[{"content":"","date":"2 October 2026","externalUrl":null,"permalink":"/tags/ai/","section":"Tags","summary":"","title":"AI","type":"tags"},{"content":"","date":"2 October 2026","externalUrl":null,"permalink":"/categories/ai-in-euc/","section":"Categories","summary":"","title":"AI in EUC","type":"categories"},{"content":"","date":"2 October 2026","externalUrl":null,"permalink":"/tags/azure/","section":"Tags","summary":"","title":"Azure","type":"tags"},{"content":"","date":"2 October 2026","externalUrl":null,"permalink":"/categories/","section":"Categories","summary":"","title":"Categories","type":"categories"},{"content":"","date":"2 October 2026","externalUrl":null,"permalink":"/tags/entra-id/","section":"Tags","summary":"","title":"Entra ID","type":"tags"},{"content":"","date":"2 October 2026","externalUrl":null,"permalink":"/tags/getting-started/","section":"Tags","summary":"","title":"Getting Started","type":"tags"},{"content":"Parallels Browser Isolation (PBI) is a cloud-hosted remote browser isolation service. Users open websites and web apps in an isolated browser that runs in the cloud, and you decide per user or group what they can do there: copy and paste, download, upload, print, and more. Setup is fast, but the identity part trips people up. This post walks through a clean first-time setup with Microsoft Entra ID as the identity provider.\nBefore you start # You\u0026rsquo;ll need:\nA PBI subscription or trial. The trial is free for 7 days and covers up to 15 users. An Entra ID account that can create app registrations and grant admin consent. A name for your environment prefix. Your tenant will live at https://\u0026lt;your-domain\u0026gt;.pbi.parallels.com. One decision to make up front is the data plane region. PBI asks for it first, and you can\u0026rsquo;t change it later. Pick the region closest to your users for the best latency.\nStep 1: Register PBI as an app in Entra ID # In the Azure portal, open Microsoft Entra ID → App registrations → New registration:\nGive it a clear name, for example Parallels Browser Isolation. Choose the supported account type that fits your organization. Under Redirect URI, select Web and add both URIs: https://\u0026lt;your-domain\u0026gt;.pbi.parallels.com/rbi/oidc/signin/callback https://\u0026lt;your-domain\u0026gt;.pbi.parallels.com/owner/test-idp The second URI is used by the Test Configuration button later on. If you forget it, the test fails even when everything else is right. Older documentation used redirect URIs without your domain prefix. Those are deprecated, so always use the tenant-specific ones.\nClick Register. Step 2: Create a client secret # Go to Certificates \u0026amp; secrets → New client secret, pick an expiry and click Add. Copy the Value column straight away, because Entra ID hides it once you leave the page.\nAdd the expiry date to your calendar. An expired client secret means nobody can sign in to PBI.\nStep 3: Configure the token claims # PBI identifies users and groups from the ID token, so the token needs the right claims.\nGo to Token configuration → Add groups claim and select the group types you want to send. Click Add optional claim, choose token type ID, select preferred_username, then click Add. Step 4: Grant API permissions # Under API permissions → Add a permission → Microsoft Graph → Delegated permissions, add Group.Read.All. Then click Grant admin consent for your tenant.\nStep 5: Collect the values # From the app\u0026rsquo;s Overview page, note the Application (client) ID. Under Endpoints, copy the OpenID Connect metadata document URL. It has this format:\nhttps://login.microsoftonline.com/\u0026lt;tenant-id\u0026gt;/v2.0/.well-known/openid-configuration Step 6: Configure the identity provider in PBI # Sign in to PBI, accept the Cloud Solution Agreement and set your region. Then open Configure Domain \u0026amp; IdP → IdP Configuration:\nField Value Domain configuration your environment prefix (https://\u0026lt;your-domain\u0026gt;.pbi.parallels.com) OpenID configuration URL the metadata document URL from step 5 Client ID the Application (client) ID Client secret the secret Value from step 2 Username claim name preferred_username Group claim name groups Click Test Configuration, then Save.\nNext, add your first administrators: enter users (UPN) and/or groups. They must match the IdP exactly. Then use Admin Sign In on the Access Admin Portal card to open the Management Portal.\nStep 7: Add users and groups # In the Management Portal, open User Management and add the users and groups who should use PBI. Again, names must match the IdP exactly. Adding them here doesn\u0026rsquo;t create anything in Entra ID; it only tells PBI who is allowed in.