Prisma Browser for Intune - Complete Deployment Guide
Focus
Focus
Prisma Browser

Prisma Browser for Intune - Complete Deployment Guide

Table of Contents

Prisma Browser for Intune - Complete Deployment Guide

.Prisma Browser for Intune Deployment Guide
Where Can I Use This?What Do I Need?
  • Microsoft Intune Administrator
  • Entra ID Directory Role:
    • Global Administrator
    • Privileged Administrator
    • Cloud Application Administrator
  • iOS Deployment
    • iOS/iPadOS devices (iOS 18.0 or newer)
    • Access to Apple App Store (for user installation) OR Apple Business Manager (for VPP deployment)
    • Devices enrolled in Intune (for MDM features; not required for MAM)
  • Android Deployment
    • Android devices (Android 12.0 or newer)
    • Access to Google Play Store (for user installation) OR Managed Google Play (for enterprise deployment)
    • Devices enrolled in Intune (for MDM features; not required for MAM)
  • License Requirements for all deployments
    • Users must be assigned an Intune license
    • Entra ID Premium (for Conditional Access features)
Prisma Browser for Intune offers seamless integration with Microsoft’s Mobile Device Management (MDM) and Mobile Application Management (MAM) frameworks. This allows IT teams to manage browser security policies and monitor user activity directly within the Microsoft Intune console, removing the need to navigate between multiple platforms.
Key Integration Benefits
  • Unified Policy Management: Manage all mobile security settings centrally through Entra ID and Intune, eliminating the need for separate policy configurations in the Prisma console.
  • Enhanced Security: Directly embed Intune security controls into the browser to safeguard corporate data across both iOS and Android devices.
  • Simplified Access Control: Facilitate the deployment of conditional access and establish Prisma as the required browser for managed applications.
  • Streamlined Administration: Gain comprehensive visibility into mobile web activity while preserving a standard user experience.
Deployment Use Case
This integration is ideal for organizations that rely on the Palo Alto Networks security stack but prefer centralized administration within the Microsoft ecosystem. It delivers enterprise-grade security for mobile browsing while simplifying the IT workflow.

Prisma Browser for Intune

Prisma Browser for Intune is specifically designed for:
  • Organizations using Microsoft Intune as their MDM or MAM solution.
  • Enhanced integration with Intune"s App Protection Policies (APP).
  • Deeper integration with Microsoft Entra ID and Conditional Access.
App Details
Key Differences Between Prisma Browser for Mobile and Prisma Browser for Intune
FeaturePrisma Browser for MobilePrisma Browser for Intune
MDM SupportAll MDM ProvidersOptimized for Microsoft Intune
App Protection PoliciesNot supportedFull Intune APP Integration
Conditional AccessBasic IdP basisEnhanced Entra ID integration
Android/iOS AppSingle AppSeparate "for Intune" app
Prisma Browser for Intune App

Use Cases

  1. Mobile Application Manager (MAM)
    • Default Browser Configuration: Configure Prisma Browser as the default for managed applications on unmanaged personal devices to ensure consistent security and compliance across web access.
    • Unified Policy Management: Extend existing Intune App Protection Policies to Prisma Browser for Intune. This eliminates the need for browser-specific policies, allowing centralized management of data protection, conditional access, and compliance rules directly within Intune.
    • Secure Browsing: Secure web traffic by tunneling it through Prisma Access, ensuring all corporate browsing requests remain protected, secure, and compliant.
  2. Mobile Device Management (MDM)
    • Single Browser Enforcement: Building on MAM capabilities, MDM allows organizations to designate Prisma Browser for Intune as the exclusive browser for corporate-managed devices. This ensures all web traffic is routed through a secure, controlled environment, guaranteeing full policy enforcement.
      This integration streamlines administration by centralizing policy management within Intune, reducing overhead while maintaining consistent security and a seamless user experience across devices.

