-with-sase%2F) [](https://twitter.com/share?text=Palo+Alto+Networks+Natively+Integrates+RBI+with+SASE&url=https%3A%2F%2Forigin-researchcenter.paloaltonetworks.com%2Fblog%2Fsase%2Fpalo-alto-networks-natively-integrates-remote-browser-isolation-rbi-with-sase%2F) [](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Forigin-researchcenter.paloaltonetworks.com%2Fblog%2Fsase%2Fpalo-alto-networks-natively-integrates-remote-browser-isolation-rbi-with-sase%2F&title=Palo+Alto+Networks+Natively+Integrates+RBI+with+SASE&summary=&source=) [](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https://origin-researchcenter.paloaltonetworks.com/blog/sase/palo-alto-networks-natively-integrates-remote-browser-isolation-rbi-with-sase/&ts=markdown) \[\](mailto:?subject=Palo Alto Networks Natively Integrates RBI with SASE) Link copied By [Nitish Khadke](https://www.paloaltonetworks.com/blog/author/nitish-khadke/?ts=markdown "Posts by Nitish Khadke") Nov 29, 2023 5 minutes [Cloud-delivered Security](https://www.paloaltonetworks.com/blog/sase/category/cloud-delivered-security/?ts=markdown) [Product Features](https://www.paloaltonetworks.com/blog/sase/category/product-features/?ts=markdown) [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [Use-Cases](https://www.paloaltonetworks.com/blog/sase/category/use-cases/?ts=markdown) [RBI](https://www.paloaltonetworks.com/blog/tag/rbi/?ts=markdown) [Remote Browser Isolation](https://www.paloaltonetworks.com/blog/tag/remote-browser-isolation/?ts=markdown) [SASE](https://www.paloaltonetworks.com/blog/tag/sase/?ts=markdown) Organizations must be able to absorb economic stress, recover quickly, and adjust to changing business circumstances to be successful. Business resilience alone, however, is insufficient in today's digital-first world. With the increasing adoption of SaaS apps, hybrid workers, and the potential for irreparable harm from a single data breach or ransomware attack, business resilience must extend to cyber resilience with a multilayered web defense. Palo Alto Networks [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation) (RBI) coupled with [Cloud Secure Web Gateway (SWG)](https://www.paloaltonetworks.com/sase/secure-web-gateway) and [Enterprise DLP](https://www.paloaltonetworks.com/network-security/enterprise-data-loss-prevention) present a formidable combination that not only fortifies web defenses, but improves user productivity and streamlines operations. # Introducing the Next-Generation RBI for Prisma SASE RBI is an advanced security approach that separates web browsing activities from local devices by executing them in a secure remote environment. The browser session occurs on virtual machines hosted in the cloud, confining any malicious code encountered during browsing to the isolated session and poses no threat to the user's device or network. However, running browser sessions far away from local devices has the potential for user disruption. Throughout its evolution, traditional RBI approaches have tried but fallen short when governing the tension between performance and security. [Palo Alto Networks Next-Generation RBI for Prisma SASE](https://www.paloaltonetworks.com/resources/datasheets/remote-browser-isolation) creates a no-code execution isolation channel between users and browsers to keep zero-day web threats at bay, never allowing malicious files to execute on user machines. Unlike traditional pixel-pushing reconstruction that causes high latency or DOM-based approaches that expose security gaps, Palo Alto Networks RBI isolation platform combines the latest rendering technologies for superior isolation outcomes while simultaneously delivering a near-native user experience. ## Zero-Day Threat Protection Zero-day vulnerabilities exploit unknown and unpatched software flaws, posing significant challenges for traditional cybersecurity solutions. However, RBI neutralizes zero-day threats by executing a web browsing session in a protected environment away from the local device. RBI mitigates the risk of system compromise by rendering zero-day exploits harmless once the web browsing session ends. ## Reducing the External Attack Surface RBI minimizes the attack surface by preventing webpage code from executing on local devices. RBI confines malicious code, malware, and phishing attempts to the isolated browser session, eliminating the risk of unauthorized access to the user's device or sensitive corporate data. This approach reduces the potential impact of successful attacks and strengthens the overall security posture. High-value users with access to sensitive data are often targets of these attacks, and RBI can further reduce the attack surface with granular user controls that help keep sensitive data safe and secure. ## Near-Native Web Browsing User Experience RBI leverages modern web technologies to ensure that web applications render in a way that is nearly native to the user, providing a seamless user experience between a web browsing session that happens inside or outside isolation. We have engineered our isolation technology to disallow code execution on the user's