\nIf group-based access doesn\u0026rsquo;t work, decode a test ID token (Microsoft\u0026rsquo;s jwt.ms works well) and check what the groups claim actually contains. The value you add in PBI has to match what\u0026rsquo;s in the token.\nStep 8: Publish your first application # Under Applications → Add Application you can choose between two types:\nSecure browser: a full isolated browser instance with a start page. You can create several instances with different users and policies. Secure web application: one specific web app. Add any extra domains it needs, such as its SSO login pages, or it\u0026rsquo;ll break halfway through sign-in. Assign users and/or groups, and optionally apply policies.\nStep 9: Add a first policy # Under Policies → Add, define who the policy applies to: users, groups, active hours, or locations. Then choose the security controls. Useful ones for a first POC:\nDisable copy \u0026amp; paste from PBI and Disable downloads: the classic data-leakage controls, with downloads blockable per file type. Watermarking: a translucent overlay that deters screenshots. Block domains by category: covers 59 categories, with a trusted-domains list for exceptions. An end-user indicator such as a blue border, tab asterisk or toast notification, so users know they\u0026rsquo;re in an isolated session. Then attach the policy to your application. If users already have the application open, the new policy only applies after they close all of its tabs, wait about five seconds and reopen it.\nKey takeaways # Choose the data-plane region carefully, because you can\u0026rsquo;t change it later. Register both redirect URIs in Entra ID, including the test-idp one. The ID token needs a groups claim and the preferred_username optional claim, plus Group.Read.All with admin consent. Users, groups and admins in PBI must match the IdP exactly. Start with one web application and one policy (copy/paste, downloads, watermark), then expand. Sources # Parallels Browser Isolation Administrator\u0026rsquo;s Guide Configuring Parallels Browser Isolation Microsoft Entra OIDC Configuration User Management Applications Policies Parallels Browser Isolation licensing ","date":"2 October 2026","externalUrl":null,"permalink":"/posts/2026-10-02-getting-started-with-parallels-browser-isolation-entra-id/","section":"Posts","summary":"From empty tenant to first isolated app: region, Entra ID OIDC app registration, admins, users, an application and a first policy.","title":"Getting started with Parallels Browser Isolation and Microsoft Entra ID","type":"posts"},{"content":"","date":"2 October 2026","externalUrl":null,"permalink":"/tags/nutanix/","section":"Tags","summary":"","title":"Nutanix","type":"tags"},{"content":"","date":"2 October 2026","externalUrl":null,"permalink":"/tags/openid-connect/","section":"Tags","summary":"","title":"OpenID Connect","type":"tags"},{"content":"","date":"2 October 2026","externalUrl":null,"permalink":"/categories/parallels-browser-isolation/","section":"Categories","summary":"","title":"Parallels Browser Isolation","type":"categories"},{"content":"","date":"2 October 2026","externalUrl":null,"permalink":"/tags/parallels-browser-isolation/","section":"Tags","summary":"","title":"Parallels Browser Isolation","type":"tags"},{"content":"","date":"2 October 2026","externalUrl":null,"permalink":"/categories/parallels-ras/","section":"Categories","summary":"","title":"Parallels RAS","type":"categories"},{"content":"","date":"2 October 2026","externalUrl":null,"permalink":"/tags/parallels-ras/","section":"Tags","summary":"","title":"Parallels RAS","type":"tags"},{"content":"","date":"2 October 2026","externalUrl":null,"permalink":"/posts/","section":"Posts","summary":"","title":"Posts","type":"posts"},{"content":"Every week: one practical Parallels RAS article, one AI in EUC \u0026amp; security article and one Parallels Browser Isolation article — configuration walkthroughs, release highlights, troubleshooting tips and POC lessons from the field.