← ALL DOCS
DOCS · ADMINISTRATORS

Admin guide

This guide is for administrators of Cloud Certainty Secure Browser. You manage everything from the Admin menu of the portal (the PortalUrl of your stack). Every change you make there is recorded in the audit log.

Roles

There are two roles:

RoleCan
UserStart, use and end their own sessions, and see their recent sessions.
AdminEverything a user can do, plus manage profiles, assignments, roles, settings, active sessions and the audit log.
  • Everyone who can sign in and has no role entry is a User.
  • Grant Admin under Admin → Roles, to a single person by email or to a group from your identity provider. Type the group name exactly as your identity provider sends it (with IAM Identity Center, the group ID).
  • The first admin is the BootstrapAdminEmail from the stack parameters. The first person who signs in with that email stays an admin permanently and can't be removed in the console, so you can't lock yourself out. Still, grant Admin to at least one more person or group.
  • You can't remove your own Admin role.

To hand the first-admin role to someone else, update the stack with a new BootstrapAdminEmail. The next sign-in with that email takes over.

Policy profiles

A profile is the set of rules that applies to a session: what may cross between the remote browser and the user's device, which websites are reachable, and how long a session may last.

The stack starts with a restrictive default profile: no clipboard, no file transfer, no printing, a 15-minute idle timeout, a 5-minute disconnect timeout and an 8-hour maximum session. Choose New profile to create one for a team.

ControlWhat it does
Clipboard: copy outUsers can copy text from the remote browser to their own computer. The viewer shows a Copy remote text button; the text reaches the user's clipboard only when they click it.
Clipboard: paste inUsers can paste text from their computer into the remote browser.
File uploadUsers can upload files from their computer. Uploaded files appear in the remote browser's Uploads folder.
File downloadFiles downloaded in the remote browser are sent to the user's computer. Dangerous file types are always blocked. When off, the remote browser blocks downloads entirely, including Save page as.
Maximum file sizeSize limit for uploads, downloads and prints (1 to 2,048 MB).
PrintPrinting in the remote browser produces a PDF that is saved on the user's computer. Allowing print does not allow other downloads.
URL filterOff, an allow list (block every site except those listed) or a block list. Patterns like example.com or https://*.corp.example are supported. Local files are always blocked.
Homepage and bookmarksThe page each session opens on, and bookmarks shown on the bookmark bar.
Developer tools, extensions, incognitoAllow or block each one. Blocking developer tools also blocks view-source: and javascript: addresses.
JavaScript JIT and WebAssemblyOff by default for extra protection against malicious websites. Pages run a little slower and sites that need WebAssembly don't work. Turn it on for profiles whose users need such sites.
Idle timeoutThe session ends after this many minutes without keyboard or mouse input. Users get a 60-second warning with a Stay connected button.
Disconnect timeoutThe session ends after this many minutes with nobody viewing it, for example after the user closes the tab.
Maximum session lengthA hard limit, up to 24 hours.
Chrome policy overridesAdvanced: extra Chrome enterprise policies (opens in a new tab) as JSON. Settings the product manages itself are rejected, and the editor lists them.

A session keeps the profile it started with. Changes apply to new sessions, not to running ones.

Assignments

Under Admin → Assignments, map users and groups to profiles. A user's profile is chosen in this order:

  1. a profile assigned to the user (by email);
  2. otherwise, of the profiles assigned to the user's groups, the one with the lowest priority number;
  3. otherwise, the default profile set in Settings.

A profile can't be deleted while it is assigned or set as the default.

Settings

SettingWhat it does
IP accessWhen the list has entries, the portal works only from those IP ranges (CIDRs). Everyone else is refused. The console won't save a list that would lock out your own current IP. Behind a corporate proxy, enter the proxy's public egress IP.
Maximum concurrent sessionsHow many sessions may run at the same time across all users.
Maximum sessions per userUsually 1.
Default profileThe profile used when no assignment matches.

Active sessions

Admin → Sessions lists every running session with its user, start time, source IP and profile. Choose Terminate to end a session immediately; the user sees "An administrator ended the session". Sessions started before an upgrade are marked as running the older version until they end.

Audit log

Admin → Audit shows events by day:

  • sessions started, ended, terminated or refused (for example because of the IP list or a limit);
  • every configuration change, with the admin who made it;
  • file uploads and downloads, with name, size and a fingerprint of the content (never the content itself);
  • clipboard transfers (that they happened, never the text);
  • new release notices.

The same events are written to Amazon CloudWatch Logs in your account, so you can forward them to your SIEM. Audit history stays until you delete it.

Updates and upgrading

Admin → About & updates shows the release you run and the latest release. When a newer release is out, a banner appears across the admin console. It is marked Security for security releases and warns you when your release is no longer supported. Releases can also be announced by email (the UpdateNotificationEmail stack parameter) or in Slack or Microsoft Teams through the stack's update SNS topic.

Upgrading is done by whoever manages the CloudFormation stack, not in the console:

  1. Read the release notes.
  2. In the CloudFormation console, select the stack and choose Update → Replace current template. Enter the new release's template URL: https://cloudcertainty-secure-browser-us-east-1.s3.us-east-1.amazonaws.com/<version>/main.yaml
  3. Keep every parameter value as it is. New parameters appear with safe defaults.
  4. Acknowledge the IAM capabilities and submit. The update takes about 5 to 10 minutes.

With Terraform, raise the module version and apply.

Running sessions are not interrupted; new sessions use the new release. Users with the portal open get the new version when they reload the page. To roll back, update the stack again with the previous release's template URL. We support the latest release and the one before it, so upgrade promptly, especially for security releases.

Coming from Amazon WorkSpaces Secure Browser

WorkSpaces Secure BrowserCloud Certainty Secure Browser
Web portal with IAM Identity Center or SAML 2.0Portal with IAM Identity Center, any SAML 2.0 or OIDC provider, or Cognito users
User settings: copy, paste, upload, download, printProfile controls, plus a maximum file size
Idle, disconnect and maximum session timeoutsProfile timeouts
Browser policy (URL filtering, bookmarks, homepage)Profile URL filter, homepage, bookmarks, plus Chrome policy overrides
IP access settingsSettings → IP access
Network settings (VPC, subnets)Stack parameters VpcId and TaskSubnetIds
User access loggingAudit log and CloudWatch Logs, plus AWS CloudTrail
Per-group settingsProfiles assigned per user or group, with priorities
Customer managed KMS keyStack parameter KmsKeyArn
WatermarkingNot yet available
Audio, webcam, microphoneNot supported

Our migration service maps your existing portal settings to profiles and plans the cut-over with you.

Something unclear or missing? Email [email protected].

Tell us what you have. We'll make it better and cheaper.

Send a short description of your current setup. We will tell you what we would improve, what it would cost, and where the savings are. A considered reply from an engineer, not a sales sequence.

TELL US ABOUT YOUR SETUP →