Set up Prisma® AIRS™ in Strata Cloud Manager so that Cortex Agentic Endpoint
Security (AES) can enforce AI security policies on AI coding agents running on developer
endpoints.
| Where Can I Use This? | What Do I Need? |
- Prisma AIRS — AI Runtime Security (API Intercept)
|
- Prisma AIRS AI Runtime API application
- Cortex AES subscription
|
Prisma AIRS integrates with Cortex Agentic Endpoint Security (AES), an endpoint
governance platform, to secure AI coding tools such as Claude Code, Cursor, Codex,
GitHub Copilot, and Antigravity on developer endpoints. Prisma AIRS inspects the
content flowing through those agents — prompts, MCP tool calls, and network calls —
and returns an enforcement verdict. AES owns everything around that verdict on the
endpoint: it decides which agents, endpoint groups, and events are in scope, deploys
and manages the AIRS hooks on every device with API keys handled centrally, enforces
the verdict and informs the developer inside the agent's chat, and records every
verdict in the AES portal attributed to the device, agent, session, and policy.
Detection rules are defined once in the Prisma AIRS console in Strata Cloud Manager
and pushed to thousands of endpoints as managed policy, with no per-device hook
setup.
Prisma AIRS inspects user prompts before they reach the LLM and after the response
returns, external MCP tool calls before execution, and network calls (WebFetch and
WebSearch) before and after execution. It detects prompt injection, sensitive data
leakage, insecure output such as malware and malicious URLs, toxic content, and
credential leakage. When sensitive data is detected, the response returns masked
text in place of the original content.
You define and manage security profiles entirely in the Prisma AIRS console in Strata
Cloud Manager. A profile specifies which detectors run and their configured actions
— for example, prompt injection set to block. Once connected, AES fetches your
security profiles so a runtime policy can reference them by name: a default profile
applies to the whole policy, and any individual rule for prompts, MCP tools, or
network calls can override it with a different profile. To enable this integration,
set up Prisma AIRS in Strata Cloud Manager
and then
complete the remaining configuration in the AES
portal.