\n","date":"2 October 2026","externalUrl":null,"permalink":"/","section":"RAS \u0026 Browser Isolation Notes","summary":"","title":"RAS \u0026 Browser Isolation Notes","type":"page"},{"content":"","date":"2 October 2026","externalUrl":null,"permalink":"/tags/ras-21.2/","section":"Tags","summary":"","title":"RAS 21.2","type":"tags"},{"content":"","date":"2 October 2026","externalUrl":null,"permalink":"/tags/release-notes/","section":"Tags","summary":"","title":"Release Notes","type":"tags"},{"content":"","date":"2 October 2026","externalUrl":null,"permalink":"/tags/secure-gateway/","section":"Tags","summary":"","title":"Secure Gateway","type":"tags"},{"content":"","date":"2 October 2026","externalUrl":null,"permalink":"/tags/","section":"Tags","summary":"","title":"Tags","type":"tags"},{"content":"Welcome! Starting this week, this blog publishes three articles every week:\nDay Topic Tuesday Parallels RAS — deployment, configuration, troubleshooting, new releases Wednesday AI in EUC \u0026amp; security — delivering and securing AI apps on virtual desktops and isolated browsers Thursday Parallels Browser Isolation — policies, IdP setup, Private Access, use cases Drafts are prepared with AI assistance from official Parallels sources and reviewed by me before they go live. See About \u0026amp; disclaimer for details.\nSubscribe via RSS to get new posts automatically.\n","date":"2 October 2026","externalUrl":null,"permalink":"/posts/welcome/","section":"Posts","summary":"What this blog covers and how the weekly articles are produced.","title":"Welcome: weekly Parallels RAS, AI and Browser Isolation articles","type":"posts"},{"content":"Parallels RAS 21.2 shipped on 23 June 2026, followed by 21.2 Update 1 in August. It\u0026rsquo;s a feature release rather than a hotfix: it brings new providers, more control at host-pool level, security hardening and a set of end-user improvements. Below is my take on what actually changes your day-to-day as an admin, and what I\u0026rsquo;d test first in a POC.\nWhere 21.2 sits in the RAS 21 timeline # RAS 21.0 arrived in November 2025, followed by 21.1 in February 2026 and 21.2 in June 2026. 21.2 is the current feature release. The Update 1 on top of it is mainly a stability release, with one critical fix you\u0026rsquo;ll want if you run Hyper-V clusters (more on that below).\nPlatform: more places to run your workloads # Nutanix Prism Central as a provider. You can now add Prism Central, not just individual Prism Element clusters. Parallels positions this as better multi-cluster and hybrid-cloud compatibility with the current Nutanix architecture. If your customer runs several Nutanix clusters, that\u0026rsquo;s one provider entry instead of many.\nThe Custom Provider Framework. This is the one I\u0026rsquo;m most excited about. It gives you a supported way to plug hypervisors that aren\u0026rsquo;t natively supported into RAS, while RAS keeps doing what it does best: brokering, host pools and application delivery. For POCs on \u0026ldquo;less common\u0026rdquo; platforms, this removes a big blocker.\nScale Computing HC3 9.6. Support for HC3 9.6 is added, and support for HC3 9.2 is removed. Check your customer\u0026rsquo;s HC3 version before upgrading RAS.\nAzure and Azure Virtual Desktop. Two additions here:\nTrusted Launch as a VM security type for Azure and AVD providers, which brings Secure Boot and virtual TPM to your session hosts. Azure Availability Zones, so you can pick the zones for your Azure and AVD session hosts. Together they make it a lot easier to meet the \u0026ldquo;secure by default, resilient by design\u0026rdquo; requirements that come up in almost every Azure security review.\nAdmin experience: more control per host pool # The change I expect to use the most is overriding settings at host-pool level:\nVM sizing and specifications can now be set per host pool instead of only per template. The Active Directory OU can be overridden per host pool too. That means one template can serve several host pools: for example a \u0026ldquo;standard\u0026rdquo; pool and a \u0026ldquo;power users\u0026rdquo; pool with bigger VMs, each landing in its own OU with its own GPOs. Fewer templates means less image maintenance.\nOther admin-side improvements:\nSessions in a \u0026ldquo;Down\u0026rdquo; state: you get clearer visibility, and you can configure how RAS handles them. Unresponsive sessions are a classic helpdesk ticket, so this is welcome. Quarantined printers: new visibility and management controls, which helps when you\u0026rsquo;re troubleshooting redirected printing. Cost Insights for AVD now supports custom time ranges, so you can report on a sprint, a month or a quarter. Configurable thresholds for failed Secure Gateway session notifications, so you only get alerted when it matters. Security: tighter Gateway and client controls # Granular access control for RAS Secure Gateways. You can now manage access to standard RAS sessions, the User Portal authentication pages, the Web API and the Connection Broker API independently. If a Gateway only needs to serve sessions, you can stop exposing the