Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Zscaler: Zero Trust Browser: Secure Access Without VPN or Enterprise Browser

Zscaler
07/25/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


My name is Brian Dietsch, and what's up, new best friends? Maybe this is your first time seeing one of my videos. It's a 2026, new year, new me, same old black polo. Today, we're going to be talking about the Zero Trust Browser from Zscaler. And I know you're thinking, does that indicate that we're going to be rolling out like an enterprise browser? Gross, yucky. I don't want to do that whatsoever. So let's look at this lens of this stick figure over here in the orange-ish color, managed device. This device over here in the pinkish, purplish color, whatever it looks like on your screen, is an unmanaged device, grandma's computer. And what are we really trying to get done with the Zero Trust Browser? So the first thing that kind of comes to mind is that we want to be able to do advanced cyber threat protection across the internet. Two, you're going to have some SaaS-based applications that you are using, and you being your employees, third-party contractors, and whatnot. Next, you're going to have some applications in the private cloud, Azure, AWS, GCP, and whatnot. And we'll call that just application one for fun. And then last but not least, you're going to have to contend with applications that still reside over here at the data center, and we'll call that application two for real estate sake. So what is the connectivity tissue that's going to kind of stitch this all together? You guessed it. You're a smart person. It's going to be the Zscare Cloud, aka the Zero Trust Exchange. And we'll start over here from a sanctioned computer. What are we doing? What are we trying to do? So let's start with the managed device. They're coming over here. Traffic is going to arrive at the Zero Trust Exchange from any browser, wherever. Chrome, Firefox, Edge, Brave, it doesn't matter as long as it's modern, we got you going. And the Zero Trust Exchange does what? A lot of the good, a lot of the bad, stop the stupid, do your data security and all that good stuff. Directionality is kind of always key when talking about this. If you're not familiar with our architecture, check out some of my other videos. From the cloud perspective, right, we always kind of meet outbound right here. Same thing with the data center. We reach outbound over here. Now, the way that we actually get this all done is through a technology called cloud browser isolation. And by leveraging cloud browser isolation, specifically the pixel streaming that comes out to this endpoint via any modern browser, it gives us some really cool controls based upon the identity of the user. I can restrict copy and paste, upload, download, printing. I can do some watermarking, read-only mode. But more importantly, I can enforce some data residency artifacts as well. So now this user can go out here, have kind of that native-y experience. They're not really going to know that they're in browser isolation unless you tell them. You put a little banner at the top. So this user has the ability to talk to applications in the internet, SaaS, cloud, data center, the list kind of goes on and on. But that's from a corporate PC, and I think we kind of all get it. Like, this is a good thing. But, like, how do we do this for grandma's PC, an employee working from home on an unmanaged device, third-party contractor? And you're going to be giving them just kind of a portal page. And that portal page is configured to basically say, hey, when this user comes in, send them to the Zero Trust Exchange and authenticate them and then just get them some tiles, right? But in true Zscaler fashion, what I want to do is I'm going to turn this up a notch . So let's say one of the applications that this third-party contractor or employee coming through on grandma's computer is maybe corporate email, right? They're in the web desktop of that. When they arrive right here, I'm storing pixels, and even though they're in there and they're doing their job, they're writing emails, maybe they click a link, I can actually keep them in that isolated portal and not just out on the internet whatsoever. Two, I still have all the same abilities, the copy and paste, upload, download restrictions, the watermarking, even have the ability to give them read-only visibility in your SaaS-based applications or cloud or even data center. And then what I really want to do is even though they're coming from a browser, not all applications here and here are written in just HTTP, HTTPS, HTML5. In fact, I can support SSH, RDP, VNC, and real VNC all from a browser window. Now, in true Zscaler fashion, I'm trying to turn up the Zero Trust lens right here. First thing I can do is I'll allow this user to log in. They can log in with their corporate credentials. I can even do bring your own identity. I support multiple identity providers. I can do session recording. So from a repudiation standpoint, maybe they're coming through and they're SSHing over here or over here. I'm going to record everything that happened for that particular user, drop it off in one of your like S3 buckets or somewhere because I don't want to have custody of that data. I want to give it to you. Two, I can do session proctoring. So if you want to sit there and be a weirdo, watch them. Like I can provide that visibility as well. And then last but not least, I can do session ushering. Let's say you have some third-party contract that's coming in and you need to kind of sit there and walk them through stuff, right? As they're coming in, if you need to be able to take over keyboard and mouse, I can do that for you as well. But again, I don't just stop right there. I'm going to turn it up a notch because the traffic's being proxied by our cloud. Let's say that this user, right, they're doing some type of update to an OT device that's on a network over here. I can provide that access. But they're moving it in binary over there. I can still run it through my sandbox to ensure that it's not some sort of wacky piece of ransomware or malware that's out there and stop that from happening. And last but not least, in true Zscare fashion, I can actually do a credential vault, which means I can allow this user to kind of log in with their own credentials here. And as they start to click the little icons, maybe going out to SaaS or cloud or the data center, I can actually inject credentials right here. That way they don't actually know what password was used to access these websites, these applications and whatnot. So when we look at the Zero Trust Browser from Zscare, it's not an enterprise browser, right? It's not another whole client that's out there. It's any modern browser that's out there in the world from a cyber threat protection lens, leveraging cloud browser isolation across the entire platform right here, doing the pixel streaming and getting those amazing controls, the copy and paste, upload, download, read-only mode, print, the session recording, session ushering, session proctoring. I mean, the list kind of goes on and on. Hopefully this is enough to get your appetite wet on the Zero Trust Browser from Zscare. Do me a favor. Reach out to your local sales team. We'd love to talk to you about the utility of the Zero Trust Browser, how it can enhance your user experience and minimize risk for your organization, whether it's your managed devices or, heck, even these third-party contractors, third-party devices. Give them access, but more importantly, not putting them on the network. Leave a comment below, like it. I don't know, but I appreciate you for watching. Have a great day. ♪♪♪

