Skip to Content

Sophos ZTNA unlocks SaaS app control and so much more

Sophos ZTNA customers now get Sophos Protected Browser as part of Sophos Workspace Protection, extending Zero Trust controls to SaaS and web apps while improving secure RDP and SSH access.
Rob Andrews

For many of you, Sophos ZTNA has been a staple in your security stack for a few years now, providing unmatched protection and a seamless user experience for securing access to your private applications. 

What you may not realize is that the same license now extends Zero Trust to your SaaS and web apps as well — through Sophos Protected Browser, included at no extra charge as part of Sophos Workspace Protection.

As you may have seen, on February 28, all Sophos ZTNA customers were automatically upgraded to the full Sophos Workspace Protection bundle. Sophos Protected Browser is a key component of that bundle and is waiting for you to switch on today.

Here's what it can do...

Extend Zero Trust from your private apps to SaaS

ZTNA already makes your private apps invisible to the internet and grants access only to users and devices that meet policy. Sophos Protected Browser applies the same Zero Trust model to the browser.  The browser is where over 85% of work happens, and naturally, SaaS applications lead here.

Control who can reach your sanctioned SaaS applications, manage how data is accessed between SaaS apps and the user, device, and other apps, and block the ones you haven’t approved.

  • Apply data boundary controls inside those apps — govern copy/paste, screen captures, printing, and uploads/downloads. It’s never been easier to ensure data stays within sanctioned applications and isn’t easily shared via personal email or other non-sanctioned applications.
  • Get visibility into shadow IT and shadow AI usage, and set guardrails for safe GenAI adoption.
  • Enforce the same device posture and Synchronized Security Heartbeat checks you already rely on in ZTNA.

Review this article to see how easy it is to set up SaaS app access control.

A better experience for your RDP and SSH users

If your people connect to servers over RDP or SSH, Protected Browser replaces the old client-based workflow with a rich RDP and SSH client built right into the browser:

  • Agentless access — no separate RDP or SSH client to install, configure, or maintain.
  • Users simply launch Protected Browser, click the remote desktop icon, and connect.
  • Files moved to or from the RDP host are automatically scanned before transfer — clean files go through, threats don’t.
  • Access still honors your ZTNA policies and device health, so a smoother experience never means weaker security.

Stronger admin and data-boundary controls, centrally managed

  • A hardened Chromium browser that’s protected against browser exploits and attacks.
  • Integrated Secure Web Gateway controls and Sophos DNS Protection block malicious, risky, and unwanted sites.
  • Granular data-boundary controls help prevent accidental — or deliberate — data leakage.
  • Everything is managed from Sophos Central alongside the rest of your Sophos products.

Getting started takes about 30 seconds

Deploy the full Sophos Protected Browser or add the new Sophos Protected Browser Extension to the Chromium-based browsers your team already uses — such as Chrome and Edge on Windows and Mac. Nothing to rip and replace; just add it on. And as you’d expect, it works better together with your other Sophos products and is easily managed from Sophos Central.

Learn more about the Sophos Protected Browser, explore everything now included with your expanded license as part of Sophos Workspace Protection, and start deploying the Protected Browser or its new Extension today.