Beyond the VPN: Locking Down What Users Can Do Inside Apps
Most CIOs we speak with are looking to consolidate dozens of point solutions as they begin their Zero Trust journey. Cloudflare One, our Secure Access Service Edge (SASE) platform, is built to help teams eliminate legacy appliances and services without sacrificing performance.
Today, we're integrating our browser isolation technology directly into our Zero Trust access control product. This lets your team manage not just who reaches an application, but also what they can do inside it, with a single click in the Cloudflare dashboard. This move is designed to help you replace private networks, virtual desktops, and data control boxes with a single, faster Zero Trust solution.
From Access Control to Data Control
Many organizations start their Zero Trust migration by replacing a VPN. The problem with VPNs is that they trust too many users by default; often, any user on the private network can reach any resource. This can lead to a marketing employee stumbling upon payroll data or an attacker with a compromised support agent's credentials pivoting to trade secrets.
Zero Trust access control inverts this model. It trusts no one by default, requiring every user and request to prove they can reach a specific resource. Over 10,000 teams have adopted Cloudflare One for this purpose. They use our rules to enforce hard key authentication, require purpose justification for temporary access, and verify device posture with integrations or custom checks.
However, once a user passes these checks, we still rely on the application itself to decide what they can do. That's a gap. An employee may be authorized to access a system but could still download customer contact info or screenshot schematics. Extending Zero Trust to control application usage and data is the next step in a SASE migration.
How Isolation Works
Cloudflare's browser isolation technology provides that control without a terrible user experience. Older methods had compromises:
- Document Object Model (DOM) manipulation – Inspects and repacks webpages, often breaking them and missing zero-day threats.
- Pixel pushing – Streams a remote browser like a video, leading to performance complaints and input issues.
Our approach is different. We run headless Chromium browsers in our global data centers and send only the final rendering commands—the draw commands—to the user's device.

To the user, it feels like a normal website. Highlighting, right-clicking, and videos work seamlessly, with no special client required on mobile or desktop. For security teams, this guarantees code never executes on end-user devices, stopping Zero-Day attacks.
We added browser isolation to Cloudflare One primarily to protect against threats from the public Internet. But controlling the browser also enables security and IT teams to address a different risk: data misuse.
As part of this launch, administrators can enable a new button when securing an application with our Zero Trust access control. This forces sessions into our isolated browser.

When a user authenticates, Cloudflare Access checks all configured Zero Trust rules. If isolation is enabled, the session is silently opened in our isolated browser, running entirely on Cloudflare's network. Users need no special software or training; they just navigate to the app and work.
Replacing the VDI
Running sessions in our isolated browser lets administrators build rules that fulfill the goals of legacy virtual desktop infrastructure (VDI) without the pain. VDI platforms were often deployed to sandbox application usage for employees and contractors. However, users find the required client software clunky and slow, and administrators must maintain the underlying desktops and virtualization software.
We're excited to help replace that point solution, too. Once an application is isolated, you can toggle rules to control user interaction. For example, you can disable data loss vectors like file downloads, printing, or copy-pasting, and add visible or invisible watermarks to audit screenshot leaks. You can even toggle "Disable keyboard" to provide a read-only view of a sensitive application without developer time for a dedicated mode.

This solution also integrates with Cloudflare One's Data Loss Prevention (DLP) suite. With a few settings, you gain comprehensive data control without extra engineering. If a user attempts to download a file containing personal information like social security or credit card numbers, Cloudflare's network will block it while still permitting approved files.

Applying the Same Control to SaaS
Many customers need this control for self-hosted applications, but there's a growing need for SaaS apps too. While some SaaS tools have robust role-based rules, they often aren't comprehensive and require managing a dozen different settings.
To avoid that hassle, you can bring this one-click isolation feature to your SaaS applications. Our access control solution can act as an identity proxy, forcing logins to any SSO-enabled SaaS application through Cloudflare's network, where additional rules—including isolation—can be applied.
Getting Started
Today's announcement unifies two popular solutions: Cloudflare Access and browser isolation. Both are available now. You can begin building rules for isolation and data control by following the guides here.
If you'd prefer the one-click version, you can join the beta we're rolling out to customer accounts today.



