ADEM Deployment Best Practices
Focus
Focus
Autonomous DEM

ADEM Deployment Best Practices

Table of Contents

ADEM Deployment Best Practices

Distribute monitoring across the three ADEM monitoring sources to achieve complete visibility without degrading endpoint or network performance.
ADEM gives you the visibility needed to quickly troubleshoot user experience issues. To get the best results without overloading your devices or network, distribute your tests effectively across Mobile Users, Remote Sites, and Prisma Access Compute Locations.

Steps to Optimize Your ADEM Deployment

To maximize troubleshooting visibility while keeping resource usage low, balance your synthetic tests across all available Mobile Users, Remote Sites, and Prisma Access Compute Locations.
  1. Shift High-Capacity Monitoring to Cloud Locations. Run high-volume SaaS and private app availability tests directly from Prisma Access Compute Locations. Because tests execute within Palo Alto Networks infrastructure, you can continuously monitor 50–200+ applications without consuming endpoint CPU or user bandwidth.
  2. Target Endpoint Synthetic Tests. Limit mobile user synthetic tests to 1–10 core baseline applications per user. Use Cloud Identity Engine (CIE) to restrict private application tests to the user groups that actually use those applications. Device, Wi-Fi, LAN, and Internet health data collected from these tests applies universally across all applications on the same connection.
  3. Enable Real User Monitoring (RUM). Turn on browser-based RUM for passive, unlimited application performance data. ADEM combines RUM telemetry with synthetic test data to provide granular root-cause analysis.
  4. Monitor Branch Sites Efficiently. Enable ADEM on Remote Network sites via SD-WAN, NGFW, or Universal Agent to differentiate branch-level routing issues from individual user problems. On branches with limited compute resources, monitor active paths only. When you monitor multiple paths, ADEM calculates the experience score by averaging the scores across all active paths.
  5. Enable UCaaS Integration. Integrate Microsoft Teams and Zoom to get per-minute root-cause analysis for audio and video call quality, correlated directly with endpoint and network health data.
  6. Integrate CCaaS and browser-based contact center applications such as Genesys Cloud CX, Five9, and Dialpad to automatically capture per-call WebRTC quality metrics directly from active browser sessions.
  7. Enable Self-Serve Notifications. Configure ADEM Self-Serve to notify end-users directly about local Wi-Fi, ISP, or app issues, reducing helpdesk ticket volume before a ticket is ever opened.