Activate Your Prisma Access License: PayGo
Focus
Focus
Prisma Access

Activate Your Prisma Access License: PayGo

Table of Contents

Activate Your Prisma Access License: PayGo

Activate the Pay-As-You-Go billing model on your root tenant to enable flexible, monthly postpaid licensing for your managed service tenants.
Where Can I Use This?What Do I Need?
  • Strata Multitenant Cloud Manager
  • Multitenant Superuser role on the root tenant
  • Active Palo Alto Networks Customer Support Portal (CSP) account
The Pay-As-You-Go (PayGo) billing model for Prisma® SASE provides Managed Service Providers (MSPs) with a flexible way to onboard customers and manage licenses as their tenant base grows. PayGo uses a monthly postpaid model, where you are billed based on the packages activated, add-ons, and the capacity (mobile users and site count) within the package activated each day during the billing cycle.
With PayGo, you can:
  • Select and scale PayGo packages—Scale to meet different customer requirements by selecting the appropriate PayGo package: use Prisma Browser for browser-based security, SASE SWG for secure internet and SaaS access, or SASE ENT for comprehensive secure internet, SaaS, and private application access.
  • Onboard tenants quickly—Add new tenants, set initial capacity count (mobile users, sites, and other resources), and deploy environments as needed.
  • Manage licenses flexibly—Increase or decrease the capacity count (mobile users, sites, and other resources), enable or disable add-ons based on tenant requirements within a PayGo package.
  • Monitor PayGo packages from the root—Gain unified visibility from the root, where packages, add-ons, and capacity counts are tracked on a daily basis across all tenants.

How PayGo Works

When a PayGo SKU order is processed, the subscription is activated on the absolute root tenant associated with the Customer Support Portal (CSP). The root tenant acts as a container for child tenants and provides a consolidated view of PayGo activity.
You can create child tenants under the absolute root tenant and activate SASE ENT, SASE SWG, and Prisma Browser Core packages on those tenants.
At the end of each billing cycle, you receive a monthly invoice based on the package chosen, add-ons selected, and capacity (MU and site count) tracked daily across your child tenants during the billing period.

Activate PayGo

When a PayGo SKU order is processed, the subscription is activated on the root tenant. The root tenant serves as the parent container for all child tenants and does not consume or activate packages. After the root tenant is activated, you can create child tenants and activate SASE SWG, SASE ENT, and Prisma Browser Core packages on those tenants. Billing is calculated based on the packages active on each child tenant for a given day.
You can view consolidated package and billing information from the root tenant. However, you cannot activate packages directly on the root tenant.
To activate PayGo:
  1. Click Activate in the activation email to open the subscription management page.
  2. Click Post Paid > Launch on the MSSP SASE PayGo product to open the MSP Portal.
    The Pre-Paid tab appears only if you have an active pre-paid subscription. Otherwise, you are directed to the Post-Paid page.
  3. In the MSP Portal, select ConfigurationWorkflowsTenant Onboarding. The Activate New Tenant with PayGo Postpaid Billing Model tile confirms that activation is complete.
After activation, you can add child tenants and activate the following packages on them:
  • Prisma Browser Core
  • SASE SWG or SASE ENT (Prisma Access and its add-ons)