TL;DR

  • Zero Trust Browser works with any modern browser—no enterprise browser deployment required—using cloud browser isolation and pixel streaming to enforce security controls.
  • Managed and unmanaged devices receive the same protection through the Zero Trust Exchange, with granular controls for copy/paste, upload/download, printing, and watermarking.
  • The solution supports SSH, RDP, and VNC protocols from the browser, enabling privileged access to infrastructure without putting users on the network.
  • Session recording, proctoring, and ushering capabilities provide audit trails and real-time oversight for third-party contractor access scenarios.

Browser-Based Zero Trust Without Client Deployment

Zscaler's Zero Trust Browser leverages cloud browser isolation to provide secure access to internet resources, SaaS applications, and private applications without requiring an enterprise browser deployment. The solution works with any modern browser including Chrome, Firefox, Edge, and Brave, routing traffic through the Zero Trust Exchange where security policies are enforced. For managed devices, users experience near-native browsing while the platform applies cyber threat protection, data security controls, and granular restrictions on actions like copy/paste, upload/download, and printing. The pixel streaming technology ensures that sensitive data never actually reaches the endpoint, with watermarking and read-only modes available for additional protection.

Unmanaged Device Access and Privileged Session Controls

For unmanaged devices such as contractor laptops or personal computers, Zero Trust Browser provides portal-based access with the same security controls applied to managed endpoints. Users authenticate through the Zero Trust Exchange and receive application tiles without requiring any client installation. The platform supports non-HTTP protocols including SSH, RDP, and VNC directly from the browser, enabling privileged access to infrastructure. Advanced session controls include recording for audit purposes with storage in customer-owned S3 buckets, live session proctoring for oversight, and session ushering that allows administrators to take over keyboard and mouse when needed. A credential vault feature injects credentials at access time, preventing users from knowing the actual passwords used to access applications.

