Prisma Browser Prerequisites
Focus
Focus
Prisma Browser

Prisma Browser Prerequisites

Table of Contents

Prisma Browser Prerequisites

Learn about the prerequisites for Prisma Access Secure Enterprise Browser (Prisma Browser), including: system requirements, domains to allow, and IdP proxy requirements.
Where Can I Use This?What Do I Need?
  • Strata Cloud Manager
  • Standalone Prisma Browser
  • Prisma Access with Prisma Browser bundle license or Prisma Browser standalone license
  • Superuser or Prisma Browser role

System Requirements

Windows
  • Windows 10 64-bit - ARM (A64) is supported.
    Effective October 14, 2025, Microsoft will discontinue support for Windows 10. After this date, they will no longer provide security updates, bug fixes, technical support, or feature enhancements.
  • Windows 11 64-bit - ARM (A64) is supported.
  • No admin privileges are required
macOS
  • macOS Monterey 12.0 or later.
  • Intel x86 or Apple M1 and above
  • No admin privileges are required
Linux
  • Ubuntu 22.04.5 LTS or later
  • Fedora 41 or later
  • IGEL OS12 or later
  • Architecture - x64
    Prisma Browser Linux deployment requires installation with Sudo permissions
Android
  • Android 12 and above with all security updates
iOS
  • iOS 18 and above.

For Prisma Access Customers

  • Dataplane (PANOS): 10.2.9-h7, 10.2.4-h17, 10.2.10, 11.2.1
  • PA Infrastructure: 5.1.1
  • Panorama: 10.2.4 and above
  • Cloud Services Plugin: 5.1.0-h15

Domains to Allow

The Prisma Browser communicates with several domains.
SSL/TLS Inspection Requirement
DO NOT enable SSL/TLS inspection for domains communicating with the Prisma Browser.
Prisma Browser uses certificate pinning for critical security. Network security infrastructure (Firewalls, Proxies, VPNs) that attempts to inspect traffic acts as a "Man-in-the-middle" by stripping the authentic Prisma Browser certificate and replacing it with its own external certificate.
Prisma Browser is designed to immediately detect and verify this behavior, resulting in the termination of the connection to the browser to prevent a potential security breach. This action is mandatory to maintain the integrity and security of the browser.
Required Action:
These domains must be added to your SSL Decryption Exclusion list. (SSL/TLS Bypass)
Please select your region:

For SSO Enforcement or Private App Access

For SSO Enforcement or Private App Access, you need to white-list *.prismaaccess.com.

For Prisma Access Customers Leveraging SSH/RDP/VNC Connections

*.panwpra.com

Prisma Browser Ecosystem and Identity Providers

The Prisma Browser ecosystem is designed to integrate with all modern Identity Providers (IdP), including:
  • Microsoft Entra ID
  • Okta
  • Google Workspace
  • PingOne
  • PingFederate
The Prisma Browser does not support older versions of ADFS. Authentication may fail if the ADFS server blocks calls to the IdP page.

Required Attributes for IdP Integration

For successful synchronization of users and groups, the IdP must populate specific attributes into the Cloud Identity Engine (CIE). The following attributes are mandatory:
  • For Group Synchronization:
    • Common-Name: The group's display name.
    • Unique Identifier: The group's ObjectGUID.
  • For User Synchronization:
    • Common-Name: The user's display name.
    • Unique Identifier: The user's ObjectGUID.
    • Mail: The user's email address.
    • User Principal Name (UPN): The user's UPN.