ADEM Deployment Best Practices
Distribute monitoring across the three ADEM monitoring sources to
achieve complete visibility without degrading endpoint or network performance.
ADEM gives you the visibility needed to quickly troubleshoot user
experience issues. To get the best results without overloading your devices or network,
distribute your tests effectively across Mobile Users, Remote Sites, and
Prisma Access Compute Locations.
Steps to Optimize Your ADEM Deployment
To maximize troubleshooting visibility while keeping resource usage low, balance your
synthetic tests across all available Mobile Users, Remote Sites, and
Prisma Access Compute Locations.
- Shift High-Capacity Monitoring to Cloud Locations. Run high-volume SaaS
and private app availability tests directly from Prisma Access Compute
Locations. Because tests execute within Palo Alto Networks infrastructure, you
can continuously monitor 50–200+ applications without consuming endpoint CPU or
user bandwidth.
- Target Endpoint Synthetic Tests. Limit mobile user synthetic tests to
1–10 core baseline applications per user. Use Cloud Identity Engine (CIE) to
restrict private application tests to the user groups that actually use those
applications. Device, Wi-Fi, LAN, and Internet health data collected from these
tests applies universally across all applications on the same connection.
- Enable Real User Monitoring (RUM). Turn on browser-based RUM for passive,
unlimited application performance data. ADEM combines RUM
telemetry with synthetic test data to provide granular root-cause analysis.
- Monitor Branch Sites Efficiently. Enable ADEM on
Remote Network sites via SD-WAN, NGFW, or Universal Agent to differentiate
branch-level routing issues from individual user problems. On branches with
limited compute resources, monitor active paths only. When you monitor multiple
paths, ADEM calculates the experience score by averaging the scores across all
active paths.
- Enable UCaaS Integration. Integrate Microsoft Teams and Zoom to get
per-minute root-cause analysis for audio and video call quality, correlated
directly with endpoint and network health data.
- Integrate CCaaS and browser-based contact center applications such as
Genesys Cloud CX, Five9, and Dialpad to automatically capture per-call WebRTC
quality metrics directly from active browser sessions.
- Enable Self-Serve Notifications. Configure ADEM
Self-Serve to notify end-users directly about local Wi-Fi, ISP, or app issues,
reducing helpdesk ticket volume before a ticket is ever opened.