Chapters

0:00 - Introduction
0:29 - Managed vs Unmanaged Devices
1:33 - Zero Trust Exchange Architecture
2:25 - Cloud Browser Isolation
3:09 - Unmanaged Device Access
4:19 - Non-HTTP Protocol Support
4:37 - Session Recording and Controls
5:57 - Credential Vault
6:16 - Summary and Call to Action

Key Quotes

0:21 "And I know you're thinking, does that indicate that we're going to be rolling out like an enterprise browser? Gross, yucky. I don't want to do that whatsoever."
2:25 "Now, the way that we actually get this all done is through a technology called cloud browser isolation."
4:19 "Not all applications here and here are written in just HTTP, HTTPS, HTML5. In fact, I can support SSH, RDP, VNC, and real VNC all from a browser window."
6:09 "That way they don't actually know what password was used to access these websites, these applications and whatnot."

FAQ

Does Zero Trust Browser require deploying a new enterprise browser to users?

No. Zero Trust Browser works with any modern browser including Chrome, Firefox, Edge, and Brave. It uses cloud browser isolation and pixel streaming through the Zero Trust Exchange rather than requiring a dedicated browser client.

How does Zero Trust Browser handle access for third-party contractors on personal devices?

Contractors access a portal page that authenticates them through the Zero Trust Exchange and presents application tiles. They receive the same security controls as managed devices—including copy/paste restrictions, watermarking, and session recording—without any client installation. The credential vault can inject passwords so contractors never see actual credentials.


Categories:
  • » Webinar Library » Zscaler
  • » Cybersecurity » Zero Trust
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Zero Trust
  • SASE
  • SSE
  • Identity & Access
  • Demo
  • Technical Deep Dive
  • Zero Trust Browser
  • Cloud Browser Isolation
  • Pixel Streaming
  • Third-Party Access
  • Privileged Access Management
  • Session Recording
  • Credential Vaulting
  • VPN Replacement
  • Unmanaged Device Security
  • ZTNA
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Zscaler: Zero Trust Browser: Secure Access Without VPN or Enterprise Browser

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Aug
                    03

                    Discover DLP Memories: The ever-evolving triage agent enhancing efficiency each shift.

                    08/03/202611:00 AM ET
                    • Aug
                      06

                      Safeguarding Sensitive Data in the Era of AI Adoption

                      08/06/202604:00 AM ET
                      • Aug
                        06

                        Same Tactics, Enhanced Velocity: The Impact of AI Agents on Identity Attacks

                        08/06/202602:00 PM ET
                        More events

                        Upcoming Webinar Calendar

                        • 07/28/2026
                          01:00 PM
                          07/28/2026
                          Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                          https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                        • 07/29/2026
                          04:00 AM
                          07/29/2026
                          Real-Time Strategies for Safeguarding Against Prompt Injections
                          https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                        • 07/29/2026
                          01:00 PM
                          07/29/2026
                          Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                          https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                        • 08/03/2026
                          11:00 AM
                          08/03/2026
                          Discover DLP Memories: The ever-evolving triage agent enhancing efficiency each shift.
                          https://www.truthinit.com/index.php/channel/2062/discover-dlp-memories-the-ever-evolving-triage-agent-enhancing-efficiency-each-shift/
                        • 08/06/2026
                          04:00 AM
                          08/06/2026
                          Safeguarding Sensitive Data in the Era of AI Adoption
                          https://www.truthinit.com/index.php/channel/2058/safeguarding-sensitive-data-in-the-era-of-ai-adoption/
                        • 08/06/2026
                          02:00 PM
                          08/06/2026
                          Same Tactics, Enhanced Velocity: The Impact of AI Agents on Identity Attacks
                          https://www.truthinit.com/index.php/channel/2064/same-tactics-enhanced-velocity-the-impact-of-ai-agents-on-identity-attacks/
                        • 08/07/2026
                          11:30 AM
                          08/07/2026
                          Refreshing Beverage Ideas Paired with Essential Cybersecurity Insights
                          https://www.truthinit.com/index.php/channel/2063/refreshing-beverage-ideas-paired-with-essential-cybersecurity-insights/
                        • 08/13/2026
                          12:00 PM
                          08/13/2026
                          Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                          https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                        • 08/19/2026
                          12:00 PM
                          08/19/2026
                          Becoming Agent Ready: Insights and Strategies with Cyera
                          https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-and-strategies-with-cyera/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version