| Where Can I Use This? | What Do I Need? |
- Strata Cloud Manager
- Standalone Prisma Browser
|
|
IP-based enforcement ensures that access to SSO-enabled applications is
only possible from the Prisma Browser. Authentication traffic to your IdP flows
through a special proxy with a set of known egress IP addresses.
The Prisma Browser uses the Authentication Proxy for
the SSO login pages only. It does not use the proxy for any other traffic.
The Prisma Access Gateway acts as a forward proxy with a set of predictable
IP addresses. You then need to configure the browser to route the IdP authentication
traffic through the Prisma Browser gateway.
You then need to create and establish a conditional access rule in the IdP,
making a requirement to only use the Prisma Browser Gateway for authentication.
This means that any attempt to authenticate via a different browser will fail.
To begin the process, perform the following actions: