Skip to main content
Browser security architecture

Enterprise browser vs remote browser isolation.

Enterprise browsers govern work inside browser software. Remote isolation executes active page content elsewhere. Some current platforms combine both approaches.

Choose enterprise browsers for session-level workforce governance. Choose isolation for remote execution requirements. Hybrid platforms can cover selected cohorts.

Architecture labels never settle procurement. Deployment, identity, data movement, application behavior, and ownership decide fit.

The cited Legba homepage documents selective isolation. It does not document enterprise browser governance. These sources do not establish platform equivalence.

Written byLegbaReviewed byAakash HarishSecurity Research Contributor, LegbaReviewed 2026-09-03 · Updated 2026-09-03

The short version

These categories overlap increasingly. Vendor category pages promote their own architecture. Direct workflow evidence matters more.

Free for 30 days. No card required. $10 a month, or $100 a year.

The architectural answer.

Enterprise browsers place controls inside browsing sessions. The browser usually remains on endpoints. Policy follows user activity there.

Remote browser isolation moves active execution remotely. A cloud browser fetches pages. The endpoint receives rendered output or instructions.

Modern products blur this boundary. Zscaler offers several browser forms. Menlo combines cloud browsing and extension controls.

Island expanded beyond one dedicated browser. Prisma also documents a browser extension. Choose using required execution boundaries.

  • Enterprise browsers govern local sessions.
  • RBI moves active execution remotely.
  • Hybrid products combine control layers.
  • Browser form changes policy reach.
  • Applications still require direct testing.

SourcesPrisma Browser documentationThe Prisma Browser ExtensionIsland Enterprise BrowserFalcon Seraphic Enterprise BrowserCloudflare Browser IsolationWhat Is Zero Trust Browser?Menlo Remote Browser Isolation

The category boundary now overlaps.

Dedicated enterprise browsers remain one model. Island presents this model directly. Prisma Browser also provides managed browser software.

Runtime modules create another model. CrowdStrike Falcon Seraphic works across chosen browsers. Its claims remain vendor-authored evidence.

Remote isolation remains a distinct execution model. Cloudflare, Zscaler, and Menlo document remote browser execution. Their delivery methods differ.

Several vendors now span categories. Buyers should avoid label-only comparisons. Product form and policy placement matter more.

  • Dedicated browsers embed enterprise management.
  • Extensions preserve existing browser choices.
  • Runtime modules add session controls.
  • Cloud browsers move content execution.
  • Hybrid platforms blend these patterns.

SourcesIsland Enterprise BrowserIsland Enterprise Platform announcementPrisma Browser documentationThe Prisma Browser ExtensionFalcon Seraphic Enterprise BrowserWhat Is Zero Trust Browser?Menlo Secure Enterprise Browser

Execution location changes exposure.

Local enterprise browsers render active pages locally. Their embedded controls observe browser activity. Endpoint exposure depends on implemented protections.

Cloudflare isolation executes active content remotely. Network Vector Rendering returns drawing commands. The endpoint reconstructs page visuals.

Zscaler creates remote Chromium containers. Pixel streaming returns image output. Turbo Mode returns rendering instructions. Endpoints render those instructions natively.

Menlo describes remote cloud browsers too. Its Adaptive Clientless Rendering returns sanitized content. This differs from pixel streaming.

No transport guarantees every application. WebRTC, devices, files, media, and extensions can behave differently. Test important workflows.

  • Locate active JavaScript execution.
  • Locate file inspection boundaries.
  • Identify endpoint rendering work.
  • Identify remote session lifecycle.
  • Test sensitive browser capabilities.

SourcesCloudflare Browser IsolationCloudflare Browser Isolation limitationsWhat Is Zero Trust Browser?Understanding Turbo Mode for isolationMenlo Remote Browser IsolationIsland Enterprise Browser

Use the execution ownership matrix.

This matrix separates five commonly merged questions. It identifies execution, control, user change, state, and ownership. Each row needs evidence.

Treat every product as a specific implementation. Category names only provide starting hypotheses. Pilot results should replace those hypotheses.

Map architecture to operating ownership and proof.
FactorEnterprise browserRemote isolationRequired proof
Active page executionUsually remains within endpoint browsing software.Runs inside remote browser infrastructure.Trace code and file boundaries.
Primary policy pointBrowser session and user actions.Traffic policy and isolated session controls.Map each required control location.
Browser choiceDedicated or extension forms vary.Native browsers receive output or instructions.Document every supported user browser.
Session stateLocal profile behavior depends on product.Remote state may expire or persist.Test sign-in and state deletion.
Unmanaged usersManaged browser workspace may be installed.Clientless or extension paths may apply.Pilot contractor onboarding and removal.
Operations ownerEndpoint and browser teams often participate.Network and access teams often participate.Assign one accountable service owner.
Failure evidenceCapture policy and browser failures.Capture transport and session failures.Use one common severity scale.

Control scope differs substantially.

Enterprise browser products emphasize identity context. They also govern data actions. Copy, paste, upload, download, and capture can become policies.

