Enable the Gen-AI-Best-Practice Snippet
Focus
Focus
AI Access Security

Enable the Gen-AI-Best-Practice Snippet

Table of Contents

Enable the Gen-AI-Best-Practice Snippet

Associate the Gen-AI-Best-Practice snippet to implement out of the box best practices for GenAI app adoption recommended by Palo Alto Networks.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by Panorama or Strata Cloud Manager)
  • Prisma Access (Managed by Panorama or Strata Cloud Manager)
One of the following:
  • AI Access Security license
  • CASB-PA license
  • CASB-X license
Activating AI Access Security gives you access to the predefined Gen-AI-Best-Practice snippet. This snippet gives your organization a starting point to implement Security policy rules that use best practices for GenAI app adoption recommended by Palo Alto Networks. This snippet allows you to quickly allow access to Sanctioned GenAI apps and blocks a wide range of potentially risky GenAI apps by default. This helps your organization maintain control over GenAI app usage while still enabling productivity-enhancing tools. AI Access Security associates the Gen-AI-Best-Practice snippet with the default Global configuration folder by default.
Review the two Security policy rules associated with the predefined Gen-AI-Best-Practice snippet for details about what each includes.
    Expand all
    Collapse all
  • Sanctioned GenAI Access
  • Default GenAI App Access
  1. Log in to Strata Cloud Manager.
  2. Select ManageConfigurationNGFW and Prisma AccessSecurity ServicesSecurity PolicyInternet Security.
  3. Toggle the setting in the State column for both the Sanctioned GenAI Access and Default GenAI App Access policy rules to enable.
  4. (Optional) Create and apply Security Profiles to the Sanctioned GenAI Access policy rule.
    Security Profiles allow you to apply additional security settings to allowed traffic to strengthen your security posture. For example, you can associate a DLP rule with the Sanctioned GenAI Access policy rule to prevent exfiltration of sensitive data to Sanctioned GenAI apps. Alternatively, you can use the AI Access Security Recommendations to enable your network security admins to quickly address gaps and strengthen your security posture when adopting GenAI apps.