Skip to content
CortexDocs
Defender · Browser sync

Set up browser sync

Enable browser routing, verify certificate trust, and recover or remove browser sync.

Browser sync
  • Browser syncControl supported web capture
  • Certificate trustComplete operating-system approval
  • Browser healthCheck routing and trust separately

Browser sync captures activity from supported AI websites. It requires both browser routing and trust in Defender's local certificate. Command-line connections have their own setup.

Enable browser sync

  1. Sign in to Defender, then open Home → Browser sync.
  2. When routing is off, select Turn on routing. Follow the displayed setup action, including Install certificate when trust is required.
  3. Approve the operating-system prompt if your device policy allows it.
  4. Restart the browser when requested, then select Check health.
  5. Enable the intended web app on Home, send a new prompt there, and verify the matching activity in Atlas.
Browser sync, routing and certificate checksManage devices in Cortex

Use the browser and operating-system combination listed in Supported AI tools. If a managed policy blocks routing or trust, ask IT to resolve it. Enabled routing alone does not prove the certificate or browser relay is working.

Read the health checks

Browser routing, Certificate trust, and Browser relay describe separate checks. Follow the recovery action next to the failing check, then select Check health again. Not checked or unavailable does not mean the check passed.

If certificate trust is required, select Install certificate and complete approval before retrying. If Defender asks for certificate regeneration or a browser restart, follow that specific action. Do not bypass browser certificate warnings to continue a test.

Set up browser sync during onboardingManage devices in Cortex

Connected and locally observed browser activity still require a matching record in Atlas to establish workspace delivery. See Verify capture and sync.

Turn off browser sync

Under Danger zone → Browser routing, select Turn off routing and complete the confirmation. This disables browser routing; certificate trust remains installed, and command-line sync keeps working. Follow any browser restart instruction and check direct access to the provider.

Remove the certificate

  1. Open Home → Browser sync.
  2. Scroll to Danger zone → Browser certificate.
  3. Select Remove certificate and read the removal confirmation.
  4. Complete the operating-system approval and any browser restart requested.
Browser routing and certificate controls in Danger zoneManage devices in Cortex

Removing trust prevents browser sync until setup is completed again. Use your organization's approved device-removal procedure when uninstalling Defender; see Offboard or replace a device.

Was this helpful?