Step 1 - Grant Prisma Browser Permissions in Microsoft Intune

This section outlines the steps required for a Microsoft Entra ID Administrator to authorize and provision the verified third-party mobile application, Prisma Browser (Palo Alto Networks Inc.), within the organization's tenant.
App Details
  • App Name: Prisma Browser
  • Publisher: Palo Alto Networks Inc. (Verified)
  • Application (Client) ID: edc4bc6b-9e08-4c12-91dc-2a3421facd71
Prerequisites
To complete this process, you must have an account with one of the Entra ID directory roles mentioned earlier.

Provisioning Process: Tenant-Wide Admin Consent

Because Prisma Browser is a third-party application, it must be installed as an "Enterprise Application" (Service Principal) in your tenant before users can authenticate it. We will do this using a direct Admin Consent URL.
  1. Initiate the Consent Request
    1. open a web browser.
      Incognito or InPrivate window is recommended to avoid caching issues with existing sessions.
    2. Copy and paste the following Microsoft Admin Consent URL into your address bar. adminconsent?client_id=edc4bc6b-9e08-4c12-91dc-2a3421facd71

Step 2 - Deploy Prisma Browser

2.1 Deploy Prisma Browser for Intune on iOS.
Microsoft Intune is a cloud-based endpoint management solution that can be used to deploy Prisma Browser onto iOS mobile devices.
Add Prisma Browser for Intune App to Microsoft Intune.
  1. Launch Microsoft Intune Admin Center.
  2. Navigate to Apps > All apps, and click Create.
  3. .
  4. From the App Type dropdown, select iOS store app.
  5. Click Search the App Store and search for Prisma Browser for Intune.
  1. Choose the Prisma Browser app and click Select.
  2. The App information page is displayed - review the details.
  3. Click Next to display the Assignments page.
    Configure App Assignments
    Define the relevant group assignments for the app that fit your enrollment strategy:
    1. Select the appropriate Assignment Type and target groups.
    2. Click Next to display the Review + Create page.
    3. Review the App Summary and click Create to add the app to Intune.
    User Installation Options
    If the Assignment Type is set as not required, users will need to manually download Prisma Browser using one of the following options:
    Option 1: Intune Company Portal
      1. Sign in to the Intune Company Portal app with a user who is part of the assigned group.
      2. Select the Prisma Browser app.
      3. Click Install.
    Add Prisma Browser for Intune to Microsoft Intune.
      1. Launch Microsoft Intune Admin Center.
      2. Navigate to Apps > All apps, and click Add.
      3. From the App Type dropdown, select Android store app.
    1. Click Next to display the Assignments page.

Step 3 - Configure App Protection Policies

The Intune SDK integrated into Prisma Browser for Intune requires an App Protection Policy (APP) assignment as part of its mandatory initialization process. Upon application launch, the SDK verifies the assigned APP and applies the relevant security controls. This is a mandatory step for the application to complete enrollment and function as intended. Organizations must assign at least one APP policy to Prisma Browser for Intune before users can access the application.
APPs are optional Intune policies that apply app-level controls to help protect organizational data within supported mobile applications. They can enforce requirements such as work credentials or PIN access, restrict data transfer between apps, and prevent data loss without requiring full device enrollment. Organizations may choose to utilize these policies when additional protection for corporate data is required, particularly in bring-your-own-device (BYOD) environments.
Configuration Steps:
  1. Navigate to Apps within Intune console.
  2. Select Protection under the Manage Apps menu.
  3. Click +Create and select your platform (iOS/iPadOS or Android) from the drop-down.
    1. On the Basics page:
      • Name your app protection policy (e.g., "Prisma Browser for Intune - Data Protection - iOS").….. .
      • Provide a description.
      • Click Next to continue.
      1. On the Apps page:
        • Click + Select public apps.
        • Search for and select Prisma Browser for Intune .
        • Click Next
        Currently, Prisma Browser for Intune does not appear in the public app list (common in Apple Business Manager or Managed Google Play deployments). Adding the app to the public list is in the process. Use the custom app option instead and search using:
        • ….….….….….….….….….….….
        • iOS: com.talon-sec.work.ios.intune
        • Android: com.talonsec.intune.talon
      1. On the Data Protection page:
        • Configure data loss prevention policies (e.g., restrict copy/paste, prevent screenshots).
        • Click Next.
      1. On the Access requirements page:
        • Configure access policies (e.g., require PIN, biometric authentication).
        • Click Next.
      1. On the Conditional launch page:
        • Configure any applicable conditional launch settings (e.g., block access if device is jailbroken).
        • Click Next.
      1. On the Assignments page:
        • Assign the app protection policy to users or groups based on your company policies.
        • Click Next.
    2. Review the policy's settings and assignments, then click Create to complete.
    3. Repeat this process for the remaining operating system (if you need to configure both iOS and Android).
    Example Policy Configuration:
    For a typical BYOD deployment, consider these settings:
    • Data Protection: Restrict cut/copy/paste to managed apps only.
    • Access Requirements: Require PIN (minimum 4 digits) or biometric authentication.
    • Conditional Launch: Block access if device is jailbroken/rooted.
    • Assignments: Target all users or specific groups requiring mobile web access.

