# Web Isolation Last Updated On: 24 Jul 2026 4 minutes read Open risky websites in a virtualized, disposable environment so malicious content never reaches the device. ## About Web Isolation Browsers are essential to modern work, and also a direct line of exposure to online threats. ### What it does **Web Isolation** provides a critical layer of protection by creating a virtualized browsing environment that isolates malicious content from user devices, reducing the risk of malware infections and data breaches. ## Working of Web Isolation Virtualization and sandboxing keep risky sites from ever touching the real device. ### Virtualization and sandboxing Web isolation uses two primary methods to protect users — virtualization and sandboxing — to prevent malicious content from reaching a device. It's like a quarantined area for websites, where everything is wiped clean after browsing, leaving no trace of potential threats. It also protects user privacy by isolating certain websites and preventing cache, image files, and cookies from being stored on the local machine. Endpoint Central MSP's Web Isolation protects devices from malware and data breaches by segregating personal and business websites, isolating malicious sites in a virtual environment so they can't infect devices or access sensitive data. When a user visits a malicious website, web isolation prevents the malware from infecting their device. **Prerequisites** This policy applies to Microsoft Internet Explorer and Edge on Windows 10 Enterprise Edition version 1709 and later. ## Implementing Web Isolation Pick which sites open in isolation, then decide how persistent and embeddable that isolated session should be. ### Create and deploy a Web Isolation policy 1. Open the Endpoint Central MSP console and go to **Browsers → Policies → Web Isolation**. 2. Click **Create Policy**. 3. Give the policy a name. 4. Enter the web applications or website groups that should open separately, in isolation. 5. Click **Allow** for **Data persistence between sessions** to retain site data across different browsing sessions. 6. Click **Allow** for **iFrame Restriction** to limit or prevent isolated sites from embedding content from other sources via iFrames. 7. Click **Save & Publish** to save the policy. 8. [Deploy](https://www.manageengine.com/desktop-management-msp/help/browser-security/policy-deployment.html) the policy with the computers or groups where web-application isolation should take place. ![Web Isolation policy configuration screen.](https://www.manageengine.com/products/desktop-central/help/images/web-isolation.png) Configuring the Web Isolation policy. ## Related - [Browser Security Overview](https://www.manageengine.com/desktop-management-msp/help/browser-security/browser-overview.html) - [Policy Deployment](https://www.manageengine.com/desktop-management-msp/help/browser-security/policy-deployment.html) - [Browser Security FAQ](https://www.manageengine.com/desktop-management-msp/help/browser-security/browser-faq.html#restrictfaq)