Parallels Browser Isolation (PBI) is a cloud-hosted remote browser isolation service. Users open websites and web apps in an isolated browser that runs in the cloud, and you decide per user or group what they can do there: copy and paste, download, upload, print, and more. Setup is fast, but the identity part trips people up. This post walks through a clean first-time setup with Microsoft Entra ID as the identity provider.
Before you start#
You’ll need:
- A PBI subscription or trial. The trial is free for 7 days and covers up to 15 users.
- An Entra ID account that can create app registrations and grant admin consent.
- A name for your environment prefix. Your tenant will live at
https://<your-domain>.pbi.parallels.com.
One decision to make up front is the data plane region. PBI asks for it first, and you can’t change it later. Pick the region closest to your users for the best latency.
Step 1: Register PBI as an app in Entra ID#
In the Azure portal, open Microsoft Entra ID → App registrations → New registration:
- Give it a clear name, for example
Parallels Browser Isolation. - Choose the supported account type that fits your organization.
- Under Redirect URI, select Web and add both URIs:
https://<your-domain>.pbi.parallels.com/rbi/oidc/signin/callback
https://<your-domain>.pbi.parallels.com/owner/test-idpThe second URI is used by the Test Configuration button later on. If you forget it, the test fails even when everything else is right. Older documentation used redirect URIs without your domain prefix. Those are deprecated, so always use the tenant-specific ones.
- Click Register.
Step 2: Create a client secret#
Go to Certificates & secrets → New client secret, pick an expiry and click Add. Copy the Value column straight away, because Entra ID hides it once you leave the page.
Add the expiry date to your calendar. An expired client secret means nobody can sign in to PBI.
Step 3: Configure the token claims#
PBI identifies users and groups from the ID token, so the token needs the right claims.
- Go to Token configuration → Add groups claim and select the group types you want to send.
- Click Add optional claim, choose token type ID, select
preferred_username, then click Add.
Step 4: Grant API permissions#
Under API permissions → Add a permission → Microsoft Graph → Delegated permissions, add
Group.Read.All. Then click Grant admin consent for your tenant.
Step 5: Collect the values#
From the app’s Overview page, note the Application (client) ID. Under Endpoints, copy the OpenID Connect metadata document URL. It has this format:
https://login.microsoftonline.com/<tenant-id>/v2.0/.well-known/openid-configurationStep 6: Configure the identity provider in PBI#
Sign in to PBI, accept the Cloud Solution Agreement and set your region. Then open Configure Domain & IdP → IdP Configuration:
| Field | Value |
|---|---|
| Domain configuration | your environment prefix (https://<your-domain>.pbi.parallels.com) |
| OpenID configuration URL | the metadata document URL from step 5 |
| Client ID | the Application (client) ID |
| Client secret | the secret Value from step 2 |
| Username claim name | preferred_username |
| Group claim name | groups |
Click Test Configuration, then Save.
Next, add your first administrators: enter users (UPN) and/or groups. They must match the IdP exactly. Then use Admin Sign In on the Access Admin Portal card to open the Management Portal.
Step 7: Add users and groups#
In the Management Portal, open User Management and add the users and groups who should use PBI. Again, names must match the IdP exactly. Adding them here doesn’t create anything in Entra ID; it only tells PBI who is allowed in.
If group-based access doesn’t work, decode a test ID token (Microsoft’s jwt.ms works well) and
check what the groups claim actually contains. The value you add in PBI has to match what’s in
the token.
Step 8: Publish your first application#
Under Applications → Add Application you can choose between two types:
- Secure browser: a full isolated browser instance with a start page. You can create several instances with different users and policies.
- Secure web application: one specific web app. Add any extra domains it needs, such as its SSO login pages, or it’ll break halfway through sign-in.
Assign users and/or groups, and optionally apply policies.
Step 9: Add a first policy#
Under Policies → Add, define who the policy applies to: users, groups, active hours, or locations. Then choose the security controls. Useful ones for a first POC:
- Disable copy & paste from PBI and Disable downloads: the classic data-leakage controls, with downloads blockable per file type.
- Watermarking: a translucent overlay that deters screenshots.
- Block domains by category: covers 59 categories, with a trusted-domains list for exceptions.
- An end-user indicator such as a blue border, tab asterisk or toast notification, so users know they’re in an isolated session.
Then attach the policy to your application. If users already have the application open, the new policy only applies after they close all of its tabs, wait about five seconds and reopen it.
Key takeaways#
- Choose the data-plane region carefully, because you can’t change it later.
- Register both redirect URIs in Entra ID, including the
test-idpone. - The ID token needs a groups claim and the
preferred_usernameoptional claim, plusGroup.Read.Allwith admin consent. - Users, groups and admins in PBI must match the IdP exactly.
- Start with one web application and one policy (copy/paste, downloads, watermark), then expand.