# Browser Restriction Allowlist or blocklist browsers so employees stay on a single, secured browser. **Last Updated On**: 24 Jul 2026 **4 minutes read** ## About Browser Restriction Control exactly which browsers are allowed to run on managed devices. ### What it does **Browser Restriction** lets admins control which browsers can be used on devices. By allowlisting or blocklisting specific browsers, admins can prevent unauthorized usage, ensure the best user experience and highest security, and prevent certain features from being available on specific browsers. ## Why mandate a single browser Fewer browsers in play means fewer compatibility surprises and a smaller security surface. ### Consistency at scale Remote work has increased reliance on web browsers, and with many browsers available, each with unique features, IT admins face real challenges managing them all. Most web applications work across different browsers, but compatibility issues can still arise, leading to disruptions and increased help desk calls. Browser Restriction lets IT admins mandate a single browser for employees, and test mission-critical web applications against just that browser. This keeps the user experience consistent and lets IT focus on securing one browser instead of several. ## Implementing Browser Restriction Build an allowlist or blocklist policy and roll it out network-wide. ### Create and deploy a Browser Restriction policy 1. Open the Endpoint Central MSP console and go to **Browsers → Policies → Browser Restriction**. 2. Click **Create Policy**. 3. Select **Allowlist** or **Blocklist** to allow or block the respective browsers. 4. Choose the browsers to allowlist or blocklist from the list. 5. Click **Save** to save the policy as a draft. 6. Click **Save & Publish** to publish the policy. 7. [Deploy](https://www.manageengine.com/desktop-management-msp/help/browser-security/policy-deployment.html) the policy with the computers or groups where web-application access should be restricted. ![Browser Restriction policy configuration screen.](https://www.manageengine.com/products/desktop-central/help/images/browser-restriction.png) Configuring the Browser Restriction policy. **Note** Browser Restriction controls Google Chrome, Mozilla Firefox, Naver Whale, Brave, Vivaldi, Coc Coc, Yandex, Ulaa, Microsoft Edge, Microsoft Edge (Legacy), and Internet Explorer. Unsupported browsers like Opera and UC Browser can be restricted indirectly — for example, allowing access only to Google Chrome effectively blocks Opera too, since every other browser is then restricted. Browser Restriction takes effect after the next asset scan when a new browser is installed. ## Related - [Browser Security Overview](https://www.manageengine.com/desktop-management-msp/help/browser-security/browser-overview.html) - [Policy Deployment](https://www.manageengine.com/desktop-management-msp/help/browser-security/policy-deployment.html) - [Browser Security FAQ](https://www.manageengine.com/desktop-management-msp/help/browser-security/browser-faq.html#restrictfaq)