Supported Applications for Tenant-Based Policy Enforcement
Focus
Focus
Prisma Browser

Supported Applications for Tenant-Based Policy Enforcement

Table of Contents

Supported Applications for Tenant-Based Policy Enforcement

A reference of all applications that support tenant-based policy enforcement in Prisma Browser, including their supported tenant identifiers and validation requirements.
Where Can I Use This?What Do I Need?
  • Strata Cloud Manager
  • Prisma Browser standalone
  • Prisma Access with Prisma Browser bundle license or Prisma Browser standalone license
  • Superuser or Prisma Browser role
  • A supported application selected in the rule's Applications scope
Tenant-Based Policy Enforcement applies instance-level access and data controls to supported multi-tenant applications. Instead of applying a single policy to an entire application, an Access and Data Control rule can target specific tenants within that application — For example, allowing file uploads to a corporate Google Workspace tenant while blocking uploads to personal Gmail accounts.
When an Access and Data Control rule includes a supported application, the rule wizard enables the Tenants step. For each supported application, select one of the following scopes:
  • Any tenant - The rule applies to all instances of the application. This is the default.
  • Specific tenants - The rule applies only to sessions that match the tenant identifiers entered for that application. The label for this option reflects the identifier the application uses, such as By domain, By workspace name, or By account ID.
Each supported application uses one or more identifier types to distinguish between tenants.
The Tenants step is unavailable when the rule's Applications scope contains no supported application, when the scope is set to any application, or when the rule is a pre-login rule.

Supported Applications and Identifiers

The following table lists all applications that support tenant-based policy enforcement, their available identifier types, and the requirements for each identifier.
ApplicationSupported Tenant IdentifiersInput TypeRequirements
Google WorkspaceDomainFree textStandard domain format, such as acme.com
Google Cloud ConsoleDomainFree textStandard domain format, such as acme.com
Microsoft 365Domain (required)
Resource Host (optional)
Free textStandard domain format, such as contoso.com
Resource host applies to OneDrive and SharePoint only
AWSAccount ID
Region
Free text
Selection list
Exactly 12 numeric (0-9) characters
Selected from the supported AWS regions list
SlackWorkspace NameFree textLowercase letters, numbers, and hyphens; must begin and end with a letter or number
OpenAI ChatGPTDomain
Account ID
Plan Type
Structure
Free text
Free text
Selection list
Selection list
Standard domain format
String match
Free, Go, Plus, Pro, Team, or Business
Workspace or Personal
GitHubAccount IDFree textString match
Claude AIDomain
Account ID
Free textStandard domain format
String match
When an application supports more than one identifier type, the identifiers are combined with AND logic. All configured identifier types must match for the rule to apply. Within a single identifier type, multiple values are combined with OR logic — The rule matches if the session matches any one of the listed values.

Considerations

  • Copy identifiers from the Events page - To ensure accuracy, copy the tenant identifier directly from the Events page rather than entering it manually.
  • Exact string matching - Most tenant identifiers require manual free-text input and are not populated from a discovery list. Certain identifiers are case-sensitive. Incorrect formatting, spacing, or capitalization causes the policy to fail to match.
  • Invalid format - If an entered identifier does not meet the required format, the management console displays an error message and the rule cannot be saved.
  • Undetermined tenant identity - When Prisma Browser cannot determine a tenant value for a session, the rule still matches on that identifier. The Microsoft 365 domain identifier is the exception: a session with an undetermined domain does not match a domain-scoped Microsoft 365 rule.
  • Pre-login behavior - Access to application login pages matches a tenant-scoped rule before the tenant identity is known, so users can reach the sign-in screen. Data controls apply only after the tenant is identified.
  • Enforcement action - When a session does not match the tenant scope of an allow rule, Prisma Browser blocks the page and offers the user the option to sign in with a different account.
  • Migration behavior - Existing rules for supported applications default to Any tenant. Upgrading does not change the current security posture.
  • Draft mode - Modifying the tenant scope of an active rule moves the rule into Draft state. The change takes effect only after the policy is published.

Platform Support

Prisma Browser DesktopPrisma Browser ExtensionPrisma Browser for Mobile
Full supportFull supportNo support
The Prisma Browser Extension supports tenant-based policy enforcement on Chrome, Edge, Firefox, and Safari. Tenant-based policy enforcement is not enforced within native mobile applications on iOS or Android.