Clientless Web Isolation: A Zero-Touch On-Ramp to Cloudflare's Remote Browser

Cloudflare has announced the beta of its clientless web isolation, a new entry point to its Browser Isolation product. The offering natively couples Zero Trust Network Access (ZTNA) with remote browsing's protections against zero-day exploits, phishing, and data loss, letting users on any device browse any website, internal app, or SaaS application without installing software or configuring certificates on the endpoint.

The service streamlines connections to remote browsers via a hyperlink, such as https://<your-auth-domain>.cloudflareaccess.com/browser. After users authenticate through any identity provider supported by Cloudflare Access, their browser establishes a low-latency HTML5 connection to a remote browser hosted in a nearby Cloudflare data center. No servers need to be managed or scaled, and no regions require configuration.

Managed and Unmanaged Device Coverage

Cloudflare's Browser Isolation became generally available in early 2021, natively integrating with the Cloudflare for Teams Zero Trust platform, which combines the Gateway secure web gateway with the Access ZTNA solution. Traditionally, administrators deployed Browser Isolation by installing Cloudflare's device client on endpoints, allowing Cloudflare to operate as a secure DNS and HTTPS Internet proxy. That model protects users and sensitive applications when the administrator controls the team's devices, and end users experience it as nearly indistinguishable from a local browser session.

The end-to-end integration of Browser Isolation with secure Internet access made deployment straightforward, but managing endpoint clients adds configuration overhead for unmanaged devices and for contractors whose devices are under third-party management. Clientless web isolation removes that burden, requiring nothing more than a clickable link to begin a protected session.

Clicking a link in an email or on a website causes a browser to download and execute active web content, which can exploit unknown zero-day threats and compromise an endpoint. Clientless web isolation can be initiated through a prefixed URL, for example https://<your-auth-domain>.cloudflareaccess.com/browser/https://www.example.com. Configuring a custom block page, email gateway, or ticketing tool to prefix high-risk links with Browser Isolation automatically sends those clicks to a remote browser, keeping malicious code off the endpoint.

Introducing Clientless Web Isolation

Cloudflare uses this approach internally for its own security investigations. By prefixing high-risk links with its auth domain, the security team can safely examine potentially malicious websites and phishing sites. No risky code reaches an employee device, and at the end of each investigation, the remote browser is terminated and reset to a known clean state for the next session.

Extending ZTNA with Data Protection

Corporate data is no longer accessed exclusively from managed devices inside controlled networks. Enterprises that rely on strict device posture controls to ensure application access only occurs from managed devices have struggled to support contractor and BYOD workforces, often resorting to costly, resource-intensive Virtual Desktop Infrastructure (VDI) environments.

Screenshot of Access App Launcher bookmark linking to Browser Isolation

Cloudflare Access already applies least-privilege, default-deny policies to web-based applications without needing client software on user devices. Clientless web isolation augments these ZTNA use cases by letting applications protected by Access and Gateway leverage Browser Isolation's data protection controls—including local printing control, clipboard restrictions, and file upload/download limits—to prevent sensitive data from being transferred onto unmanaged devices.

Isolated links can be added to the Access app launcher as bookmarks, enabling team members and contractors to reach any site with one click. Additionally, the remote browser's own traffic remains subject to security controls: all traffic from the remote browser to the target website is secured, inspected, and logged by Cloudflare's Gateway solution, ensuring known threats are filtered through HTTP policies and anti-virus scanning.

Beta Availability

Clientless web isolation will be available to Cloudflare for Teams subscribers who have added Browser Isolation to their plan. Cloudflare is opening the feature for beta access, and interested parties can sign up to participate. The offering aims to let teams of any size deliver seamless Zero Trust connectivity to unmanaged devices anywhere in the world.