Settings
Configure browser settings, such as Browser enforcement and Phishing Protection.
Browser enforcement via IdP
You can configure access to your critical SaaS applications only through Protected Browser, blocking access from other browsers. To enforce this, use an identity provider (IdP), such as Entra ID or Okta. The IdP authenticates all requests to a specified domain and then routes the traffic through a ZTNA data plane region. To enable this, create a conditional access policy in your IdP that allows the IP address of the ZTNA data plane region you want to use for authentication.
Note
The authentication token is managed by your IdP. If you configure session controls through conditional access policies in your IdP, those settings take precedence. For example, if you set a sign-in frequency of 2 days using a conditional access policy, sessions expire after 2 days. If you don't configure any session controls in your IdP, Protected Browser uses a default session expiry of 7 days.
To configure browser enforcement for your applications, do as follows:
- Click the Global Settings icon
. - Go to Products and Services, and click Protected Browser.
-
Select an identity provider from the following options:
- Entra ID: Entra ID authenticates all application access requests that
login.microsoftonline.comreceives. - Okta: Enter the domain that receives application access requests. Okta authenticates requests that the domain you specify receives.
- Entra ID: Entra ID authenticates all application access requests that
-
Under Data plane region, select the ZTNA data plane region you want to use for authentication.
-
Click Copy IPs list to copy the IP addresses of the ZTNA dataplane region.
You must allow these IP addresses in your IdP for every application whose access you want to enforce through Protected Browser.
Phishing Protection
Phishing Protection helps prevent users from entering corporate email addresses and credentials on suspicious or impersonated websites. It monitors website forms for email addresses and domains that you specify. To use Phishing Protection, turn it on globally and then turn it on in web policies for specific sites, applications, or web categories. If a user attempts to submit a monitored email address on a site, Protected Browser can either warn the user or block the submission, depending on the setting you specify in the policy.
Phishing Protection monitors websites that users visit in Protected Browser. It doesn't scan email messages. Instead, it helps protect users when they interact with websites that attempt to collect corporate credentials.
To turn on Phishing Protection globally, do as follows:
- Go to My Products > Protected Browser > Settings.
- Select the Phishing Protection tab.
- Turn on Phishing Protection.
-
In Email domains to protect, enter one or more corporate email domains or specific email addresses.
- To protect all users in a domain, enter a domain such as
example.com. - To protect specific users, for example during testing, enter individual email addresses.
- To protect all users in a domain, enter a domain such as
-
Click Save.
- Go to My Products > Protected Browser > Web policies, and turn on Phishing Protection in the base policy or any custom policy.