Managed AIRS for AWS Tenant
This section gives details on all Managed AIRS for AWS tenants.
| Where Can I Use This? | What Do I Need? |
|
|
- Managed AIRS for AWS subscription
- Palo Alto Networks Customer Support Account (CSP)
- AWS Marketplace account
- User role (either tenant or administrator)
|
A Managed AIRS for AWS tenant is an instantiation of Palo Alto Networks’ Cloud
Next-Generation Firewall (NGFW) service associated with your (or your organization’s)
AWS environment. It represents a logically isolated and dedicated boundary for
deploying, managing, and monitoring the SaaS firewall (also known as Managed AIRS for AWS
resource) protections natively in your AWS environment.
Managed AIRS for AWS console helps you centrally manage and govern your tenant. It enables
centralized user administration, AWS account administration, firewall and policy
management, and integration with both AWS and Palo Alto Networks’ security management
platforms.
Key Functions of a Tenant:
| Functions | Description |
| AWS account(s) administration | A Managed AIRS for AWS tenant manages AWS account administration
through a combination of direct AWS marketplace subscription, permission
delegation, and allow-list enablement. Refer here for further details on
Subscribed accounts, Onboarded accounts, and AllowListed
accounts. |
| Users & Roles Management | A Managed AIRS for AWS tenant uses robust role-based access control
(RBAC) to manage who can access and administer firewall resources, and
who can manage local policies or integrate with Palo Alto Networks’
policy managers (Panorama, Strata Cloud Manager). |
| NGFW resource management | A Managed AIRS for AWS tenant streamlines and centralizes the
management of Managed AIRS for AWS resources in AWS by providing a unified
administrative layer for deployment, configuration, and policy
enforcement |
| Metering & Billing management | A Managed AIRS for AWS tenant consolidates the metering and billing
of all its Managed AIRS for AWS resources and their related usage of
Cloud-Delivered Security Services (CDSS) and Centralized management
(Panorama, Strata Cloud Manager, and Strata Logging Service). For this
purpose, it enables you to associate credits that you
procured via contract. It also allows you to subscribe from AWS
Marketplace for sending PAYG and overage metering records. |
Tenant Information in Strata Cloud Manager Console
If you have previously started from
Strata Cloud Manager, you can access the
Strata Cloud Manager console to view your Managed AIRS for AWS tenant Information.
To determine your tenant information:
Log in to the Strata Cloud Manager console.
Go to Configurations and then select Managed AIRS for AWS.
Click Managed AIRS for AWS Tenant Info.