Admin guide
This guide is for administrators of Cloud Certainty Secure Browser. You manage everything from the
Admin menu of the portal (the PortalUrl of your stack). Every change you make there is
recorded in the audit log.
Roles
There are two roles:
| Role | Can |
|---|---|
| User | Start, use and end their own sessions, and see their recent sessions. |
| Admin | Everything a user can do, plus manage profiles, assignments, roles, settings, active sessions and the audit log. |
- Everyone who can sign in and has no role entry is a User.
- Grant Admin under Admin → Roles, to a single person by email or to a group from your identity provider. Type the group name exactly as your identity provider sends it (with IAM Identity Center, the group ID).
- The first admin is the
BootstrapAdminEmailfrom the stack parameters. The first person who signs in with that email stays an admin permanently and can't be removed in the console, so you can't lock yourself out. Still, grant Admin to at least one more person or group. - You can't remove your own Admin role.
To hand the first-admin role to someone else, update the stack with a new BootstrapAdminEmail.
The next sign-in with that email takes over.
Policy profiles
A profile is the set of rules that applies to a session: what may cross between the remote browser and the user's device, which websites are reachable, and how long a session may last.
The stack starts with a restrictive default profile: no clipboard, no file transfer, no printing,
a 15-minute idle timeout, a 5-minute disconnect timeout and an 8-hour maximum session. Choose
New profile to create one for a team.
| Control | What it does |
|---|---|
| Clipboard: copy out | Users can copy text from the remote browser to their own computer. The viewer shows a Copy remote text button; the text reaches the user's clipboard only when they click it. |
| Clipboard: paste in | Users can paste text from their computer into the remote browser. |
| File upload | Users can upload files from their computer. Uploaded files appear in the remote browser's Uploads folder. |
| File download | Files downloaded in the remote browser are sent to the user's computer. Dangerous file types are always blocked. When off, the remote browser blocks downloads entirely, including Save page as. |
| Maximum file size | Size limit for uploads, downloads and prints (1 to 2,048 MB). |
| Printing in the remote browser produces a PDF that is saved on the user's computer. Allowing print does not allow other downloads. | |
| URL filter | Off, an allow list (block every site except those listed) or a block list. Patterns like example.com or https://*.corp.example are supported. Local files are always blocked. |
| Homepage and bookmarks | The page each session opens on, and bookmarks shown on the bookmark bar. |
| Developer tools, extensions, incognito | Allow or block each one. Blocking developer tools also blocks view-source: and javascript: addresses. |
| JavaScript JIT and WebAssembly | Off by default for extra protection against malicious websites. Pages run a little slower and sites that need WebAssembly don't work. Turn it on for profiles whose users need such sites. |
| Idle timeout | The session ends after this many minutes without keyboard or mouse input. Users get a 60-second warning with a Stay connected button. |
| Disconnect timeout | The session ends after this many minutes with nobody viewing it, for example after the user closes the tab. |
| Maximum session length | A hard limit, up to 24 hours. |
| Chrome policy overrides | Advanced: extra Chrome enterprise policies (opens in a new tab) as JSON. Settings the product manages itself are rejected, and the editor lists them. |
A session keeps the profile it started with. Changes apply to new sessions, not to running ones.
Assignments
Under Admin → Assignments, map users and groups to profiles. A user's profile is chosen in this order:
- a profile assigned to the user (by email);
- otherwise, of the profiles assigned to the user's groups, the one with the lowest priority number;
- otherwise, the default profile set in Settings.
A profile can't be deleted while it is assigned or set as the default.
Settings
| Setting | What it does |
|---|---|
| IP access | When the list has entries, the portal works only from those IP ranges (CIDRs). Everyone else is refused. The console won't save a list that would lock out your own current IP. Behind a corporate proxy, enter the proxy's public egress IP. |
| Maximum concurrent sessions | How many sessions may run at the same time across all users. |
| Maximum sessions per user | Usually 1. |
| Default profile | The profile used when no assignment matches. |
Active sessions
Admin → Sessions lists every running session with its user, start time, source IP and profile. Choose Terminate to end a session immediately; the user sees "An administrator ended the session". Sessions started before an upgrade are marked as running the older version until they end.
Audit log
Admin → Audit shows events by day:
- sessions started, ended, terminated or refused (for example because of the IP list or a limit);
- every configuration change, with the admin who made it;
- file uploads and downloads, with name, size and a fingerprint of the content (never the content itself);
- clipboard transfers (that they happened, never the text);
- new release notices.
The same events are written to Amazon CloudWatch Logs in your account, so you can forward them to your SIEM. Audit history stays until you delete it.
Updates and upgrading
Admin → About & updates shows the release you run and the latest release.
When a newer release
is out, a banner appears across the admin console. It is marked Security for security
releases and warns you when your release is no longer supported. Releases can also be announced by
email (the UpdateNotificationEmail stack parameter) or in Slack or Microsoft Teams through the
stack's update SNS topic.
Upgrading is done by whoever manages the CloudFormation stack, not in the console:
- Read the release notes.
- In the CloudFormation console, select the stack and choose Update → Replace current
template. Enter the new release's template URL:
https://cloudcertainty-secure-browser-us-east-1.s3.us-east-1.amazonaws.com/<version>/main.yaml - Keep every parameter value as it is. New parameters appear with safe defaults.
- Acknowledge the IAM capabilities and submit. The update takes about 5 to 10 minutes.
With Terraform, raise the module version and apply.
Running sessions are not interrupted; new sessions use the new release. Users with the portal open get the new version when they reload the page. To roll back, update the stack again with the previous release's template URL. We support the latest release and the one before it, so upgrade promptly, especially for security releases.
Coming from Amazon WorkSpaces Secure Browser
| WorkSpaces Secure Browser | Cloud Certainty Secure Browser |
|---|---|
| Web portal with IAM Identity Center or SAML 2.0 | Portal with IAM Identity Center, any SAML 2.0 or OIDC provider, or Cognito users |
| User settings: copy, paste, upload, download, print | Profile controls, plus a maximum file size |
| Idle, disconnect and maximum session timeouts | Profile timeouts |
| Browser policy (URL filtering, bookmarks, homepage) | Profile URL filter, homepage, bookmarks, plus Chrome policy overrides |
| IP access settings | Settings → IP access |
| Network settings (VPC, subnets) | Stack parameters VpcId and TaskSubnetIds |
| User access logging | Audit log and CloudWatch Logs, plus AWS CloudTrail |
| Per-group settings | Profiles assigned per user or group, with priorities |
| Customer managed KMS key | Stack parameter KmsKeyArn |
| Watermarking | Not yet available |
| Audio, webcam, microphone | Not supported |
Our migration service maps your existing portal settings to profiles and plans the cut-over with you.
Something unclear or missing? Email [email protected].