Deploy Prisma Access Agents to macOS Endpoints Using Jamf Pro
Focus
Focus
Prisma Access Agent

Deploy Prisma Access Agents to macOS Endpoints Using Jamf Pro

Table of Contents

Deploy Prisma Access Agents to macOS Endpoints Using Jamf Pro

Learn how to deploy the Prisma Access Agent package to macOS endpoints using Jamf Pro.
Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Strata Cloud Manager)
  • Prisma Access (Managed by Panorama)
  • NGFW (Managed by Panorama)
  • Check the prerequisites for the deployment you're using
  • Minimum Prisma Access Agent version: 25.3.1.14
  • macOS 14 and later desktop devices
  • Contact your Palo Alto Networks account representative to activate the Prisma Access Agent feature
Jamf Pro is a mobile device management (MDM) tool that enables you to configure and deploy software to macOS endpoints from a central console. After you download the Prisma Access Agent package and configuration file from the Endpoint Management page (ConfigurationEndpoint Management), you can use Jamf Pro to deploy the agent to macOS endpoints.
To deploy the Prisma Access Agent, complete the following tasks:
  1. Push the required GoDaddy CA certificates to your macOS endpoints using a certificate payload in a Jamf Pro configuration profile before deploying the Prisma Access Agent.
    If the Go Daddy Root Certificate Authority - G2 certificate is not in the endpoint's trusted root store, the Prisma Access Agent fails to enroll with the Endpoint Manager. See CA Certificate Requirements for Endpoint Manager Enrollment for details.
    1. In Jamf Pro, select ComputersConfiguration Profiles and click New.
    2. In the General payload, choose Computer Level as the level. This ensures the certificate is installed in the System Keychain and is trusted system-wide.
    3. Add a Certificate payload and upload the Go Daddy Root Certificate Authority - G2 certificate file.
    4. Click the Scope tab and assign the profile to the device groups targeted for Prisma Access Agent deployment.
    5. Click Save.
    6. Create a second profile using the same process for the Go Daddy Secure Certificate Authority - G2 intermediate certificate.
    7. Confirm that both profiles show a Completed status before proceeding.
  2. Deploy configuration profiles that define how Prisma Access Agents are configured using one of the following methods:
  3. Create a Jamf policy that will trigger the installation of the Prisma Access Agent on enrolled macOS devices.