Proofpoint ZenWeb Browser Extension for the Agent
Proofpoint ZenWeb is an optional module that does not require an additional license. It is built as a Chromium-based browser extension that utilizes the Chrome API.
The ZenWeb browser extension enhances the existing endpoint data leak prevention capabilities of the Proofpoint Agent. As an add-on to the agent, it improves the user experience and increases the accuracy of web upload blocking. The extension supports the agent by performing rule assessment and content scanning, and sending the resulting data to the customer's tenant.
Without ZenWeb, the Proofpoint Agent first attempts to extract the URL of web activity using Web Accessibility. If Web Accessibility is unavailable, the agent extracts the URL directly from the browser's address bar instead. This method is less accurate and may capture a partial URL if it is still being typed, rather than the actual URL that was opened — which can also introduce latency in the browser experience.
When ZenWeb is enabled for a supported activity, and the extension is active and communicating with the agent, the agent queries the extension for browser activity context instead of relying on Web Accessibility. If the agent is unable to communicate with the extension, it falls back to Web Accessibility or other agent-side collection methods.
Installation
After the initial download, the Proofpoint ZenWeb is automatically updated to the latest version.
You can install the Proofpoint ZenWeb on a single endpoint or deploy on multiple endpoints (GPO).
For instructions to install Proofpoint ZenWeb on a single endpoint and on multiple endpoints, see Proofpoint ZenWeb Deployment and Installation.
Incognito Mode
Proofpoint ZenWeb cannot work in Incognito mode without explicit permission by the user. To ensure that Incognito browsing does not become an unmonitored exit point for Proofpoint's ITM/DLP agent, do the following:
-
Force users to allow ZenWeb on Microsoft Edge’s InPrivate browsing by using MandatoryExtensionsForInPrivateNavigation MDM managed key (https://learn.microsoft.com/en-us/deployedge/microsoft-edge-browser-policies/mandatoryextensionsforinprivatenavigation).
-
Block users from using Incognito mode, on non-Microsoft Edge browsers, based on policy set by organization’s IT.
Enabling Proofpoint ZenWeb and Activities
You must enable the Proofpoint ZenWeb Browser Extension from the Agent Realm. To enable, from the Administration application, select Endpoints > Agent Realms. In the Advanced Settings of the Agent Realm, in the Browser Extension area, turn on Enable Browser Extension.
Next, enable the specific activities you want to use with the Browser Extension. If an activity is not enabled, the Agent will run without using the browser.
Enabling an activity for the Browser Extension does not mean the agent stops supporting that activity entirely. The agent continues to support the activity through its standard collection methods (such as Web Accessibility) when ZenWeb is unavailable or does not apply.
ZenWeb is used only for activities that are both enabled and supported for the installed agent version, browser, and platform. If an activity is not supported under the current configuration, the agent relies on its existing collection methods instead.
Proofpoint ZenWeb Supported Activities
Most of the activities are supported for Agent or Agent and ZenWeb. Deploying the Agent with ZenWeb enhances the capabilities.
You must toggle on the relevant activity in the Agent Realm
Detect/Prevent Text Submit in Websites (GenAI) is supported only with the Agent and ZenWeb. All other activities are supported for Agent only or Agent and ZenWeb.
Windows Agent
| Activity | Supported Agent and ZenWeb deployments | ZenWeb Supported Browsers | Agent Minimum versions for ZenWeb Compatibility |
|---|---|---|---|
| Detect File Upload Activity |
Agent only or Agent + ZenWeb |
Google Chrome Microsoft Edge Island Enterprise Opera |
3.6.0 |
| Prevent File Upload Activity |
Agent only or Agent + ZenWeb |
Google Chrome Microsoft Edge Island Enterprise Opera |
4.3.3 |
| Detect Web Browsing Activity |
Agent only or Agent + ZenWeb |
Google Chrome Microsoft Edge Island Enterprise Opera |
3.6 |
|
Detect/Prevent Text Submit in Websites (GenAI) |
Agent + ZenWeb |
Google Chrome Microsoft Edge Island Enterprise Opera |
3.6 |
| Differentiate Between Corporate and Personal GenAI Activities |
Agent only or Agent + ZenWeb |
Google Chrome Microsoft Edge Island Enterprise Opera |
5.0 |
Mac Agent
| Activity | Supported Agent and ZenWeb deployments | ZenWeb Supported Browsers | Agent Minimum versions for ZenWeb Compatibility |
|---|---|---|---|
| Detect File Upload Activity |
Agent only or Agent + ZenWeb |
Google Chrome Microsoft Edge Firefox |
4.2 |
| Detect Web Browsing Activity |
Agent only or Agent + ZenWeb |
Google Chrome Microsoft Edge Firefox |
4.2 |
|
Detect/Prevent Text Submit in Websites (GenAI) |
Agent + ZenWeb
|
Google Chrome Microsoft Edge Firefox |
4.4 |
| Detect Download Activity |
Agent only or Agent + ZenWeb |
Google Chrome Microsoft Edge Firefox |
4.2 |
| Differentiate Between Corporate and Personal GenAI Activities |
Agent only or Agent + ZenWeb |
Google Chrome Microsoft Edge Firefox |
5.0 |
| Prevent File Upload Activity |
Agent only or Agent + ZenWeb |
Google Chrome Microsoft Edge Firefox |
4.2 |
File Upload is limited to 1000 files.
Supported GenAI Sites
-
ChatGPT by OpenAI: ChatGPT
-
Gemini by Google: Google Gemini
-
Copilot by Microsoft:
- Microsoft CoPilot
-
GenAI prompt submit detection and prevention is not supported for Microsoft CoPilot when using Microsoft Edge Browser” replace Microsoft CoPilot with this specific URL: Microsoft Copilot: Your AI Companion.
- m365.cloud.microsoft/chat/
- https://www.copilot.com/
-
Claude (by Antrophic): Claude
-
Deep Seek Chat: chat.deepseek.com/sign_in
-
Perplexity: https://www.perplexity.ai/
-
character.ai: https://character.ai/
-
AnonChatGPT: https://anonchatgpt.com/
-
YouChat: https://you.com/
-
Grok: https://grok.com/
-
Mistral AI: https://chat.mistral.ai/chat
-
Liner: https://app.liner.com/
-
Quillbot:
Paraphrasing Tool (Ad-Free and No Sign-up Required) - QuillBot AI
-
Genspark: Genspark - The All-in-One AI Workspace