| Where Can I Use This? | What Do I Need? |
- Prisma Access (Managed by Strata Cloud Manager)
- Prisma Access (Managed by Panorama)
- NGFW (Managed by Panorama)
|
- Check the prerequisites for the deployment you're
using
- Prisma Access Agent 25.6 or earlier versions
- macOS 14 and later desktop devices
- Contact your Palo Alto Networks account representative to
activate the Prisma Access Agent feature
|
Create and deploy a configuration profile for Prisma Access Agents that defines
how the Prisma Access Agent is configured on managed macOS devices. For
example, you can set up the configuration profile to automatically load system
extensions to provide a seamless experience for users running the Prisma Access Agent to access the internet, SaaS applications, and private
applications and resources in your organization.
This configuration profile will automatically load the following
Prisma Access Agent extensions on a managed endpoint:
- PAA Network Extension (com.paloaltonetworks.pang.networkextension)
- PAA Security Extension (com.paloaltonetworks.pang.securityextension)
After you deploy the agent, you can run the
systemextensionsctl
list command on an endpoint to verify that the extensions have been
loaded. For example:
Endpoint DLP Considerations
If you plan to use
Endpoint DLP with
Prisma Access Agent, complete the following steps:
If you previously deployed other Palo Alto Networks apps such as GlobalProtect™
and Cortex® XDR® to your endpoints, when deploying the system extensions via
mobile device management (MDM) software, the configuration profiles for Prisma Access Agent and the other Palo Alto Networks apps must include the
Allowed System Extension and Removable
System Extension settings. If only one of the profiles has the
removable system extension, the uninstallation of Prisma Access Agent
won’t complete.
The following procedure is based on the Prisma Access Agent unified
configuration profile (V2_1).