Step 4 - Configure SSO Extension for Seamless Authentication (iOS only)

The Microsoft Enterprise SSO plug-in provides single sign-on (SSO) capabilities to Prisma Browser for Intune, enabling seamless authentication to corporate web resources that use Microsoft Entra ID for authentication.
Prerequisites
  • Microsoft Intune Admin Access — Administrator privileges in Microsoft Intune.
  • Device Requirements — iOS/iPadOS devices (iOS 13.0 or newer) enrolled in Intune.
  • Microsoft Authenticator App — Must be installed on the device.
  • Prisma Browser for Intune — Must be deployed to target devices (see Step 2).
Create a Single Sign-On (SSO) Configuration Profile
  1. Launch Microsoft Intune and Create Profile
    1. Open the Microsoft Intune Admin Center (https://intune.microsoft.com
    2. Navigate to Devices > Configuration profiles.
    3. Click + Create profile.
  2. Define Profile Basics
    FieldValue
    PlatformiOS/iPadOS
    Profile TypeTemplates
    TemplateDevice Features
    • Click Create to Proceed.
  3. Enter Profile Name
    1. Enter a descriptive name (e.g., "Prisma Browser SSO - iOS/iPadOS").
    2. Click Next.
  4. Configure SSO App Extension
    1. Select Single sign-on app extension.
    2. Set SSO app extension type to Microsoft Entra ID.
    3. Set Enable shared device mode to Not configured.
  5. Add Extension Configuration Data
    In the Additional configuration section, add these key-value pairs:
    KeyType Value
    AppPrefixAllowListStringcom.apple., com.microsoft., com.talon-sec.work.ios
    browser_sso_interaction_enabledInteger1
    disable_explicit_app_promptInteger1
    Enable_SSO_On_All_ManagedAppsInteger1
    Click + Add for each entry.
  6. Assign Profile to Groups
    1. Click Next to proceed to Assignments.
    2. Click + Add groups and select target user or device groups.
    3. Click Select to confirm.
  7. Review and Create
    1. Click Next to review all settings.
    2. Click Create to deploy the SSO configuration profile.

Validation and Testing

After configuring Prisma Browser for Intune, validate the deployment to ensure everything is working correctly.
Validate App Deployment
For iOS:
  1. Ensure Prisma Browser for Intune is available in the Intune Company Portal or App Store (for VPP deployments).
  2. Test the installation on a few devices before proceeding.
  3. Confirm users can launch the app and see the login screen.
For Android:
  1. Ensure Prisma Browser for Intune is available in Managed Google Play
  2. Test the installation on a few devices before proceeding.
  3. Confirm users can launch the app and see the login screen.
  4. Verify the correct app (Prisma Browser for Intune, not standard Prisma Browser) is installed.…..
Validate Entra ID Authentication
  1. Launch Prisma Browser for Intune on a test device.
  2. Attempt to sign in with Entra ID credentials.
  3. Verify successful authentication and access to the browser.
  4. Confirm user can browse to web resources.….….….….….….….….….….….….….….….….….….….….….….…..
Verify Permissions in Azure
  1. In Microsoft Entra Admin Center, navigate to Enterprise Applications.
  2. Search for Prisma Browser.
  3. Select the application and go to Permissions.
  4. Verify all required API permissions show as Granted for [Your Tenant].

