Talk to us
by SophosTechBag Intel Page

Sophos Workspace Protection

Your staff work in a browser from anywhere. Your web control shouldn’t need a certificate on every laptop — Sophos Workspace Protection puts web and data policy inside a hardened Chromium browser, filters every Windows app at the DNS layer, and opens private apps through ZTNA, all on one per-user licence.

Policy in the browser, no proxyWindows DNS filtering over DoHZTNA now ships inside it

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Sophos prints no list price; partners quote per user, counted on the largest component
Quote
Inspection
Content policy runs inside Protected Browser; there is no proxy or TLS interception
In-browser
Roaming DNS
The endpoint DNS agent skips macOS and Windows Server, Sophos’s docs say
Windows only
India
Resolver PoPs are global and unlisted; ask which one your Indian offices reach
Not published

Quick answer

Sophos Workspace Protection, on sale since February 2026, puts four controls on one per-user licence: a Chromium browser built with Island, Sophos ZTNA, DNS Protection for Windows endpoints, and an email monitor. There is no network proxy and no inspection certificate. The browser applies web and data policy itself, and the DNS agent filters every other app. There is no public price and no published Indian resolver city. Read more ↓ Show less ↑
Part 01 · Orient

The Sophos platform family

This page covers Sophos Workspace Protection, the browser, DNS and ZTNA bundle. The rest:

Quick facts

30-second orientation
Product
A per-user bundle: Protected Browser and its extension, ZTNA, DNS Protection for endpoints, Email Monitoring
Maker
Sophos, Oxford, UK; owned by Thoma Bravo; CEO Joe Levy; 600,000+ customers worldwide
Status
Announced 21 January 2026 and on sale from February 2026; ZTNA customers moved over on 28 February
Price
No public list price; quoted per user through Sophos partners, with a 30-day trial
Licence
One count: the highest of browser users, ZTNA users or DNS-protected devices in the bundle
Browser
Hardened Chromium built with Island, for 64-bit Windows and Intel or Apple-silicon Macs
DNS layer
A Windows agent sends every app’s DNS over DoH to the nearest Sophos resolver, on or off the network
ZTNA
Now sold only inside this bundle; standalone term SKUs could not be ordered after 1 May 2026
India
Offices in Ahmedabad and Bengaluru; DNS Protection manageable from the India Central region
In India via
TechBag — browser pilot design, licence count check, quote in INR with GST
Part 02 · Learn

Understand browser-led web security before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is a browser-led workspace bundle?

A secure browser enforces web and data policy where the page is drawn, and a DNS agent filters every other app.

A VPN, a web filter and a DNS service bought apart vs one browser-led bundle — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionVPN, web filter and DNS bought apartSophos Workspace Protection
Seeing inside HTTPSA proxy and a certificate on every deviceThe browser already holds the page
Apps outside the browserCovered only on the office networkDNS filtered over DoH on Windows, anywhere
Contractor accessA VPN client and a flat networkZTNA or agentless SSH/RDP in a browser tab
Data leaving a SaaS appUnseen once the page loadedUpload, clipboard and print rules per app
Licences to trackVPN, web filter and DNS, metered apartOne count across all four components
What it is NOT—A network proxy, an API CASB, or a Mac DNS agent

The cheapest test is the 30-day trial: deploy the browser to one team in Warn mode and count what it would have blocked.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where web and data policy is enforced

Browser

Sophos Protected Browser

A hardened Chromium browser built with Island. Each page is allowed, blocked or warned by category, app group or site list, with upload, download and clipboard rules.

02
Policy without a browser switch

Extension

Protected Browser Extension

An extension for Chrome, Edge and Atlas on MDM-managed devices. It omits device-health checks, screen-capture rules, agentless RDP/SSH and incognito windows.

03
The filter for every other app

DNS agent

DNS Protection for endpoints

A component of the Sophos Endpoint agent on Windows. It catches DNS from every program and sends it over DoH to the nearest Sophos resolver, on any network.

04
Private apps, not the network

ZTNA

Sophos ZTNA gateways

Agent-based or agentless access to private apps through on-premises or Sophos Cloud gateways, which allow an average of 15 GB per user a month.

05
One policy and log view

Central

Sophos Central console

Browser, ZTNA, DNS and email monitoring are run from the console that already manages Sophos Endpoint, Firewall and MDR, with one licence count across them.

