For many of you, Sophos ZTNA has been a staple in your security stack offering for a few years now – providing unmatched protection and a seamless user experience for securing access to your customer’s private applications. What you may not realize is that the same license now extends Zero Trust to SaaS and web apps as well — through Sophos Protected Browser, included at no extra charge as part of Sophos Workspace Protection.
As you may have seen, on February 28, all Sophos ZTNA customers were automatically upgraded to the full Sophos Workspace Protection bundle. Sophos Protected Browser is a key component of that bundle and is waiting for you to switch on today. The best part: it just got a lot easier with the Sophos Protected Browser Extension.
Extend Zero Trust from your private apps to SaaS
ZTNA already makes private apps invisible to the internet and grants access only to users and devices that meet policy. Sophos Protected Browser applies the same Zero Trust model to the browser. The browser is where over 85% of work happens, and naturally, SaaS applications lead here.
Control who can reach sanctioned SaaS applications, manage how data is accessed between SaaS apps and the user, device, and other apps, and block the apps that haven’t been approved.
- Apply data boundary controls inside those apps — govern copy/paste, screen captures, printing, and uploads/downloads.It’s never been easier to ensure data stays within sanctioned applications and isn’t easily shared via personal email or other non-sanctioned applications.
- Get visibility into shadow IT and shadow AI usage, and set guardrails for safe GenAI adoption.
- Enforce the same device posture and Synchronized Security Heartbeat checks you already rely on in ZTNA.
Review this article to see how easy it is to setup SaaS app access control.
A better experience for RDP and SSH users
If your customers connect to servers over RDP or SSH, Protected Browser replaces the old client-based workflow with a rich RDP and SSH client built right into the browser:
- Agentless access — no separate RDP or SSH client to install, configure, or maintain.
- Users simply launch Protected Browser, click the remote desktop icon, and connect.
- Files moved to or from the RDP host are automatically scanned before transfer — clean files go through, threats don’t.
- Access still honors your ZTNA policies and device health, so a smoother experience never means weaker security.
Stronger admin and data-boundary controls, centrally managed
- A hardened Chromium browser that’s protected against browser exploits and attacks.
- Integrated Secure Web Gateway controls and Sophos DNS Protection block malicious, risky, and unwanted sites.
- Granular data-boundary controls help prevent accidental — or deliberate — data leakage.
- Everything is managed from Sophos Fusion (the evolution of Sophos Central), alongside the rest of your Sophos product stack.
Getting started takes about 30 seconds
Deploy the full Sophos Protected Browser or add the new Sophos Protected Browser Extension to the Chromium-based browsers your customer’s already use — such as Chrome and Edge on Windows and Mac. Nothing to rip and replace; just add it on. And as you’d expect, it works better together with their other Sophos products and is easily managed from Sophos Fusion.
Learn more about the Sophos Protected Browser, explore everything now included with your expanded license as part of Sophos Workspace Protection, and start deploying the Protected Browser or new Extension today.