Verify Single Sign-On (SSO) Configuration Profile Deployment

On Intune Console
  1. Navigate to Devices > Configuration profiles.
  2. Select your SSO profile and click Device and user check-in status.
  3. Confirm target devices show Compliant status.
On iOS Device
  1. Open Settings > General > VPN & Device Management.
  2. Verify the SSO configuration profile appears and shows Verified.
Test SSO Authentication
  1. Launch Prisma Browser for Intune on a test device.
  2. Navigate to a corporate web resource using Entra ID authentication.
  3. Verify automatic authentication without login prompts.
  4. Test multiple resources to confirm seamless SSO experience.

Troubleshooting

Authentication & Enrollment Errors
Click View Intune diagnostics.
Error: Status Code 225 - "User Not Targeted with MAM Policy"
What This Error Means: The user's account is not assigned a Mobile Application Management (MAM) policy in Intune. The app successfully authenticates with Entra ID, but Intune rejects the enrollment because there's no policy targeting this user.
Where You'll See It:
Intune logs show: CMAROperationScheduler: Enrollment failed with status code 225.
Diagnostic info shows account in RegisteredAccountsNotTargeted list.
User sees: "Your organization requires that you have an Intune policy to access data for this account"User sees: "Your organization requires that you have an Intune policy to access data for this account".
Root Cause: This is a Microsoft Intune or Microsoft Entra ID configuration issue rather than a Prisma Browser problem. The application is functioning correctly, but Intune is rejecting the enrollment request.
What Should Be Done:
Create or Modify a MAM Policy in Intune:
  1. Go to Microsoft Intune Admin Center and create an App Protection Policy as explained above.
  2. Ensure Prisma Browser for Intune is included in the policy.
  3. Ensure the policy is set to Required or Available (not excluded).
  4. Confirm the user has an active Intune license.
  5. Check that the user is in the correct Entra ID security groups for policy targeting.
Verify Policy Deployment:
  1. Wait 5-10 minutes for policy sync to the device.
  2. Have the user close and reopen Prisma Browser for Intune.
  3. The app should now enroll successfully.
What NOT to Do:
❌ Don't reinstall the app
❌ Don't reset the device
❌ Do not modify Prisma Browser settings
❌ Do not change Microsoft Entra ID authentication settings
  • Verification: Once the policy is assigned, check the diagnostic info in the app. The account should move from RegisteredAccountsNotTargeted to MAMEnrolledUsers.
    App Will Not Install
    iOS:
    • Verify device meets minimum iOS requirements (iOS 18.0+).
    • Check VPP license availability (if using Apple Business Manager).
    • Verify MDM communication between device and Intune.
    • Ensure device is enrolled in Intune (for required deployments).
    Android:
    • Verify device meets minimum Android requirements (Android 12.0+)
    • Check Managed Google Play is enabled.
    • Verify work profile is configured (for Work Profile deployments).
    • Ensure you're installing Prisma Browser for Intune, not the standard app.
Sign-In Issues
  • Verify user is in directory sync scope.
  • Check whether the authentication profile supports mobile devices.
  • Verify network connectivity to authentication endpoints.….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….….…....
  • Check for MFA/conditional access policies blocking mobile.
  • Ensure Microsoft Entra ID permissions have been granted (see "Grant Permissions" section).
App Crashes or Doesn't Work
  • Verify OS version meets requirements (iOS 18.0+ or Android 12.0+).
  • Check for jailbreak/root detection triggers.
  • Clear app data and reinstall.
  • Check for conflicting VPN/security apps.
Permissions Issues
  • Verify all required permissions have been granted in Entra ID Enterprise Applications.
  • Check that the Prisma Browser Enterprise Application appears in your Microsoft Entra ID tenant.
  • Ensure admin consent has been granted (not just user consent).
  • Review the permissions list to ensure all required Graph API permissions are granted.

