Your staff work in a browser from anywhere. Your web control shouldn’t need a certificate on every laptop — Sophos Workspace Protection puts web and data policy inside a hardened Chromium browser, filters every Windows app at the DNS layer, and opens private apps through ZTNA, all on one per-user licence.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Sophos Workspace Protection, the browser, DNS and ZTNA bundle. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A secure browser enforces web and data policy where the page is drawn, and a DNS agent filters every other app.
What consolidation actually replaces, dimension by dimension.
| Dimension | VPN, web filter and DNS bought apart | Sophos Workspace Protection |
|---|---|---|
| Seeing inside HTTPS | A proxy and a certificate on every device | The browser already holds the page |
| Apps outside the browser | Covered only on the office network | DNS filtered over DoH on Windows, anywhere |
| Contractor access | A VPN client and a flat network | ZTNA or agentless SSH/RDP in a browser tab |
| Data leaving a SaaS app | Unseen once the page loaded | Upload, clipboard and print rules per app |
| Licences to track | VPN, web filter and DNS, metered apart | One count across all four components |
| What it is NOT | — | A network proxy, an API CASB, or a Mac DNS agent |
The cheapest test is the 30-day trial: deploy the browser to one team in Warn mode and count what it would have blocked.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
A hardened Chromium browser built with Island. Each page is allowed, blocked or warned by category, app group or site list, with upload, download and clipboard rules.
An extension for Chrome, Edge and Atlas on MDM-managed devices. It omits device-health checks, screen-capture rules, agentless RDP/SSH and incognito windows.
A component of the Sophos Endpoint agent on Windows. It catches DNS from every program and sends it over DoH to the nearest Sophos resolver, on any network.
Agent-based or agentless access to private apps through on-premises or Sophos Cloud gateways, which allow an average of 15 GB per user a month.
Browser, ZTNA, DNS and email monitoring are run from the console that already manages Sophos Endpoint, Firewall and MDR, with one licence count across them.
Policy where the page is drawn — a hardened browser for content, a Windows DNS agent for every other app, ZTNA for the rest.
Sophos Workspace Protection enforces policy in the browser and at DNS, with no proxy in the path.
Browser policies match web categories, site lists or app groups and return one of three effects, ranked so the first match wins.
On Windows the agent catches DNS from all programs, not just browsers, and resolves it over an encrypted tunnel to Sophos.
Download rules range from blocking every file to scanning executables only, set per policy rather than one rule for all sites.
Upload rules can stop every upload to an app group or let documents through while scanning the rest, without a proxy in the path.
Cut, copy and paste can be held inside one app or the browser; printing, saving pages and screen capture can each be blocked.
Sophos pitches visibility into shadow IT and AI use, so staff can reach approved AI services while uploads to others are stopped.
Users reach only the private applications they are granted, through agent or agentless access, and the rest stays invisible.
Agentless SSH and RDP sessions open inside Protected Browser, which suits contractors who should never get a VPN client.
Device-posture objects for Windows and Mac join user groups in a policy, so an unhealthy laptop meets a stricter rule.
The launch overview, setting up Protected Browser, governing AI use, and agentless SSH and RDP access, all from Sophos.
Sophos’s own three-minute launch film for the bundle: browser, ZTNA, DNS and email monitoring in one licence.
Users, a first web policy and deployment, step by step in the Sophos console.
How browser policy lets staff use approved AI tools while uploads to unapproved ones are stopped.
Setting up server access from a browser tab, without a VPN client on the contractor’s laptop.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
A proxy has to decrypt traffic to see inside it, which means trusting an inspection certificate on every device and listing the apps that pin their own. Protected Browser is the endpoint of the session, so it already sees the page. Upload, download, clipboard and print rules apply there, with no proxy in the path and no certificate to deploy.
Traffic outside the browser still needs a control. On Windows, the DNS Protection agent intercepts lookups from every program and sends them over DoH to Sophos’s nearest resolver. So Outlook, Teams and an unknown updater are filtered by category on or off the office network, and the encrypted tunnel removes the simplest snooping and poisoning paths.
ZTNA, web policy and DNS filtering usually mean three products, three agents and three meters. Here they share one count: the highest of browser users, ZTNA users or DNS devices. Existing Sophos ZTNA customers were moved into the bundle on 28 February 2026. Everything is run from the Sophos Central console an Intercept X or Firewall estate already uses.
Nothing is inspected in the network: traffic from other browsers or apps gets DNS filtering only. The DNS agent runs on Windows alone, not on macOS or Windows Server, and there is no mobile browser. CASB means in-browser controls, not API scans of data at rest. Sophos publishes no price, no resolver cities and no scale beyond 5,000 users.
List browser users, ZTNA users and Windows devices; the largest sets the licence, and Macs will get no DNS agent.
Name the SaaS and private apps whose uploads, clipboard and downloads matter, and who outside the company needs them.
Deploy Protected Browser by Intune or Jamf to a pilot group, start policies on Warn, and log what they would block.
Enable the DNS agent on Windows, run your top fifty destinations, and check what a personal VPN still gets past.
