Stable
Browser extension user guide
Private-app-only mode, workspace switching, downloads, sign out and common states.
Steps
Follow these in order.
- 01Install (Chrome, Firefox, Opera, Edge)Get the build for your browser from Downloads and add it; verify the signature.
- 02Sign in and pick a workspaceSign in to BusinessProxy and select the workspace you operate in.
- 03Choose a routing modePrivate apps only (default), work scope, or proxy-all. Personal traffic stays direct.
- 04Open a private app by its internal namePublished browser hosts can be internal names that do not exist in public DNS; they work only while the extension has an active BusinessProxy route.
- 05Route work domains through exit countriesAdd a work domain first, then add an egress rule that selects the exit location for that domain.
- 06Connect, disconnect and session statesWhat each status means and how recovery works after a stalled connect/disconnect.
- 07Permissions and what is routedWhy each permission exists; the gateway never inspects HTTPS page content on the browser path.
Reference
Implementation details for setup and review.
- Private apps only: only published private-app browser hosts use BusinessProxy.
- Work sites and private apps: policy work domains and published private apps use BusinessProxy; other Chrome traffic stays outside the managed path.
- Proxy all Chrome traffic: browser traffic uses BusinessProxy except local, service, update and explicit bypass entries.
- A regional rule can send a matching destination through a selected exit location, bypass that location or block the destination.
- When the extension is connected, a matching published browser host is routed through the extension proxy or opened through the managed app address before the browser reaches a normal DNS failure.
- When the extension is disconnected, BusinessProxy does not control the user device DNS. If that hostname is not resolvable on the user network, it will not open. If the customer network already resolves it locally, the browser may reach whatever that local DNS points to.
- This is not a wildcard proxy for arbitrary unknown domains. The hostname must be listed as a published browser host for an app the user can access.
- The connector still needs to reach the configured internal upstream from inside the customer network. The external user does not need public DNS for the browser host; the connector needs DNS or routing for the upstream it actually opens.
- Open the policy routing block and select Work sites and private apps, or Proxy all Chrome traffic.
- Add the destination to Work domains, for example crm.example.com or *.support.example.com.
- Open the regional routing block, add a rule for the same domain, choose Route through egress and select the exit location, for example US or RU.
- If the Work-domain egress shortcut is shown, select the exit location there and create the rule without retyping the domain.
- Save the policy. New browser sessions use the saved routing snapshot.
Routing mode: Work sites and private apps
Work domains:
- crm.example.com
- *.support.example.com
Regional routing rules:
- crm.example.com and subdomains -> US exit location
- support.example.com and subdomains -> RU exit location- If no regional rule matches in work-scope mode, only Work domains and published private-app browser hosts use BusinessProxy.
- If a domain uses BusinessProxy without a matching regional rule, it uses the workspace or policy default exit country according to the current settings.
- Changing the default exit country, available exit locations or regional routing can be limited by the plan and by platform-admin settings.