Enforcing Login with Prisma Browser (Optional)

To maximize security, you can create a Microsoft Entra Conditional Access policy that restricts access to the Prisma Browser app. Specifically, you can enforce that users may only log in if they are using the Intune-managed version of Prisma Browser AND their device is fully managed and compliant.
Step-by-Step Policy Configuration
  1. Log in to the Microsoft Entra Admin Center.
  2. Navigate to Conditional Access > Policies.
  3. Click New policy and give it a descriptive name (e.g., "Require Compliant Device & App Protection for Prisma Browser").
  4. Assignments > Users:
  • Under Include, select the users or target groups.
  1. Target resources > Resources (formerly cloud apps):
  • Under Include, choose Select resources > Select specific resources.
  • Search for and select CIE Enterprise app
    Conditions > Device platforms:
    • Set Configure to Yes.
    • Under Include, select Android and iOS.
    • Click Done.
    Access controls > Grant:
    • Select Grant access.
    • Check Require device to be marked as compliant (Ensures the device is managed by Intune and meets your corporate security baselines).
    • Under For multiple controls, select Require all the selected controls.
    • Click Select.
Enable Policy:
  • It is highly recommended to set the policy to Report-only first to monitor its impact.
  • Once you have verified via the Entra sign-in logs that legitimate user logins are passing the conditions, change the toggle to On.
  • Click Create or Save

Restricting SaaS Applications to Prisma Browser Only (Optional)

In addition to enforcing login to Prisma Browser itself, you can restrict access to specific SaaS applications — such as SharePoint, OneDrive, or the entire Office 365 suite — so they can only be accessed via Prisma Browser for Intune on mobile devices.
This is useful when organizations want to ensure that corporate resources are only accessed through a managed, secure browser and not through Safari, Chrome, or other unmanaged browsers.
How It Works
On Intune-managed iOS and Android devices, Prisma Browser for Intune can locate and present the device management certificate installed by Intune. This certificate proves to Entra ID that the device is compliant with your organization's security baselines.
Other browsers (Safari, Chrome, Firefox, etc.) cannot access this certificate—even on the same managed device. When a Conditional Access policy requires a compliant device, these browsers will fail the compliance check and be blocked.
Note: Native O365 apps (OneDrive, Outlook, Teams) are unaffected by this configuration. These apps have their own Intune SDK integration and can independently prove device compliance. Only browser-based access is restricted to Prisma Browser.

Use Case Example

A customer wants to ensure SharePoint and other O365 web apps can only be accessed from Prisma Browser for Intune on mobile — and not from Safari or any other browser — without having to whitelist Auth Proxy IPs (which could inadvertently block native O365 apps).

