Activate Your Prisma Access License: PayGo
Activate the Pay-As-You-Go billing model on your root tenant to enable flexible,
monthly postpaid licensing for your managed service tenants.
| Where Can I Use This? | What Do I Need? |
- Strata Multitenant Cloud Manager
|
- Multitenant Superuser role on the root tenant
- Active Palo Alto Networks Customer Support Portal (CSP)
account
|
The Pay-As-You-Go (PayGo) billing model for Prisma® SASE provides Managed Service
Providers (MSPs) with a flexible way to onboard customers and manage licenses as their
tenant base grows. PayGo uses a monthly postpaid model, where you are billed based on
the packages activated, add-ons, and the capacity (mobile users and site count) within
the package activated each day during the billing cycle.
With PayGo, you can:
- Select and scale PayGo packages—Scale to meet different customer
requirements by selecting the appropriate PayGo package: use Prisma Browser for
browser-based security, SASE SWG for secure internet and SaaS access, or SASE ENT
for comprehensive secure internet, SaaS, and private application access.
- Onboard tenants quickly—Add new tenants, set initial capacity count (mobile
users, sites, and other resources), and deploy environments as needed.
- Manage licenses flexibly—Increase or decrease the capacity count (mobile
users, sites, and other resources), enable or disable add-ons based on tenant
requirements within a PayGo package.
- Monitor PayGo packages from the root—Gain unified visibility from the root,
where packages, add-ons, and capacity counts are tracked on a daily basis across all
tenants.
How PayGo Works
When a PayGo SKU order is processed, the subscription is activated on the absolute
root tenant associated with the Customer Support Portal (CSP). The root tenant acts
as a container for child tenants and provides a consolidated view of PayGo
activity.
You can create child tenants under the absolute root tenant and activate SASE ENT,
SASE SWG, and Prisma Browser Core packages on those tenants.
At the end of each billing cycle, you receive a monthly invoice based on the package
chosen, add-ons selected, and capacity (MU and site count) tracked daily across your
child tenants during the billing period.
Activate PayGo
When a PayGo SKU order is processed, the subscription is activated on the root
tenant. The root tenant serves as the parent container for all child tenants and does
not consume or activate packages. After the root tenant is activated, you can create
child tenants and activate SASE SWG, SASE ENT, and Prisma Browser Core packages on
those tenants. Billing is calculated based on the packages active on each child
tenant for a given day.
You can view consolidated package and billing information from the root tenant.
However, you cannot activate packages directly on the root tenant.
To activate PayGo:
- Click Activate in the activation email to open the
subscription management page.
- Click Post Paid > Launch on the
MSSP SASE PayGo product to open the MSP Portal.
The
Pre-Paid tab appears only if you have an active
pre-paid subscription. Otherwise, you are directed to the
Post-Paid page.
- In the MSP Portal, select . The Activate New Tenant with PayGo Postpaid Billing
Model tile confirms that activation is complete.
After activation, you can add child tenants and activate the following packages on
them:
- Prisma Browser Core
- SASE SWG or SASE ENT (Prisma Access and its add-ons)