Set Up Prisma Agent User Authentication
Focus
Focus
Prisma Agent

Set Up Prisma Agent User Authentication

Table of Contents

Set Up Prisma Agent User Authentication

Set up the authentication for Prisma Agent users.
Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Strata Cloud Manager)
  • Prisma Access (Managed by Panorama)
  • NGFW (Managed by Panorama)
  • Check the prerequisites for the deployment you're using
  • Contact your Palo Alto Networks account representative to activate the Prisma Agent feature
Set up user authentication so that only legitimate Prisma Agent users have access to your services and applications.
The first time a user connects to the Prisma Agent app, the user is prompted to authenticate to the server (also known as the Prisma Agent Manager or EPM). Once authenticated, the Prisma Agent receives the configuration from the server, which includes the list of gateways to which the app can connect, and optionally a client certificate for connecting to the gateways. After successfully downloading and caching the configuration, the app attempts to connect to one of the gateways specified in the configuration. Because these components provide access to your network resources and settings, they also require the end user to authenticate. The appropriate security level required on the gateways varies with the sensitivity of the resources that the gateway protects.
Prisma Agent provides the following authentication types:
  • SAML 2.0 or Client Certificate authentication through Cloud Identity Engine
    Prisma Agent supports the following combinations of SAML and Client Certificate authentication through Cloud Identity Engine:
    • SAML
    • Client Certificate (Does not apply to Prisma Agent Linux)
    • SAML or Client Certificate (Does not apply to Prisma Agent Linux)
    • SAML and Client Certificate (Does not apply to Prisma Agent Linux)
    Cloud Identity Engine provides both user identification and user authentication for mobile users.
  • LDAP authentication through the GlobalProtect™ portal (Does not apply to Prisma Agent Linux)
    LDAP authentication for Prisma Agent leverages your existing GlobalProtect portal LDAP authentication infrastructure, eliminating the need to reconfigure authentication methods when migrating to Prisma Agent. With LDAP authentication support, you can configure Prisma Agent to authenticate users against your existing directory services through the GlobalProtect portal, providing a smooth transition path for you to migrate existing deployments from GlobalProtect to Prisma Agent.
Be sure to set up user authentication before you complete the first Push Config.