Fix browser isolation for Blify (Mimecast, Zscaler, Proofpoint...)
Blify is accessed through the web (app.blify.co) and natively inside Microsoft Teams, Slack and WhatsApp. If Blify opens in an isolated window with a countdown timer, or if sign-in keeps looping, your security tool is routing Blify to browser isolation (Browser Isolation). This article explains how to fix it in a few minutes.
Symptoms
You are affected if your users notice any of the following:
- The Blify page opens in a remote, isolated session: isolation banner, countdown timer, "End Session" button.
- The isolated session expires after a few minutes and interrupts their work.
- Sign-in via "Continue with Microsoft" or "Continue with Google" fails or loops.
Why this happens
Browser isolation is triggered when a domain is not yet categorized in your security tool's database. Because blify.co is a recently launched domain, it is treated as unknown and routed to an isolated session as a precaution.
Domains to allow
Allow these domains and exclude them from browser isolation:
Domain | Role |
|---|---|
Root domain | |
Web application used by learners | |
| All subdomains (recommended, covers current and future ones) |
For sign-in to complete, these identity provider domains must also stay out of isolation (they are usually already known to your tool):
login.microsoftonline.comandlogin.live.comfor Microsoft sign-inaccounts.google.comfor Google sign-in
The principle, in 3 actions
Whatever your tool, the logic is always the same:
- Exclude `blify.co` and its subdomains from browser isolation. This is the decisive action.
- Allow (allow / permit) those same domains.
- If Blify links are delivered by email, disable link rewriting (URL rewriting).
Configuration by tool
Menu names vary depending on the tool and console version. When in doubt, rely on the 3 actions above and on your vendor's support.Mimecast
Isolation comes from Mimecast Browser Isolation. Add the domain to Managed URLs (Administration > Gateway > Managed URLs), with the Permit action and Match on subdomains enabled. This entry exempts the domain from both isolation and link rewriting.
Microsoft Defender for Office 365
Defender works by rewriting links (Safe Links), not by isolation. Add blify.co and *.``blify.co to the "Do not rewrite the following URLs" list in your Safe Links policy. If Blify still opens in an isolated session, the isolation comes from a third-party web proxy, to be handled in that tool.
Proofpoint
Exclude blify.co and its subdomains from Proofpoint Browser Isolation, then add the domain to the URL Defense allow list (Security Settings > Email > URL Defense).
Zscaler (Internet Access)
Create a custom URL category containing blify.co and *.``blify.co. Allow this category in URL filtering, then exclude it from Zscaler Cloud Browser Isolation.
Netskope
Add blify.co and its subdomains to an allow list, permit them in a Real-time Protection policy, then exclude them from the RBI (Remote Browser Isolation) module.
Cisco Umbrella
Add blify.co and its subdomains to an Allow list (Policies > Management > Destination Lists), then apply this list to the relevant policy.
Fortinet, Palo Alto and other tools
Apply the 3 actions: exclude blify.co and *.``blify.co from isolation, allow those domains, and disable link rewriting if your users receive Blify links by email.
Durable fix
Ask your vendor for a category review so thatblify.co is permanently classified as a legitimate business application. Once the domain is categorized, isolation will no longer be triggered, even without a manual allow entry.Check that it works
- Open
https://app.blify.coin a browser. - Confirm the page loads directly, with no isolation banner and no countdown timer.
- Sign in with Microsoft or Google and confirm the login completes.
Need help?
Write to help@blify.co with the security tool you use and, if possible, a screenshot of the symptom. We will help you finalize the configuration.
Updated on: 17/07/2026
