Transcript
My name is Brian Dietsch, and what's up, new best friends? Maybe this is your first time seeing one of my videos. It's a 2026, new year, new me, same old black polo. Today, we're going to be talking about the Zero Trust Browser from Zscaler. And I know you're thinking, does that indicate that we're going to be rolling out like an enterprise browser? Gross, yucky. I don't want to do that whatsoever. So let's look at this lens of this stick figure over here in the orange-ish color, managed device. This device over here in the pinkish, purplish color, whatever it looks like on your screen, is an unmanaged device, grandma's computer. And what are we really trying to get done with the Zero Trust Browser? So the first thing that kind of comes to mind is that we want to be able to do advanced cyber threat protection across the internet. Two, you're going to have some SaaS-based applications that you are using, and you being your employees, third-party contractors, and whatnot. Next, you're going to have some applications in the private cloud, Azure, AWS, GCP, and whatnot. And we'll call that just application one for fun. And then last but not least, you're going to have to contend with applications that still reside over here at the data center, and we'll call that application two for real estate sake. So what is the connectivity tissue that's going to kind of stitch this all together? You guessed it. You're a smart person. It's going to be the Zscare Cloud, aka the Zero Trust Exchange. And we'll start over here from a sanctioned computer. What are we doing? What are we trying to do? So let's start with the managed device. They're coming over here. Traffic is going to arrive at the Zero Trust Exchange from any browser, wherever. Chrome, Firefox, Edge, Brave, it doesn't matter as long as it's modern, we got you going. And the Zero Trust Exchange does what? A lot of the good, a lot of the bad, stop the stupid, do your data security and all that good stuff. Directionality is kind of always key when talking about this. If you're not familiar with our architecture, check out some of my other videos. From the cloud perspective, right, we always kind of meet outbound right here. Same thing with the data center. We reach outbound over here. Now, the way that we actually get this all done is through a technology called cloud browser isolation. And by leveraging cloud browser isolation, specifically the pixel streaming that comes out to this endpoint via any modern browser, it gives us some really cool controls based upon the identity of the user. I can restrict copy and paste, upload, download, printing. I can do some watermarking, read-only mode. But more importantly, I can enforce some data residency artifacts as well. So now this user can go out here, have kind of that native-y experience. They're not really going to know that they're in browser isolation unless you tell them. You put a little banner at the top. So this user has the ability to talk to applications in the internet, SaaS, cloud, data center, the list kind of goes on and on. But that's from a corporate PC, and I think we kind of all get it. Like, this is a good thing. But, like, how do we do this for grandma's PC, an employee working from home on an unmanaged device, third-party contractor? And you're going to be giving them just kind of a portal page. And that portal page is configured to basically say, hey, when this user comes in, send them to the Zero Trust Exchange and authenticate them and then just get them some tiles, right? But in true Zscaler fashion, what I want to do is I'm going to turn this up a notch . So let's say one of the applications that this third-party contractor or employee coming through on grandma's computer is maybe corporate email, right? They're in the web desktop of that. When they arrive right here, I'm storing pixels, and even though they're in there and they're doing their job, they're writing emails, maybe they click a link, I can actually keep them in that isolated portal and not just out on the internet whatsoever. Two, I still have all the same abilities, the copy and paste, upload, download restrictions, the watermarking, even have the ability to give them read-only visibility in your SaaS-based applications or cloud or even data center. And then what I really want to do is even though they're coming from a browser, not all applications here and here are written in just HTTP, HTTPS, HTML5. In fact, I can support SSH, RDP, VNC, and real VNC all from a browser window. Now, in true Zscaler fashion, I'm trying to turn up the Zero Trust lens right here. First thing I can do is I'll allow this user to log in. They can log in with their corporate credentials. I can even do bring your own identity. I support multiple identity providers. I can do session recording. So from a repudiation standpoint, maybe they're coming through and they're SSHing over here or over here. I'm going to record everything that happened for that particular user, drop it off in one of your like S3 buckets or somewhere because I don't want to have custody of that data. I want to give it to you. Two, I can do session proctoring. So if you want to sit there and be a weirdo, watch them. Like I can provide that visibility as well. And then last but not least, I can do session ushering. Let's say you have some third-party contract that's coming in and you need to kind of sit there and walk them through stuff, right? As they're coming in, if you need to be able to take over keyboard and mouse, I can do that for you as well. But again, I don't just stop right there. I'm going to turn it up a notch because the traffic's being proxied by our cloud. Let's say that this user, right, they're doing some type of update to an OT device that's on a network over here. I can provide that access. But they're moving it in binary over there. I can still run it through my sandbox to ensure that it's not some sort of wacky piece of ransomware or malware that's out there and stop that from happening. And last but not least, in true Zscare fashion, I can actually do a credential vault, which means I can allow this user to kind of log in with their own credentials here. And as they start to click the little icons, maybe going out to SaaS or cloud or the data center, I can actually inject credentials right here. That way they don't actually know what password was used to access these websites, these applications and whatnot. So when we look at the Zero Trust Browser from Zscare, it's not an enterprise browser, right? It's not another whole client that's out there. It's any modern browser that's out there in the world from a cyber threat protection lens, leveraging cloud browser isolation across the entire platform right here, doing the pixel streaming and getting those amazing controls, the copy and paste, upload, download, read-only mode, print, the session recording, session ushering, session proctoring. I mean, the list kind of goes on and on. Hopefully this is enough to get your appetite wet on the Zero Trust Browser from Zscare. Do me a favor. Reach out to your local sales team. We'd love to talk to you about the utility of the Zero Trust Browser, how it can enhance your user experience and minimize risk for your organization, whether it's your managed devices or, heck, even these third-party contractors, third-party devices. Give them access, but more importantly, not putting them on the network. Leave a comment below, like it. I don't know, but I appreciate you for watching. Have a great day. ♪♪♪