You can now route DNS traffic from Palo Alto Networks® Prisma Browser to the Advanced DNS Security Resolver using DNS-over-HTTPS (DoH), providing real-time DNS threat inspection and policy enforcement for all browser-based DNS activity without requiring traffic decryption or separate firewall infrastructure. This integration extends Advanced DNS Security Resolver protections to browser users who may not have a tunnel connection available.
When you enable this integration, the browser resolves DNS queries through the Advanced DNS Security Resolver instead of the system DNS client. The resolver inspects each query against your DNS Security profile policies and returns block or sinkhole responses for domains that match threat categories. Internal domains and private application domains configured in Prisma Browser are automatically excluded from Advanced DNS Security Resolver resolution and use the system DNS instead, ensuring internal resources remain accessible.
You configure the failure behavior to match your security requirements. In fail-open mode, the browser falls back to system DNS resolution if the resolver is unavailable, ensuring uninterrupted connectivity. In fail-close mode, DNS resolution is blocked entirely when the resolver is unavailable, preventing any queries from bypassing inspection. A predefined
connection source for
Prisma Browser appears automatically in the
Advanced DNS Security Resolver console, where you assign a DNS Security profile to define the inspection policies applied to browser DNS traffic.