Configure the Prisma Access Agent's anti-tamper protection features to protect agent
processes, files, and registries from unauthorized tampering.
| Where Can I Use This? | What Do I Need? |
Prisma Access Agent's anti-tamper feature protects the agent's services, processes,
files, and registries from tampering by users. When configured, users require
specific one-time passwords (OTPs) or a Privileged Access Token to perform
privileged actions such as restarting agent services or uninstalling the agent.
The enhanced anti-tamper functionality addresses several security concerns:
- Provides unique per-device OTPs for specific privileged operations
- Enforces role-based access controls (RBAC) for viewing or generating anti-tamper
credentials
- Maintains comprehensive audit trails for anti-tamper usage
- Offers a "break glass in case of emergency" Privileged Access Token for use in
case of the loss of network connectivity
The anti-tamper protection system supports several types of passwords for different
purposes:
| Password Type | Expires After First Use | System Generated | Purpose |
| Disable Agent OTP | Yes | Yes | Single-use token for temporarily disabling the agent |
| Uninstall Agent OTP | Yes | Yes | Single-use token for uninstalling the agent |
| Privileged Access OTP | Yes | Yes | Used for any privileged operation including restarting agent
services |
| Privileged Access Token | No | No | Administrator-defined emergency token for critical access
scenarios |
All OTPs will refresh after one-time use and are never stored on the endpoint. The
Privilege Access Token is static and does not expire after each use.
To configure anti-tamper protection: