Below, you will find information regarding the current limitations for Browser Isolation.
Our Network Vector Rendering (NVR) technology sends drawing instructions to the user's browser instead of streaming video of the page. This allows us to deliver a secure remote computing experience without the bandwidth limitations of video streams. While we expect most websites to work perfectly, some browser features and web technologies are unsupported and will be implemented in the future:
- Webcam and microphone support is unavailable.
- Websites that use WebGL (a browser technology for rendering 3D graphics) may not function. To turn off WebGL in the browser, refer to WebGL Rendering Error.
- Netflix and Spotify Web Player are unavailable.
- H.265/HEVC (a video compression format) is not a supported video format at this time.
Browser Isolation supports one active window at a time. All tabs and windows in the same local browser (for example, all Chrome tabs) share a single isolated session. Within that session, the remote browser actively renders and processes only the tab or window currently in focus. Browser Isolation deactivates background tabs and windows until you switch to them.
This means that workflows requiring simultaneous activity across multiple windows are unavailable.
For example:
- Audio or video playing in one isolated window will pause when you switch to a different isolated window.
- Real-time content (such as live dashboards or streaming media) will not update in background windows.
- Applications that rely on multi-window communication or synchronization are not supported.
| Browser | Compatibility |
|---|---|
| Google Chrome | ✅ |
| Mozilla Firefox | ✅ |
| Safari | ✅ |
| Microsoft Edge (Chromium-based) | ✅ |
| Other Chromium-based browsers (Opera, Brave) | ✅ |
| Internet Explorer 11 and below | ❌ |
On iOS, Apple WebKit requires direct user interaction before the local browser can pass keyboard input into the remote browser. This means users should tap twice to begin entering text in an isolated session.
The first tap focuses the text field. The second tap starts text entry.
Browser Isolation shows an inline prompt over the focused text field when this interaction is required. If the text field is too small to display the full prompt, Browser Isolation displays a keyboard icon in the center of the field instead.
Browser Isolation uses WebRTC for low-latency communication between the local and remote browser. Brave's WebRTC IP Handling Policy can impact how Cloudflare RBI loads and functions. If the WebRTC IP Handling Policy is configured to Disable Non-Proxied UDP, RBI may fail to load correctly because Brave blocks the UDP connections that WebRTC requires.
To ensure RBI loads correctly, go to brave://settings/privacy in your Brave browser window, find WebRTC IP Handling Policy, and change the setting from Disable Non-Proxied UDP to one of the following:
- Default
- Default Public and Private Interfaces
- Default Public Interface Only
Browser Isolation requires HTTPS. Websites served over unencrypted HTTP cannot be isolated.
Browser Isolation is not supported in virtualized environments (VMs).
Certain selectors for Gateway HTTP policies bypass Browser Isolation, including:
You cannot use these selectors to isolate traffic and isolation matches for these selectors will not appear in your Gateway logs. Additionally, you cannot apply other policies based on these selectors while in isolation. For example, if you have a Block policy that matches traffic based on destination IP, Gateway will not block the matching traffic if it is already isolated by an Isolate policy.
The remote browser runs in a Linux-based container that does not include proprietary or licensed fonts such as Arial, Times New Roman, or other fonts typically bundled with Windows or macOS. If a website's CSS specifies one of these fonts without a generic fallback, the remote browser cannot match the named font and falls back to its own default, which may render text differently than expected.
For example, the following CSS will produce different results in the remote browser than on a local Windows machine:
/* No generic fallback — text may render differently in Browser Isolation */
body {
font-family: Arial;
}To avoid font rendering differences, website owners should always include a generic fallback family at the end of their font-family declarations:
/* Generic fallback ensures consistent rendering */
body {
font-family: Arial, sans-serif;
}Websites that load custom fonts as web fonts (for example, from Google Fonts or a self-hosted source) are not affected, because the remote browser downloads and uses the font file directly.
When a user downloads a file within the remote browser, the file is held in memory and destroyed at the end of the remote browser session. Therefore, the total size of files downloaded per session is shared with the amount of memory available to the remote browser. We recommend a maximum individual file size of 512 MB.
Clientless Web Isolation does not support Yubikey or WebAuthN (hardware security key authentication). These authentication technologies require the isolated website to use the same domain name as the non-isolated website. Clientless Web Isolation changes the URL by adding a prefix, which breaks this requirement. Therefore, Yubikey and WebAuthN will not work with prefixed Clientless Web Isolation URLs but will work normally for in-line deployments such as isolated Access applications.
Cloudflare Remote Browser Isolation now supports SAML applications that use HTTP-POST bindings. SAML is a protocol used for single sign-on (SSO), and some SAML implementations send login data via an HTTP POST request (HTTP-POST bindings). This resolves previous issues such as 405 errors and login loops during SSO authentication flows.
You no longer need to isolate both the Identity Provider (IdP) and Service Provider (SP), or switch to HTTP-Redirect bindings, to use Browser Isolation with POST-based SSO. Users can log in to internal or SaaS applications in the isolated browser securely and seamlessly.
Clientless Web Isolation may still be preferred in some deployment models. Clientless Web Isolation implicitly isolates all traffic (both IdP and SP) and supports HTTP-POST SAML bindings.
Browser Isolation is not compatible with self-hosted private applications that use private IPs or hostnames on ports other than 443. Trying to access self-hosted applications on non-443 ports will result in a Gateway block page.
To use Browser Isolation for an application on a private IP address with a non-443 port, configure a private network application instead.