Policy where the page is drawn — a hardened browser for content, a Windows DNS agent for every other app, ZTNA for the rest.

Part 03 · Evaluate

Nine capabilities. Filter, control, access.

Sophos Workspace Protection enforces policy in the browser and at DNS, with no proxy in the path.

Filter
Web categories

Allow, block or warn

Browser policies match web categories, site lists or app groups and return one of three effects, ranked so the first match wins.

Filter
DNS over HTTPS

Every app’s lookups filtered

On Windows the agent catches DNS from all programs, not just browsers, and resolves it over an encrypted tunnel to Sophos.

Filter
Downloads

Files scanned on the way in

Download rules range from blocking every file to scanning executables only, set per policy rather than one rule for all sites.

Control
Uploads

Uploads held at the app

Upload rules can stop every upload to an app group or let documents through while scanning the rest, without a proxy in the path.

Control
Data boundary

Copy and paste kept inside

Cut, copy and paste can be held inside one app or the browser; printing, saving pages and screen capture can each be blocked.

Control
Shadow AI

AI tools seen and governed

Sophos pitches visibility into shadow IT and AI use, so staff can reach approved AI services while uploads to others are stopped.

Access
ZTNA

Apps reached, network hidden

Users reach only the private applications they are granted, through agent or agentless access, and the rest stays invisible.

Access
SSH and RDP

Servers from a browser tab

Agentless SSH and RDP sessions open inside Protected Browser, which suits contractors who should never get a VPN client.

Access
Posture

Device health in the rule

Device-posture objects for Windows and Mac join user groups in a policy, so an unhealthy laptop meets a stricter rule.

See it, don’t just read it

Watch Sophos Workspace Protection in action

The launch overview, setting up Protected Browser, governing AI use, and agentless SSH and RDP access, all from Sophos.

Sophos (official)·Overview, January 2026

Sophos Workspace Protection: The Future of Hybrid Work

Sophos’s own three-minute launch film for the bundle: browser, ZTNA, DNS and email monitoring in one licence.

Sophos (official)·Walkthrough, January 2026

Sophos Workspace Protection: Set up Sophos Protected Browser

Users, a first web policy and deployment, step by step in the Sophos console.

Sophos (official)·Demo, January 2026

Sophos Workspace Protection: Safe AI use

How browser policy lets staff use approved AI tools while uploads to unapproved ones are stopped.

Sophos (official)·Walkthrough, January 2026

Sophos Protected Browser: Configure agentless SSH/RDP access

Setting up server access from a browser tab, without a VPN client on the contractor’s laptop.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Sophos Workspace Protection

Most work now happens in a browser. Sophos puts the security control inside it.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Content control without a certificate rollout

A proxy has to decrypt traffic to see inside it, which means trusting an inspection certificate on every device and listing the apps that pin their own. Protected Browser is the endpoint of the session, so it already sees the page. Upload, download, clipboard and print rules apply there, with no proxy in the path and no certificate to deploy.

02

A DNS floor under every other app

Traffic outside the browser still needs a control. On Windows, the DNS Protection agent intercepts lookups from every program and sends them over DoH to Sophos’s nearest resolver. So Outlook, Teams and an unknown updater are filtered by category on or off the office network, and the encrypted tunnel removes the simplest snooping and poisoning paths.

03

One licence where there were three

ZTNA, web policy and DNS filtering usually mean three products, three agents and three meters. Here they share one count: the highest of browser users, ZTNA users or DNS devices. Existing Sophos ZTNA customers were moved into the bundle on 28 February 2026. Everything is run from the Sophos Central console an Intercept X or Firewall estate already uses.

04

Where it stops

Nothing is inspected in the network: traffic from other browsers or apps gets DNS filtering only. The DNS agent runs on Windows alone, not on macOS or Windows Server, and there is no mobile browser. CASB means in-browser controls, not API scans of data at rest. Sophos publishes no price, no resolver cities and no scale beyond 5,000 users.

The idea
Policy in the browser, not a proxy
The floor
DNS over DoH for every Windows app
The price
Quote only, one per-user count
Proof, not promises

The numbers behind the platform

4 products
browser, ZTNA, endpoint DNS filtering and email monitoring sold on one per-user licence
— Vendor
15 GB
the average monthly ZTNA traffic per user that Sophos Cloud gateways allow
— Vendor
3 effects
every browser policy returns allow, block or warn, evaluated in rank order
— Vendor
30 days
the free trial, and the idle period after which a ZTNA user leaves the licence count
— Vendor
2026
the year Sophos launched the bundle and moved every ZTNA customer onto it
— Vendor
2 offices
Sophos offices in India, in Ahmedabad and Bengaluru, with a toll-free support line
— Vendor

What your Sophos Workspace Protection rollout looks like

Week 1Model

Count users, devices and Macs

List browser users, ZTNA users and Windows devices; the largest sets the licence, and Macs will get no DNS agent.

Week 2Decide

Pick the apps that hold the data

Name the SaaS and private apps whose uploads, clipboard and downloads matter, and who outside the company needs them.

Week 3Pilot

Pilot the browser with one team

Deploy Protected Browser by Intune or Jamf to a pilot group, start policies on Warn, and log what they would block.

Month 2Prove

Switch on DNS and test bypass

Enable the DNS agent on Windows, run your top fifty destinations, and check what a personal VPN still gets past.

Month 3Commit

Move contractors to ZTNA

Replace VPN accounts with browser-based ZTNA and agentless RDP/SSH, then turn Warn rules into Block where safe.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4
38+ reviews*
78% would recommend
Browser data controls4.3
ZTNA and SSH/RDP4.2
DNS filtering4.0
Platform coverage3.5
Value for money3.8
5★
40%
4★
37%
3★
15%
2★
6%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“Auditors log into our core app through the protected browser now. Copy-out is blocked, and nobody had to install a VPN.”
IT Manager
BFSI
IT Services
“We had never got a TLS certificate onto contractor laptops. Putting the controls in the browser removed that whole fight.”
Security Lead
IT Services
Pharma
“The DNS agent caught a field laptop beaconing from a hotel network. Our firewall would never have seen that traffic.”
Systems Administrator
Pharma
Healthcare
“Staff can use one approved AI tool while uploads to the rest are stopped. That calmed our compliance team quickly.”
Head of IT
Healthcare
Media
“Our design team runs Macs, so they get the browser but no DNS agent. Plan for that gap before you promise coverage.”
Infrastructure Engineer
Media
Manufacturing
“The licence counts the biggest component, and 100 DNS devices set our number even though only 80 used the browser.”
Procurement Lead
Manufacturing
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the secure web and DNS market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Secure Web & DNS Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Sophos Workspace ProtectionThis page

Quote-only per user; launched February 2026.

Grid 02 · The architecture

Off-Network Reach × Content Visibility

The grid nobody publishes — how many devices and operating systems the agent covers off the network vs how much of the traffic it can actually see.

Deep, but browser-boundFull proxy, everywhereDNS floor, Windows-firstWide DNS reach
Sophos Workspace ProtectionThis page

Windows DNS agent; content rules inside the browser only.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Sophos Workspace Protection vs the secure web and DNS field

Against Cisco Umbrella, Cloudflare One Gateway, Zscaler Internet Access, OpenText Core DNS Protection and Fortinet FortiSASE: on enforcement layer, TLS, roaming, bypass, CASB, ZTNA, price and India.

DimensionSophos Workspace ProtectionCisco UmbrellaCloudflare One GatewayZscaler Internet AccessOpenText Core DNS ProtectionFortinet FortiSASE
What it isBrowser + DNS + ZTNADNS security, then SIGSWG in Cloudflare OneCloud proxy SWGDNS filter, ex-WebrootFortinet’s SASE service
DeploymentBrowser and agentsResolver or clientWARP client or tunnelsConnector or tunnelsAgent or DNS forwardingFortiClient or FortiGate
Enforcement layerDNS + in-browser policyDNS, proxy at SIG tiersDNS, HTTP and networkFull proxy onlyDNS layer onlyDNS and full proxy
TLS inspectionNone needed in-browserSelective, SIG tiersFull, with a certificateFull inspectionNoneFull inspection
Roaming coverageWindows DNS agentRoaming moduleWARP on five OSesClient ConnectorWindows agent onlyFortiClient agent
DoH and bypassAgent intercepts all DNSClient plus categoriesDevice client owns DNSProxy sees DoH as HTTPSBlocks DoH and DoTAgent-dependent
Cloud app controlIn-browser app rulesAPI CASBInline and APIInline and APINoneInline CASB
Private app accessZTNA includedNot in UmbrellaAccess in the planZPA, sold apartNoneZTNA included
Pricing modelPer user, largest partPer user, four packagesPer user a monthPer user, editionsNo unit publishedPer user, by tier
Published entry priceNot published~$30–40/user/yrFree, then $7/user/mo~$6–12/user/moQuote onlyQuote; G-Cloud £78–304
India presenceOffices; PoPs unlistedMumbai and ChennaiSix Indian citiesFour Indian citiesNot publishedPoP cities unverified
SupportPartner + SophosSupport packagesPlan-dependentTiered, on contractThrough the MSPFortiCare
Lock-in and exitBrowser habits to undoResolver swapCertificate and clientProxy policy rebuildLight to leaveFabric pulls you in
Best fitBrowser-first hybridCheap DNS everywherePublished-price SSEDeepest inspectionMSP-run DNS floorFortiGate estates
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Sophos Workspace Protection if…