Replace VPN accounts with browser-based ZTNA and agentless RDP/SSH, then turn Warn rules into Block where safe.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Auditors log into our core app through the protected browser now. Copy-out is blocked, and nobody had to install a VPN.”
“We had never got a TLS certificate onto contractor laptops. Putting the controls in the browser removed that whole fight.”
“The DNS agent caught a field laptop beaconing from a hotel network. Our firewall would never have seen that traffic.”
“Staff can use one approved AI tool while uploads to the rest are stopped. That calmed our compliance team quickly.”
“Our design team runs Macs, so they get the browser but no DNS agent. Plan for that gap before you promise coverage.”
“The licence counts the biggest component, and 100 DNS devices set our number even though only 80 used the browser.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the secure web and DNS market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quote-only per user; launched February 2026.
The grid nobody publishes — how many devices and operating systems the agent covers off the network vs how much of the traffic it can actually see.
Windows DNS agent; content rules inside the browser only.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Cisco Umbrella, Cloudflare One Gateway, Zscaler Internet Access, OpenText Core DNS Protection and Fortinet FortiSASE: on enforcement layer, TLS, roaming, bypass, CASB, ZTNA, price and India.
| Dimension | Sophos Workspace Protection | Cisco Umbrella | Cloudflare One Gateway | Zscaler Internet Access | OpenText Core DNS Protection | Fortinet FortiSASE |
|---|---|---|---|---|---|---|
| What it is | Browser + DNS + ZTNA | DNS security, then SIG | SWG in Cloudflare One | Cloud proxy SWG | DNS filter, ex-Webroot | Fortinet’s SASE service |
| Deployment | Browser and agents | Resolver or client | WARP client or tunnels | Connector or tunnels | Agent or DNS forwarding | FortiClient or FortiGate |
| Enforcement layer | DNS + in-browser policy | DNS, proxy at SIG tiers | DNS, HTTP and network | Full proxy only | DNS layer only | DNS and full proxy |
| TLS inspection | None needed in-browser | Selective, SIG tiers | Full, with a certificate | Full inspection | None | Full inspection |
| Roaming coverage | Windows DNS agent | Roaming module | WARP on five OSes | Client Connector | Windows agent only | FortiClient agent |
| DoH and bypass | Agent intercepts all DNS | Client plus categories | Device client owns DNS | Proxy sees DoH as HTTPS | Blocks DoH and DoT | Agent-dependent |
| Cloud app control | In-browser app rules | API CASB | Inline and API | Inline and API | None | Inline CASB |
| Private app access | ZTNA included | Not in Umbrella | Access in the plan | ZPA, sold apart | None | ZTNA included |
| Pricing model | Per user, largest part | Per user, four packages | Per user a month | Per user, editions | No unit published | Per user, by tier |
| Published entry price | Not published | ~$30–40/user/yr | Free, then $7/user/mo | ~$6–12/user/mo | Quote only | Quote; G-Cloud £78–304 |
| India presence | Offices; PoPs unlisted | Mumbai and Chennai | Six Indian cities | Four Indian cities | Not published | PoP cities unverified |
| Support | Partner + Sophos | Support packages | Plan-dependent | Tiered, on contract | Through the MSP | FortiCare |
| Lock-in and exit | Browser habits to undo | Resolver swap | Certificate and client | Proxy policy rebuild | Light to leave | Fabric pulls you in |
| Best fit | Browser-first hybrid | Cheap DNS everywhere | Published-price SSE | Deepest inspection | MSP-run DNS floor | FortiGate estates |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Sophos Workspace Protection is one of 44 secure web & DNS products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (hybrid users; IT-hour cost). Estimates model IT time spent on VPN accounts for contractors, blocked-site exceptions and chasing data copied out of SaaS apps, at an assumed 1.5 hours per user a year, with 70% of it removed by browser policy, ZTNA and DNS filtering on one console. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not published: Sophos sells Workspace Protection per user through partners, as a fixed-term subscription or monthly through MSP Flex. The count is the largest of three numbers in the bundle: Protected Browser users, ZTNA users or DNS-protected devices. A 30-day trial runs from Sophos Central. TechBag checks which component sets your count, then quotes in INR with GST.
Best for estates buying it directly
Best for a broader rollout
Best for businesses run by an MSP
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Which component is largest — browser users, ZTNA users or DNS devices? That number sets the whole licence.
How will macOS laptops and Windows servers be filtered, since the DNS agent covers Windows endpoints only?
Will Chrome and Edge be blocked from sensitive apps, or covered by the extension on MDM-managed devices?
Does a regulator apply? SEBI CSCRF guideline 4.e says “REs shall implement DNS filtering services…”.
Can DNS and browser logs be kept 180 days, as the CERT-In Directions of 28 April 2022 require of logs?
Which Sophos resolver do our Indian offices reach? Sophos lists no cities, so measure lookups from each site.
Which Sophos Central region will store our browser, ZTNA and DNS logs? Ask for the India region in writing.
Is every Windows endpoint on a supported Sophos Endpoint release, the agent that carries DNS Protection?
Count your browser users, ZTNA users and Windows devices first, or let a TechBag advisor scope a pilot that puts one team's SaaS apps behind Protected Browser.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.