Configure Agent Settings for Migration (Panorama)
Focus
Focus
Prisma Agent

Configure Agent Settings for Migration (Panorama)

Table of Contents

Configure Agent Settings for Migration (Panorama)

Configure basic agent settings, anti-tamper protection, and gateway settings for the Prisma Agent on a Panorama-managed tenant.
Agent settings control how the Prisma Agent connects and behaves on endpoints. During migration, you configure a default agent profile to match your GlobalProtect deployment's connect method, and optionally enable anti-tamper protection before you uninstall GlobalProtect. External gateway settings are shared with GlobalProtect and carry over automatically; you must reconfigure Internal Host Detection specifically for the Prisma Agent.
  1. Configure Basic Agent Settings
    1. Select ConfigurationPrisma Access AgentSettingsPrisma Access Agent.
    2. In the Agent Settings table, select the DEFAULT agent settings profile.
    3. Review the following default settings and change them to meet your requirements:
      • User Groups: Match Any
      • Connect method: Always On
  2. (Optional) Configure Anti-Tamper Protection
    Enable anti-tamper protection to prevent users from disabling or uninstalling the Prisma Agent after GlobalProtect is removed.
    1. In Agent Settings, scroll to the Anti-Tamper section.
    2. Enable Privileged Access Protection.
    3. Configure a Privileged Access Token ("break glass in case of emergency" password).
      For the full anti-tamper configuration, see Configure Enhanced Anti-Tamper Protection for Prisma Agents.
  3. Verify Gateway Configuration
    External Gateway configurations are shared with GlobalProtect and do not require reconfiguration. However, you must reconfigure Internal Host Detection for the Prisma Agent.
    To edit External Gateway settings such as IP, region, or priority, click the External Gateway name.
    Prisma Access Remote Network Internal Gateway is not supported. However, internal gateways are supported when using on-premises NGFWs. For more information, see Configure Gateways for the Prisma Agent.