  • ✓You want upload, clipboard and download rules for SaaS apps without decrypting traffic or rolling a certificate to every laptop
  • ✓Contractors or partners need private apps, SSH or RDP from a browser tab rather than a VPN client and a flat network
  • ✓You already run Sophos Endpoint or Firewall, and want ZTNA, web policy and Windows DNS filtering on one per-user count

Compare alternatives if…

  • ✓Every app and browser must be inspected in depth: Zscaler ZIA or Cloudflare One proxy and decrypt all of it
  • ✓You need a printed price: Cloudflare is free to 50 users, then $7; FortiSASE is quoted, though a UK G-Cloud list starts at £78 a year
  • ✓Indian resolver cities must be documented: Cloudflare names six and Cisco Umbrella two

Do not expect…

  • ✓A DNS agent for macOS or Windows Server, or a mobile browser
  • ✓API CASB scans of data already in your SaaS tenants
  • ✓A published price, or an analyst placement for this product

Sophos Workspace Protection is one of 44 secure web & DNS products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does piecemeal remote-access security cost you?

Drag the sliders (hybrid users; IT-hour cost). Estimates model IT time spent on VPN accounts for contractors, blocked-site exceptions and chasing data copied out of SaaS apps, at an assumed 1.5 hours per user a year, with 70% of it removed by browser policy, ZTNA and DNS filtering on one console. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual remote-access admin cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Not published: Sophos sells Workspace Protection per user through partners, as a fixed-term subscription or monthly through MSP Flex. The count is the largest of three numbers in the bundle: Protected Browser users, ZTNA users or DNS-protected devices. A 30-day trial runs from Sophos Central. TechBag checks which component sets your count, then quotes in INR with GST.

Workspace Protection (term)

Best for estates buying it directly

  • Quoted per user; no public list price
  • Browser, ZTNA, Windows DNS and email monitoring
  • 30-day trial from Sophos Central

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Workspace Protection (MSP Flex)

Best for businesses run by an MSP

  • Billed monthly through a Sophos MSP
  • Same four components, same count rule
  • Standalone ZTNA no longer offered on Flex

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Licence count

Which component is largest — browser users, ZTNA users or DNS devices? That number sets the whole licence.

2
Mac and server gap

How will macOS laptops and Windows servers be filtered, since the DNS agent covers Windows endpoints only?

3
Other browsers

Will Chrome and Edge be blocked from sensitive apps, or covered by the extension on MDM-managed devices?

4
DNS filtering mandate

Does a regulator apply? SEBI CSCRF guideline 4.e says “REs shall implement DNS filtering services…”.

5
Log retention

Can DNS and browser logs be kept 180 days, as the CERT-In Directions of 28 April 2022 require of logs?

6
Resolver latency

Which Sophos resolver do our Indian offices reach? Sophos lists no cities, so measure lookups from each site.

7
Data storage

Which Sophos Central region will store our browser, ZTNA and DNS logs? Ask for the India region in writing.

8
Agent version

Is every Windows endpoint on a supported Sophos Endpoint release, the agent that carries DNS Protection?

FAQ

Questions buyers ask

A per-user bundle Sophos launched in February 2026. It contains Protected Browser, a hardened Chromium browser built with Island, and an extension for Chrome and Edge. It adds Sophos ZTNA, DNS Protection for Windows endpoints, and an Email Monitoring System that scans journaled mail but takes no action.

Ready to evaluate Sophos Workspace Protection?

Count your browser users, ZTNA users and Windows devices first, or let a TechBag advisor scope a pilot that puts one team's SaaS apps behind Protected Browser.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.