machine, providing uncompromising security for even the most dynamic and demanding web applications. # RBI Natively Integrated with SWG and DLP [SWGs act as a proxy](https://www.paloaltonetworks.com/blog/sase/unleashing-the-benefits-of-cloud-swg-with-agent-based-proxy/) between users and the internet, monitoring and controlling all web traffic for potential threats. It applies various security measures, including [URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering), content inspection, and antivirus scanning, to prevent unauthorized access and to block threats. Along with these services, [DLP helps discover, monitor, and protect sensitive data](https://www.paloaltonetworks.com/blog/sase/palo-alto-networks-stops-ai-app-data-leakage-in-its-tracks/) across every network, cloud, and user. Combining RBI with SWG and DLP creates a multilayered defense against modern web threats. [SWG](https://www.paloaltonetworks.com/blog/sase/on-premises-making-the-case-cloud-swg/) provides comprehensive security checks on web traffic before and after it reaches the remote browser isolation environment. This proactive approach ensures that even if a threat bypasses one layer of security, another layer will catch it, significantly reducing the risk of zero-day web attacks. When viewing through a data security lens, DLP policies work holistically on a user's session, regardless of whether the user is in or outside of isolation. RBI introduces a host of granular browser-level controls that help to augment the delivery and enforcement of data security to the user level, working hand-in-hand with existing Enterprise DLP policies. # Centralized Management and Enforcement with Prisma SASE Organizations can enforce consistent security policies across all web traffic for all users from all locations. SASE ensures that all user activities, including web browsing, adhere to corporate security guidelines, restricting access to risky or unknown websites. At the same time, RBI maintains the isolation principle, providing an extra layer of defense against potential zero-day threats arising from user interactions with the web. ![](https://www.paloaltonetworks.com/blog/wp-content/uploads/2023/11/word-image-309760-1-1.png) *Figure 1: RBI isolation profile natively integrated with Prisma Access* Applying the isolation context to existing security policies makes it easy to start isolation for any desired segment of traffic or based on the many levers that already exist as part of [Prisma Access](https://www.paloaltonetworks.com/sase/access). Organizations can monitor and view logs from user traffic in [one single-pane-of-glass](https://www.paloaltonetworks.com/network-security/strata-cloud-manager), allowing for an increasingly simplified and consolidated troubleshooting and investigation process. # Embracing the Power of RBI with Prisma SASE [Prisma SASE](https://www.paloaltonetworks.com/sase) fuses RBI with SWG and DLP functionality, representing one of the most formidable defenses against web attacks with a multilayered approach for enhanced protection against zero-day threats. By reducing the attack surface and enforcing consistent security policies, a natively integrated solution fortifies cybersecurity defenses for businesses and individuals. Moreover, the streamlined web browsing experience ensures faster access to web content and cross-product compatibility, fostering productivity while maintaining the highest levels of data protection. Combining the power of RBI with SWG and DLP is an intelligent investment in robust cybersecurity and a proactive step toward a safer, more efficient digital future. Learn more about RBI with Prisma SASE and all of our other recent AI-powered SASE innovations at our [SASE Converge 2023 on-demand event](https://www.saseconverge.paloaltonetworks.com/). *** ** * ** *** ## Related Blogs ### [Product Features](https://www.paloaltonetworks.com/blog/sase/category/product-features/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [Use-Cases](https://www.paloaltonetworks.com/blog/sase/category/use-cases/?ts=markdown) [#### Maximize Zero-Day Protection with Dynamic RBI \& Prisma SASE](https://origin-researchcenter.paloaltonetworks.com/blog/sase/maximize-zero-day-protection-dynamic-rbi-prisma-sase/) ### [Cloud-delivered Security](https://www.paloaltonetworks.com/blog/sase/category/cloud-delivered-security/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/sase/category/product-features/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [Use-Cases](https://www.paloaltonetworks.com/blog/sase/category/use-cases/?ts=markdown), [Web Security](https://www.paloaltonetworks.com/blog/category/web-security/?ts=markdown) [#### Your Secure Web Gateway Needs a Cloud Makeover](https://origin-researchcenter.paloaltonetworks.com/blog/sase/your-secure-web-gateway-needs-a-cloud-makeover/) ### [Cloud-delivered Security](https://www.paloaltonetworks.com/blog/sase/category/cloud-delivered-security/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/sase/category/product-features/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [Use-Cases](https://www.paloaltonetworks.com/blog/sase/category/use-cases/?ts=markdown) [#### Operational Resilience: Ensuring Business Continuity with Prisma SASE](https://origin-researchcenter.paloaltonetworks.com/blog/sase/operational-resilience-ensuring-business-continuity-with-prisma-sase/) ### [Product Features](https://www.paloaltonetworks.com/blog/sase/category/product-features/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [Use-Cases](https://www.paloaltonetworks.com/blog/sase/category/use-cases/?ts=markdown) [#### Use RBI as Your Edge Over Zero-Day Browser Vulnerabilities](https://origin-researchcenter.paloaltonetworks.com/blog/sase/use-rbi-as-your-edge-over-zero-day-browser-vulnerabilities/) ### [Product Features](https://www.paloaltonetworks.com/blog/sase/category/product-features/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [Use-Cases](https://www.paloaltonetworks.com/blog/sase/category/use-cases/?ts=markdown) [#### Why Traditional DLP Fails to Protect Your Most Sensitive Data](https://origin-researchcenter.paloaltonetworks.com/blog/sase/why-traditional-dlp-fails-to-protect-your-most-sensitive-data/) ### [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Cloud-delivered Security](https://www.paloaltonetworks.com/blog/sase/category/cloud-delivered-security/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/sase/category/product-features/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Introducing Security for Interconnected SaaS](https://origin-researchcenter.paloaltonetworks.com/blog/sase/introducing-security-for-interconnected-saas/) ### Subscribe to Sase Blogs! Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more. ![spinner](https://origin-researchcenter.paloaltonetworks.com/blog/wp-content/themes/panwblog2023/dist/images/ajax-loader.gif) Sign up Please enter a valid email. By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) and acknowledge our [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown). Please look for a confirmation email from us. If you don't receive it in the next 10 minutes, please check your spam folder. This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply. {#footer} {#footer} ## Products and Services * [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown) * [Secure AI by Design](https://www.paloaltonetworks.com/precision-ai-security/secure-ai-by-design?ts=markdown) * [Prisma AIRS](https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security?ts=markdown) * [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown) * [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown) * [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [Industrial OT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown) * [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown) * [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown) * [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown) * [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown) * [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown) * [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown) * [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) * [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown) * [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown) ## Company * [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown) * [Careers](https://jobs.paloaltonetworks.com/en/) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown) * [Customers](https://www.paloaltonetworks.com/customers?ts=markdown) * [Investor Relations](https://investors.paloaltonetworks.com/) * [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown) * [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown) ## Popular Links * [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown) * [Communities](https://www.paloaltonetworks.com/communities?ts=markdown) * [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) * [Event Center](https://events.paloaltonetworks.com/) * [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center) * [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) * [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown) * [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown) * [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown) * [Tech Docs](https://docs.paloaltonetworks.com/) * [Unit 42](https://unit42.paloaltonetworks.com/) * [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd) ![PAN logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg) * [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) * [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown) * [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) * [Documents](https://www.paloaltonetworks.com/legal?ts=markdown) Copyright © 2026 Palo Alto Networks. All Rights Reserved * [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks) * [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown) * [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/) * [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks) * [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks) * EN Select your language