Configure the Prisma Agent
Focus
Focus
Prisma Agent

Configure the Prisma Agent

Table of Contents

Configure the Prisma Agent

Secure the endpoints in your mobile workforce by onboarding your mobile users so that they can access Prisma Access using the Prisma Agent.
Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Strata Cloud Manager)
  • Prisma Access (Managed by Panorama)
  • NGFW (Managed by Panorama)
  • Check the prerequisites for the deployment you're using
  • Contact your Palo Alto Networks account representative to activate the Prisma Agent feature
Onboard your mobile users so that they can access Prisma Access using the Prisma Agent. When your end users access your organization's network and resources using the Prisma Agent, traffic is sent through the tunnel to Prisma Access or NGFW for policy enforcement and threat prevention. The Prisma Agent also provides host information profile reports to ensure that the endpoints comply with your Security policy before they can access sensitive applications.
To onboard your mobile users, you must first contact your Palo Alto Networks account representative to activate the Prisma Agent feature. Then, you can set up Prisma Access to provision the Prisma Agent environment and configure the Prisma Agent settings so that the settings can be pushed to your endpoints.
(Not supported on Prisma Agent Linux) You can also set up staged rollouts of the Prisma Agent at this time, or configure the staged rollouts later. After the initial deployment of the Prisma Agents, you can use the upgrade rollout functionality to automatically upgrade groups of devices. With upgrade rollouts, you don't have to rely on mobile device management (MDM) software, such as Jamf Pro and Microsoft Intune, to upgrade Prisma Agents.
Before configuring mobile users, ensure that you have the required licenses (Prisma Access license for mobile users and a Strata Logging Service license with proper firewall storage space). If mobile users will be connecting to other connected networks, you will need either the Zero Trust Network Access or Enterprise Edition Prisma Access license that will provide the corporate access node (CAN) necessary to connect.
You can configure the agent on a Prisma Access tenant (instance) that already has GlobalProtect configured (coexistence-enabled tenant).