Set Up Prisma Access Agent User Authentication
Focus
Focus
Prisma Access Agent

Set Up Prisma Access Agent User Authentication

Table of Contents

Set Up Prisma Access Agent User Authentication

Set up the authentication for Prisma Access Agent users.
Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Strata Cloud Manager)
  • Prisma Access (Managed by Panorama)
  • NGFW (Managed by Panorama)
  • Check the prerequisites for the deployment you're using
  • Contact your Palo Alto Networks account representative to activate the Prisma Access Agent feature
Set up user authentication so that only legitimate Prisma Access Agent users have access to your services and applications.
The first time a user connects to the Prisma Access Agent app, the user is prompted to authenticate to the server (also known as the Prisma Access Agent Manager or EPM). Once authenticated, the Prisma Access Agent receives the configuration from the server, which includes the list of gateways to which the app can connect, and optionally a client certificate for connecting to the gateways. After successfully downloading and caching the configuration, the app attempts to connect to one of the gateways specified in the configuration. Because these components provide access to your network resources and settings, they also require the end user to authenticate. The appropriate security level required on the gateways varies with the sensitivity of the resources that the gateway protects.
Prisma Access Agent provides the following authentication types:
  • SAML 2.0 or Client Certificate authentication through Cloud Identity Engine
    Prisma Access Agent supports the following combinations of SAML and Client Certificate authentication through Cloud Identity Engine:
    • SAML
    • Client Certificate
    • SAML or Client Certificate
    • SAML and Client Certificate
    Cloud Identity Engine provides both user identification and user authentication for mobile users.
  • LDAP authentication through the GlobalProtect™ portal
    LDAP authentication for Prisma Access Agent leverages your existing GlobalProtect portal LDAP authentication infrastructure, eliminating the need to reconfigure authentication methods when migrating to Prisma Access Agent. With LDAP authentication support, you can configure Prisma Access Agent to authenticate users against your existing directory services through the GlobalProtect portal, providing a smooth transition path for you to migrate existing deployments from GlobalProtect to Prisma Access Agent.
Be sure to set up user authentication before you complete the first Push Config.