rest. That\u0026rsquo;s a quick win for any DMZ design review. Automatic client logout while sessions stay active. Users can be signed out of the Client or User Portal while their remote sessions keep running. That\u0026rsquo;s useful for shared devices and for stricter compliance policies. Crypto and runtime updates. OpenSSL moves to 3.5.6 and FIPS to 3.1.2 with FIPS 140-3 validation, and .NET moves to 10.0.7. User experience: the Web Client grows up # Local file access and multi-file transfer in the Web Client. Users can upload and download files between their device and remote applications, several files at once. Admins can also suppress the \u0026ldquo;Save As\u0026rdquo; prompts to streamline multi-file uploads. Experimental file-content caching for redirected drives, which improves save performance from a remote session with Parallels Client for Windows. It\u0026rsquo;s experimental, so try it on a pilot group first. macOS users get richer clipboard redirection (including images) in the macOS Client, and Command+C/V/A/X support in the User Portal. Linux Client and IGEL OS12 get extended USB redirection (including HID peripherals), and IGEL OS12 gets passthrough authentication. Clearer launch feedback in the Windows and Web clients, so users can see that an application is still opening. That means fewer double-clicks and duplicate sessions. 21.2 Update 1: install it if you run Hyper-V clusters # Update 1 fixes a critical issue where the VDI Provider Agent could stop responding when it manages Hyper-V clusters. It also adds a registry setting to disable application monitoring on VDI Guest Agents, and runtime input-locale propagation so keyboard language changes are redirected correctly.\nWhat I\u0026rsquo;d test first in a POC # Host-pool overrides: one template, two host pools with different VM sizes and OUs. Secure Gateway granular access: lock a Gateway down to sessions only, and confirm the User Portal still works through the Gateway that is meant to serve it. Web Client file transfer: it\u0026rsquo;s the feature end users notice first. Trusted Launch on Azure/AVD, if the customer has a security baseline that requires it. As always: read the full release notes before upgrading production, and check the supported versions of your hypervisors and clients.\nKey takeaways # 21.2 adds Nutanix Prism Central, the Custom Provider Framework, Scale HC3 9.6 (9.2 dropped), and Trusted Launch plus Availability Zones for Azure/AVD. Host-pool-level overrides for VM sizing and AD OU cut down on template sprawl. Secure Gateways can now expose only the services they need. The Web Client gets local file access and multi-file transfer. Apply 21.2 Update 1 if you manage Hyper-V clusters. Sources # Parallels Remote Application Server v21 Release Notes (KB 131037) What\u0026rsquo;s New in Parallels RAS 21.2 Parallels RAS 21 release history Parallels RAS 21 Administrator\u0026rsquo;s Guide — What\u0026rsquo;s new ","date":"2 October 2026","externalUrl":null,"permalink":"/posts/2026-10-02-whats-new-in-parallels-ras-21-2/","section":"Posts","summary":"A practical walk through Parallels RAS 21.2 and 21.2 Update 1: new providers, host pool overrides, Gateway hardening and Web Client file transfer.","title":"What's new in Parallels RAS 21.2: the features that matter for admins","type":"posts"},{"content":"","date":"2 October 2026","externalUrl":null,"permalink":"/tags/zero-trust/","section":"Tags","summary":"","title":"Zero Trust","type":"tags"},{"content":"This is a personal blog by a Senior Sales Engineer working with Parallels RAS and Parallels Browser Isolation.\nDisclaimer # This is not an official Parallels website. Opinions are my own and do not represent Parallels. Parallels® and the Parallels logo are trademarks of Parallels International GmbH. Always check the official documentation at docs.parallels.com and the Parallels Knowledge Base before changing a production environment. How articles are made # Articles are drafted with AI assistance (Claude) from official Parallels documentation, release notes and knowledge-base articles. Every draft is reviewed, corrected and approved by me before it is published. Each article lists its sources at the bottom.\n","externalUrl":null,"permalink":"/about/","section":"RAS \u0026 Browser Isolation Notes","summary":"","title":"About \u0026 disclaimer","type":"page"},{"content":"","externalUrl":null,"permalink":"/authors/","section":"Authors","summary":"","title":"Authors","type":"authors"},{"content":"","externalUrl":null,"permalink":"/series/","section":"Series","summary":"","title":"Series","type":"series"}]