This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Redefining Security Standards: Prisma Access Brower Leads the Way Unlock the future of secure workspaces

Download resources

About this session

Karl-Etienne St. Pierre, a SASE specialist at Palo Alto Networks, argues that enterprise browsers close a gap left by SASE and Zero Trust platforms: unmanaged devices, BYOD and contractor access. He recaps what SASE already delivers (consolidated cloud security, SD-WAN, digital experience monitoring) then walks through the limitations of reverse proxies, browser-based access and remote browser isolation for unmanaged endpoints, citing Microsoft data that 85% of ransomware compromises start on unmanaged devices. The core pitch is a containerized, Chromium-based enterprise browser that isolates traffic, applies device-posture checks every 90 seconds, and enforces last-mile controls such as data masking, watermarking, clipboard and file-transfer restrictions, and blocked screen capture, all logged into the same SASE telemetry. He covers use cases including mergers and acquisitions onboarding, BYOD without a managed profile, and undecryptable traffic such as certificate-pinned mobile apps, plus performance features like prefetching and first-mile TCP optimization. A brief Q&A compares the approach to remote browser isolation and clarifies interoperability with existing VPN agents.

Key takeaways

  • Treat unmanaged devices and BYOD as the highest-risk access path; Microsoft data puts 85% of ransomware compromises on unmanaged endpoints.
  • Use a containerized enterprise browser rather than a reverse proxy for contractor and third-party access; URL-rewriting proxies break as applications change.
  • Apply last-mile controls (dynamic data masking, watermarking, clipboard and file-transfer blocking) at the browser layer for data you cannot fully decrypt centrally.
  • Run device-posture checks continuously, not just at login, so access can change automatically if the endpoint's risk profile changes.
  • Pick unified telemetry over point products: route enterprise-browser logs into the same SASE data lake instead of standing up a separate console.

Speakers

Karl-Etienne St. Pierre
Karl-Etienne St. Pierre
SASE Specialist · Palo Alto Networks

Resources

Tags

More from GoSec 2024

Also from Karl-Etienne St. Pierre

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.