Private Web Application Access for Secure Agentless Access
Focus
Prisma Access

Private Web Application Access for Secure Agentless Access

Table of Contents

Private Web Application Access for Secure Agentless Access

You can enable secure, agentless access to private web applications for unmanaged users, simplifying onboarding and enhancing enterprise security with browser-based access.
Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Strata Cloud Manager)
  • Prisma Access (Managed by Panorama)
  • Minimum Prisma Access version: 6.1 Preferred
  • Minimum PAN-OS dataplane version: 11.2.7
  • Prisma Access license with a Mobile User subscription
  • Cloud Identity Engine (CIE) for user authentication
  • Service Connection (SC), or ZTNA Connector, or Colo-Connect for private app connectivity
  • Remote Browser Isolation (RBI) license for data controls for SaaS applications
  • Network Administrator or Superuser role
For modern enterprises, secure access is a requirement for all devices, with the trend of the workforce (FTEs, contractors, partners) using their own devices to access sensitive data. This extended workforce accessing enterprise applications on unmanaged devices presents unique challenges, as traditional solutions like Mobile Device Management (MDM) or endpoint agents are often not applicable, leading to potential loss of sensitive data and possibly loss of productivity.
Providing secure access to unmanaged devices without installing additional software remains a significant hurdle. Mandatory installation of agents, VPN clients, or other software on endpoints is often not viable for unmanaged users such as contractors, vendors, and BYOD employees who either lack administrative rights, have conflicting software already installed, or prefer not to install additional software for privacy reasons. This challenge is particularly acute for federal contractors working on government-furnished equipment (GFE), where installation of third-party software or browser extensions is strictly prohibited by security policies. This challenge was previously addressed for SSH, RDP, and VNC applications through the Secure Agentless Access (formerly Secure Agentless Access) solution.
Private Web Application Access now extends this capability, enabling secure, browser-based access to internal HTTP or HTTPS applications for unmanaged devices and users. This feature leverages the existing Secure Agentless Access architecture to include private web resources. The primary goal is to simplify administration and enhance productivity for the extended workforce by eliminating the need for client software or agents on end-user devices, thereby providing a streamlined and secure access solution where traditional endpoint agents or MDM are not applicable.
You can optionally enable Remote Browser Isolation (RBI) for private web applications to add an additional layer of data protection. When isolation is enabled, private web application content is rendered in a secure, cloud-hosted browser environment rather than directly on the user's device. This ensures that sensitive corporate data from internal applications never reaches the unmanaged endpoint.
To enable isolation, you configure the application URL under a custom URL category, mark it for isolation in a URL Access Management profile, associate the profile with a profile group, and bind the profile group to a security policy. A Remote Browser Isolation (RBI) license is required in addition to the Secure Agentless Access (SAA) license.
App isolation is optional for private web applications. Without the RBI license and isolation configuration, private web applications function normally through direct browser-based access without isolation.