If the external servers that the browsers send info to are known then the IPs or domains should be listed so that people can add them to any firewall or proxy they happen to have.
As a small example, in my Dev environment, it is completely isolated however I have a set of 10 IP addresses outside of the DHCP scope that allow internet access, but the firewall is configured to block all access to Microsoft websites from those IPs.
People can choose for themselves whether they want to use the browser or not, and how involved they want to be in using it.