Migrate from GlobalProtect to Prisma Agent
Focus
Focus
Prisma Agent

Migrate from GlobalProtect to Prisma Agent

Table of Contents

Migrate from GlobalProtect to Prisma Agent

Learn how to migrate your mobile user deployments from GlobalProtect to the Prisma Agent on an existing Prisma Access tenant.
If you have an active GlobalProtect deployment on a Prisma® Access tenant, you can onboard the Prisma Agent on the same tenant without removing your existing GlobalProtect configuration. The two apps can coexist on the same tenant, and many infrastructure settings—such as Client DNS, Client IP Pool, Prisma Access locations, and external gateways—are shared, which reduces the work required to bring the Prisma Agent online.
Regardless of how your Prisma Access tenant is managed, the migration involves the same four areas of configuration that are specific to the Prisma Agent:
  • Infrastructure—You must configure a Prisma Agent Domain Name. This is the only new mandatory infrastructure setting; all other infrastructure settings are inherited from your existing GlobalProtect configuration.
  • User authentication—The Prisma Agent requires Cloud Identity Engine (CIE) for SAML 2.0 authentication. If your GlobalProtect deployment uses a different authentication method, you must configure a CIE-based authentication profile before you can commit your Prisma Agent configuration.
  • Forwarding profiles—The Prisma Agent uses forwarding profiles instead of GlobalProtect split tunnel settings to control how traffic is routed. You create equivalent forwarding profiles and Destination profiles to replicate your existing split tunnel exclusions.
  • Agent deployment—You deploy the Prisma Agent to endpoints using your MDM software or manual installation. The recommended approach is to install the Prisma Agent in active mode first, verify it is working correctly, and then uninstall GlobalProtect.
After the Prisma Agent is operational and GlobalProtect is removed, the migration is complete. Select the section below that corresponds to how your Prisma Access tenant is managed: