Policy Object: Quarantine Device Lists
Focus
Focus
Network Security

Policy Object: Quarantine Device Lists

Table of Contents

Policy Object: Quarantine Device Lists

Identify and quarantine compromised devices that are connected with the GlobalProtect app.
Where Can I Use This?What Do I Need?
  • NGFW
  • Prisma Access
Check for any license or role requirements for the products you're using.
Quarantine Device Lists enable you to centrally manage and isolate potentially compromised or non-compliant devices across your network. When you add devices to a quarantine list, you can automatically apply restrictive security policies that limit their network access while allowing essential remediation activities.
Devices can be added to quarantine lists manually by administrators or automatically through integration with threat detection systems, endpoint protection platforms, or compliance monitoring tools. Once quarantined, devices remain isolated until they're explicitly removed from the list after successful remediation and validation.
A device appears in the quarantine list as a result of the following actions:
  • The system administrator added the device to this list manually.
  • The device was added to the quarantine list automatically: (Prisma Access Only)
    • Using a log forwarding profile with a security rule whose match list had a built-in action set to Quarantine.
    • Using HIP match log settings with built-in action set to Quarantine.
  • The device was added to the quarantine list using an API. (Prisma Access Only)
  • The quarantine list was received as a part of redistributed entry. (Prisma Access Only)
Here's how to get started with Quarantine Device Lists. Here are additional use cases for Quarantine List Redistribution.
To redistribute Quarantine List information in Prisma Access for both Prisma Access (Managed by Strata Cloud Manager) and Prisma Access (Managed by Panorama), see Redistribute Quarantine List Information in the Prisma Access Administration Guide.

Policy Object: Quarantine Device Lists (Strata Cloud Manager)

Configure the quarantine list feature for Strata Cloud Manager Managed NGFWs and Prisma Access mobile user (GlobalProtect) deployments.
Quarantine devices for cloud managed NGFWs and Prisma Access using the Quarantine Device List in Strata Cloud Manager. You can either manually or automatically (based on auto-tags) add devices to a quarantine list. You can block quarantined devices from accessing the network or restrict the device traffic based on a security rule.
Prisma Access allows you to identify and quarantine compromised devices with the GlobalProtect app.

Set Up a Quarantined Device List

The Quarantined Device List screen is where you identify devices you want to block from accessing your network.
Follow these steps to add a device to the Quarantined Device List:
  1. Select ConfigurationNGFW and Prisma AccessObjectsQuarantined Device List.
    For Prisma Access deployments, select a Configuration Scope of Prisma Access, for NGFWs, select a Configuration Scope of Global.
  2. Select Add Device.
  3. Fill in the Host ID and Serial Number fields.
  4. Select Save.
  5. Repeat steps 1 through 4 to add additional devices.

Use Quarantine Device List for Security Policy Enforcement

Prevent quarantined devices from sending or receiving traffic on the network by specifying options in a security rule.
Follow these steps to configure Security Policy to use your Quarantined Device List to prevent quarantined devices from sending or receiving traffic on the network:
  1. Select ConfigurationNGFW and Prisma AccessSecurity ServicesSecurity Policy from the sidebar.
    For Prisma Access deployments, select a Configuration Scope of Prisma Access, for NGFWs, select a Configuration Scope of Global.
  2. Select Security Rules and Add RuleSecurity Rule.
  3. In the Source area, find Devices and select Quarantined Devices.
    The policy now uses devices in the quarantine list as the match criteria, whether you specify Quarantine as the Source Device for Source traffic or the Destination Device for Destination traffic.
  4. In the Actions area, specify an Action, that blocks the quarantined device, such as Deny as required by your rule.
  5. Select Save.

Configure Identity Redistribution for Prisma Access

The Identity Redistribution screen is where you configure how identity information is redistributed in the Prisma Access Infrastructure. Configure identity redistribution to use the quarantined device list so that all devices on the network that enforce policy know to block the compromised devices.
To configure identity redistribution, follow the procedure in the Prisma Access Administration Guide.

Block Login for Quarantined Devices for Prisma Access

Block quarantined devices from accessing the network, or block users from logging into the network from devices on the Quarantined Device List.
Follow these steps to configure Authentication Settings to prevent users from logging into GlobalProtect from a quarantined device:
  1. Select .
  2. Scroll down to User Authentications and select Authentication Settings.
    Click the gear to edit the Authentication Settings.
  3. Select the check box for Block Login for Quarantined Devices.
  4. Select Save.

Policy Object: Quarantine Device Lists (PAN-OS & Panorama)

Configure the quarantine list feature for Panorama Managed Prisma Access mobile user (GlobalProtect) deployments.
To manually add and remove devices from the quarantine list, see the procedure in the GlobalProtect Administration Guide. For more information about quarantining device in PAN-OS and Panorama, see Quarantine Devices Using Host Information in the GlobalProtect Administration Guide.
To redistribute quarantine information to and from service connections and the Panorama that manages Prisma Access, see Configure Quarantine List Redistribution in Prisma Access in the Prisma Access Administration Guide. The Prisma Access (Managed by Panorama) procedure is near the bottom of the document.