Launching External Applications
Focus
Focus
Prisma Browser

Launching External Applications

Table of Contents

Launching External Applications

Control whether links in the Prisma Browser can launch external desktop applications.
Prisma Browser DesktopPrisma Browser ExtensionPrisma Browser for Mobile
Full supportNo supportNo support
This control applies to desktop devices only. Scope rules that use this control to desktop devices. To control external application launching on mobile devices, see Open Links in External Apps.
The Launching External Applications control determines whether links in the Prisma Browser can start external desktop applications such as Zoom or Slack. External applications operate outside the Prisma Browser, where browser security controls - data leak prevention, URL filtering, and threat prevention - cannot inspect or restrict the data a user shares. This control defines a single default behavior for every external application, and then overrides that default for individual applications.
The control has two parts. The global setting defines the default behavior for all external applications. The specific application settings define exceptions to that default, each identified by one or more protocol schemes. The Prisma Browser evaluates the specific application settings first, and falls back to the global setting for any scheme that is not listed.
To set the Launching External Applications control:
  1. From Strata Cloud Manager, select ConfigurationPolicyControl SetsBrowser Security
  2. Select Launching External Applications.
  3. Select one of the following options:
    • User can decide - Users will see a prompt before launching external applications. This is the default option.
    • Never - All external applications will not launch. The Prisma Browser displays a notification to the user and the page remains available.
    • Always - External applications launch automatically without prompting users.
  4. Under Define launch settings for specific applications, override the global setting for individual applications.
    1. To configure a predefined application, select Zoom or Slack from the applications list. The Prisma Browser populates the protocol schemes for that application.
    2. To configure any other application, select Add custom application settings and specify the Application Name.
    3. In Schemes, review the populated schemes, remove any that do not apply, and add any additional schemes the application uses. At least one scheme is required.
    4. In Launch Settings, select Always, Never, or User can decide for this application. No value is selected by default.
    5. Click Add. The application appears in the list with a desktop platform badge and its launch setting. Use the edit and delete icons on the application entry to change or remove it. An application that is removed from the list reverts to the global setting.
  5. Click Set.
    The setting applies after the next policy synchronization.
Scheme Formats
A scheme identifies the external application that handles a link. Specify schemes in one of the following formats:
FormatExampleMatches
Scheme with separatorzoom://Any link that begins with zoom://
Bare schemeglobalprotectcallbackAny link that begins with globalprotectcallback:, including links that do not use the :// separator
Scheme with domainzoom://us.zoom.com/Any link that begins with zoom://us.zoom.com/
Note the following when you specify schemes:
  • The Prisma Browser matches schemes as a prefix of the full link and ignores letter case. A scheme with a domain restricts the setting to that destination, so zoom://us.zoom.com/ applies to zoom://us.zoom.com/j/123 but not to zoom://eu.zoom.com/j/456.
  • A scheme that specifies a domain must end with a forward slash and cannot include a path.
  • Schemes cannot contain spaces or backslashes.
  • A scheme cannot be assigned to more than one application. A broad scheme such as zoom:// conflicts with any scheme that uses the same base scheme, including zoom://us.zoom.com/.
The predefined applications populate the following schemes, all of which can be edited:
ApplicationSchemes
Zoomzoom://, zoomus://, zoommtg://
Slackslack://