RBI products emphasize remote execution. Many also expose data controls. Zscaler profiles include file, clipboard, print, and watermark settings.

Menlo now presents combined cloud browsing. Its secure extension adds local visibility and controls. That combination creates another hybrid model.

Similar control names can mislead. Enforcement points differ across architectures. Test both allowed and denied workflows.

  • Map identity signals by cohort.
  • Map data actions by application.
  • Locate each enforcement point.
  • Review audit data ownership.
  • Test exception handling paths.

SourcesManage Prisma Browser access and data rulesIsland Enterprise BrowserCreating isolation profilesMenlo Secure Enterprise Browser

State and experience need testing.

Local browser profiles can preserve familiar state. Exact behavior depends on enterprise configuration. Browser replacement can still change user habits.

Zscaler documents temporary remote containers. Default idle expiration is ten minutes. Optional persistent state can restore browser information.

Zscaler stores persistent state encrypted. Inactive state expires after fifteen days. A one-hundred-megabyte limit applies.

Those figures are volatile product limits. Recheck them before procurement. Other vendors may document different behavior.

Remote rendering also changes interaction paths. Zscaler offers native and browser-in-browser experiences. Turbo Mode adds native endpoint rendering. Application testing remains mandatory.

  • Test authentication persistence requirements.
  • Test idle session recovery.
  • Test multiple windows and tabs.
  • Test accessibility and input methods.
  • Reverify every published limit.

SourcesWhat Is Zero Trust Browser?Understanding Turbo Mode for isolationUsing persistent state for isolationUser experience modes in isolationCloudflare Browser Isolation limitations

Treat vendor comparisons carefully.

Menlo criticizes pixel-streaming isolation publicly. Menlo promotes its own rendering method. That remains vendor positioning.

Enterprise browser vendors often criticize remote latency. RBI vendors often criticize endpoint exposure. Neither argument proves universal outcomes.

Request reproducible pilot evidence. Reject unlabeled benchmark charts. Keep network conditions and applications identical.

  • Label vendor comparisons explicitly.
  • Separate architecture from performance claims.
  • Reject unmatched test conditions.
  • Record undisclosed methodology gaps.
  • Prefer repeatable local evidence.

SourcesMenlo Remote Browser IsolationCloudflare Browser Isolation limitations

Build the proof around boundaries.

Begin with content execution requirements. Then map enterprise controls. Choose representative devices and applications.

Create a managed employee cohort. Create an unmanaged contractor cohort. Include administrators and high-risk workflows.

Record deployment effort separately. Record browsing failures separately. Record policy authoring and support work.

Test rollback before purchase. Exit difficulty can outweigh licensing. Evidence should include complete cleanup.

  1. 01

    Declare boundaries

    State where active content may execute. State required endpoint controls.

  2. 02

    Select cohorts

    Include managed and unmanaged users. Include important operating systems.

  3. 03

    Exercise workflows

    Test identity, data, files, media, and private applications. Record every failure.

  4. 04

    Measure ownership

    Track endpoint, network, identity, and support effort. Name unresolved dependencies.

  5. 05

    Prove rollback

    Remove policies and endpoint components. Confirm state deletion where required.

SourcesPrisma Browser documentationIsland Enterprise BrowserCloudflare Browser IsolationWhat Is Zero Trust Browser?Menlo Remote Browser Isolation

Legba's documented boundary is narrower.

The cited homepage documents Ghost and Shield. It does not document workforce browser management. The homepage does not establish centralized policy.

Shield opens selected pages remotely. Ghost gives Chrome a private route. These modes provide user-chosen routing and isolation.

That homepage does not document comprehensive DLP. It does not establish audit controls. Enterprise architecture needs broader verification.

Evaluate Legba against documented public uses. Evaluate enterprise platforms for governed fleets. Compare only matching contract scopes.

  • Legba's homepage documents Chrome workflows.
  • Enterprise browsers govern workforce sessions.
  • RBI platforms manage remote infrastructure.
  • Hybrid suites span multiple control layers.
  • The homepage does not establish enterprise governance.

SourcesLegba product overviewIsland Enterprise BrowserWhat Is Zero Trust Browser?

FAQs.

What separates enterprise browsers from RBI?
Enterprise browsers govern browser sessions. RBI moves active page execution remotely.
Can one platform provide both models?
Yes, several platforms now blend forms. Verify each documented enforcement boundary.
Does RBI always use pixel streaming?
No, delivery methods differ. Cloudflare uses drawing commands. Menlo returns sanitized content. Zscaler also documents Turbo Mode instructions.
Which architecture performs better?
Public documentation cannot answer universally. Test your applications and network conditions.
Which model suits unmanaged contractors?
Both categories offer relevant options. Compare installation, identity, data, and removal requirements.
Is Legba an enterprise browser platform?
These sources do not establish equivalence. Legba's homepage does not document fleet governance.

References

  1. 01
  2. 02
  3. 03
  4. 04
  5. 05
  6. 06
  7. 07
  8. 08
  9. 09
  10. 10
  11. 11
  12. 12
  13. 13
  14. 14
  15. 15
  16. 16

Keep exploring