Step-by-Step Policy Configuration

  1. Log in to the Microsoft Entra Admin Center
  2. Navigate to Protection > Conditional Access > Policies
  3. Click New policy and give it a descriptive name (e.g., "Restrict O365 Browser Access to Prisma Browser on Mobile")
Screenshot Placeholder: [Conditional Access new policy screen]
  1. Assignments > Users:
    • Under Include, select the users or target groups that should be restricted
Screenshot Placeholder: [User assignments in Conditional Access]
  1. Target resources > Cloud apps:
    • Under Include, choose Select apps
    • Search for and select the target applications (e.g., Office 365, SharePoint Online, Exchange Online)
  2. Tip: Selecting "Office 365" covers SharePoint, OneDrive, Exchange, and Teams web access in a single selection. Alternatively, select individual apps for more granular control.
Screenshot Placeholder: [Cloud apps selection showing Office 365]
  1. Conditions > Device platforms:
    • Set Configure to Yes
    • Under Include, select Android and iOS
    • Click Done
Screenshot Placeholder: [Device platforms configuration]
  1. Conditions > Client apps:
    • Set Configure to Yes
    • Check Browser only (uncheck Mobile apps and desktop clients)
    • Click Done
  2. Important: Selecting only "Browser" ensures this policy applies to web access. Native O365 mobile apps (Outlook, Teams, OneDrive) use the "Mobile apps and desktop clients" category and will not be affected.
Screenshot Placeholder: [Client apps configuration showing Browser selected]
  1. Access controls > Grant:
    • Select Grant access
    • Check Require device to be marked as compliant
    • Under For multiple controls, select Require all the selected controls
    • Click Select
Screenshot Placeholder: [Grant controls showing device compliance requirement]
  1. Enable policy:
    • Set the policy to Report-only first to monitor its impact
    • Once verified via Entra sign-in logs, change the toggle to On
    • Click Create or Save
    Screenshot Placeholder: [Enable policy toggle]
Why This Blocks Safari But Allows Prisma Browser
BrowserAccess device certificateCompliance check resultAccess
Prisma Browser for Intune✅ YesCompliant✅ Allowed
Safari❌ NoNon-compliant❌ Blocked
Chrome❌ NoNon-compliant❌ Blocked
Other Browsers❌ NoNon-compliant❌ Blocked
Native O365 apps (Outlook, Teams, OneDrive)✅ Yes (own SDK)Compliant✅ Allowed
Validation
After creating the Conditional Access policy:
  1. Monitor the policy in Report-only mode for at least 24-48 hours
  2. Review sign-in logs in Azure AD > Sign-ins to verify:
    • Prisma Browser for Intune access to O365 apps → Success
    • Safari access to O365 apps → Blocked (device compliance)
    • Native O365 apps (Outlook, Teams) → Unaffected
  3. Look for any unexpected blocks (e.g., legitimate apps being denied)
  4. Once confident, switch the policy to On
Testing Checklist
  • Open SharePoint in Prisma Browser for Intune → Should load successfully
  • Open SharePoint in Safari → Should be blocked with a compliance error
  • Open SharePoint in Chrome → Should be blocked with a compliance error
  • Open OneDrive native app → Should work normally (not affected by browser policy)
  • Open Outlook native app → Should work normally (not affected by browser policy)
Limitations
  • Managed devices only: This approach requires devices to be enrolled in Intune. It does not apply to unmanaged BYOD devices using MAM-only.
  • No IP whitelisting needed: This avoids the pitfalls of using PB Auth Proxy IPs in Trusted Locations, which could block native apps.
  • WebKit limitation: On iOS, the "Require app protection policy" grant control does not work for PB for Intune because WebKit-based rendering does not carry the Intune SDK context. Use "Require device to be marked as compliant" instead.
Combining with Prisma Browser Login Enforcement
For maximum security, combine this policy with the Enforcing Login with Prisma Browser policy above. Together, they ensure:
  1. Users can only log into Prisma Browser from compliant devices (login enforcement)
  2. Corporate SaaS apps can only be accessed via Prisma Browser on mobile (app access enforcement)

Understanding the MDM Key: Device Classification and Policy Differentiation

What is the MDM Key?

The MDM key is a unique configuration value that administrators generate in the Prisma Browser Management Console (SCM) and send to the device via the MDM console using the app configuration policy. This aims to distinguish between MDM-managed devices and unmanaged devices. This mechanism works with any MDM solution (Microsoft Intune, Jamf, VMware Workspace ONE, etc.).

When Should You Use the MDM Key?

Use the MDM key when you need to apply different security policies to managed vs. unmanaged devices within the same organization. Scenario Example:
  • Managed Devices: Apply lenient policies (device is fully controlled by MDM)
  • Unmanaged Devices: Apply stricter policies (device is not managed)

Why Can't This Be Done on the Intune Console Side?

Intune's App Protection Policies (APP) are designed to apply uniformly to all users and devices within a policy assignment group. Intune cannot natively distinguish between MDM-managed and MAM-only devices within the same policy assignment.
Here's why:
  1. Policy Assignment Limitation: When you assign an App Protection Policy in Intune, it applies to all users in that group regardless of their device's management status. There's no built-in conditional logic to say "apply Policy A to MDM devices and Policy B to unmanaged devices."
  2. Device Context Unavailable: Intune's APP framework doesn't expose the device's MDM enrollment status to the policy engine in a way that allows conditional policy application within a single policy assignment.
  3. Application-Level Decision Required: The only way to differentiate policies based on MDM status is to pass this information directly to the application (Prisma Browser) so it can make its own policy decisions at runtime.

Getting Help

If you encounter any issues or have questions that aren't covered in this guide:

Additional Configuration Guides

The following configuration guides apply to both Prisma Browser and Prisma Browser for Intune: