Migrate from GlobalProtect to Prisma Agent
Learn how to migrate your mobile user deployments from GlobalProtect to the Prisma Agent on an existing Prisma Access tenant.
If you have an active GlobalProtect deployment on a Prisma® Access tenant, you can
onboard the Prisma Agent on the same tenant without removing your existing
GlobalProtect configuration. The two apps can coexist on the same tenant, and many
infrastructure settings—such as Client DNS, Client IP Pool, Prisma Access locations, and
external gateways—are shared, which reduces the work required to bring the Prisma Agent online.
Regardless of how your Prisma Access tenant is managed, the migration involves the same
four areas of configuration that are specific to the Prisma Agent:
- Infrastructure—You must configure a Prisma Agent Domain Name. This is
the only new mandatory infrastructure setting; all other infrastructure settings are
inherited from your existing GlobalProtect configuration.
- User authentication—The Prisma Agent requires Cloud Identity Engine
(CIE) for SAML 2.0 authentication. If your GlobalProtect deployment uses a different
authentication method, you must configure a CIE-based authentication profile before
you can commit your Prisma Agent configuration.
- Forwarding profiles—The Prisma Agent uses forwarding profiles instead
of GlobalProtect split tunnel settings to control how traffic is routed. You create
equivalent forwarding profiles and Destination profiles to replicate your existing
split tunnel exclusions.
- Agent deployment—You deploy the Prisma Agent to endpoints using your
MDM software or manual installation. The recommended approach is to install the
Prisma Agent in active mode first, verify it is working correctly, and then
uninstall GlobalProtect.
After the Prisma Agent is operational and GlobalProtect is removed, the migration
is complete. Select the section below that corresponds to how your Prisma Access tenant
is managed: