New Features - Prisma Access Agent - 25.3
Customizable Prisma Access Agent Session Timeout Settings
Unexpected session timeouts and inactivity logouts can significantly disrupt user productivity and lead to increased helpdesk tickets. Prisma® Access Agent addresses this issue by introducing configurable notifications that alert users before their sessions expire or terminate due to inactivity. You can now set up timely warnings and custom messages to keep your users informed and provide them with the option to extend their sessions when needed.
You can customize sessions by setting their duration, scheduling logout notifications, and creating custom expiration messages. You can set the duration a user can stay logged in to a session, and also set the amount of time to wait before the agent session ends due to user inactivity. The ability to customize session timeouts and notifications helps balance user access needs with network security. It enables you to control session timeouts, keep users informed about their session status, and communicate important information.
Disable Prisma Access Agent with One-Time Password
To address the potential risks of end users disabling the Prisma® Access Agent, your users can now use a one-time password (OTP) system to securely disable the agent. With the OTP system, Prisma Access Agent can generate unique, single-use codes for agent disabling, enhancing security and administrative control. You can configure the OTP system on a per-user or per-user group basis, providing granular control over who can disable agents and when. When users enter the correct OTP, the agent verifies it locally and disables itself, ensuring functionality even in offline scenarios. This feature also improves auditing capabilities by logging all OTP-related activities, helping you track and monitor agent disabling events across your network. By implementing this OTP system, you can meet compliance requirements, align with industry standards, and provide a more secure and flexible solution for managing Prisma Access Agents.
Endpoint Insights for Prisma Access Agent
IT administrators and support teams often face challenges with limited visibility into endpoints, making it difficult to troubleshoot any access issues that arise from agent rollouts, upgrades, configuration changes, or changes to the endpoint environment. Prisma Access Agent addresses these challenges by collecting endpoint insights data that provides comprehensive endpoint visibility and troubleshooting data collection capabilities.
Prisma Access Agent simplifies troubleshooting endpoint access issues by automatically collecting diagnostic data. Understanding the endpoint insights can help you reduce the mean time to resolve (MTTR) issues by minimizing the need for human involvement when troubleshooting endpoint issues. Prisma Access Agent collects comprehensive data on the endpoint state and health, agent deployment and performance, and troubleshooting data periodically or based on critical triggers. This streamlines the process to collect and access the data necessary for troubleshooting endpoint issues, reducing downtime, and improving the overall reliability of Prisma Access Agent deployments.
Endpoint insights assist in troubleshooting various use cases, such as interoperability conflicts with third-party software, OS compatibility issues, and agent performance problems by collecting detailed information about the endpoints such as installed applications, agent details, and performance and troubleshooting data.
IPv6 Sinkholing for Prisma Access Agent
While the Prisma® Access Agent routes mobile user IPv4 traffic through a protected tunnel to Prisma Access, IPv6 traffic is conventionally sent to the local network adapter on an endpoint. Prisma Access offers the ability to enhance security for dual-stack endpoints by sinkholing IPv6 traffic.
By enabling IPv6 sinkholing, you can effectively mitigate risks associated with IPv6-based threats, thus reducing your overall attack surface. This feature is valuable in scenarios where you need to maintain a secure environment for mobile users accessing the internet. As endpoints can automatically fall back to IPv4 addresses, you can ensure a continuous and protected user experience without compromising on security. By implementing this capability, you strike an optimal balance between robust threat prevention and uninterrupted connectivity for your mobile workforce.
Mobile Support for Prisma Access Agent
Prisma Access Agent adds mobile support for Android OS, iOS, and iPadOS devices, enabling you to extend secure network access to your mobile workforce through a next-generation mobile access solution. You can deploy the agent to deliver consistent security protection and network access controls across all applications (browser and native apps), while maintaining visibility for your IT and security teams. The mobile agent integrates with your existing Prisma Access or Next-Generation Firewall (NGFW) infrastructure to provide secure connectivity for both internet and private app access, ensuring that mobile users receive the same level of protection as desktop endpoints.
You can leverage the mobile agent to support hybrid work environments where employees require secure access from various locations and network conditions. The agent simplifies your mobile security operations by eliminating the need for complex VPN configurations while providing secure tunnel establishment between mobile devices and your security infrastructure. You benefit from unified management capabilities that enable you to configure and monitor mobile agents through familiar administrative interfaces, reducing the complexity associated with managing separate mobile security solutions.
The mobile agent addresses the operational challenges of securing diverse mobile device fleets by providing consistent policy enforcement across different operating systems. You can maintain the same security posture and access controls that you apply to desktop endpoints, extending your organization's security perimeter to include mobile devices without compromising control.
Pre-Logon for Prisma Access Agent
To avoid delays in critical device updates and maintain security, you need a way to connect remote corporate-owned machines to the network before users log in. The pre-logon feature for Prisma® Access Agent addresses this challenge by establishing a secure device-level connection before user authentication occurs.
This feature improves IT productivity and enhances your overall security posture by ensuring all managed devices receive essential updates and configuration changes, regardless of the user's login status. You can now perform critical management tasks—such as applying group policies, installing software updates, and synchronizing roaming profiles—without waiting for a user to log in.
Pre-logon is designed to provide consistent connectivity for your managed devices across system restarts and sleep-wake cycles. By utilizing this capability, you significantly improve the management of your remote assets and enhance security by ensuring devices are properly configured and updated before users gain full network access.
Prisma Access Agent Captive Portal Support
Mobile users often struggle to connect securely when working from locations with captive portals, such as hotels, cafes, and airports. These captive portals require authentication before allowing internet access. Prisma® Access Agent automatically detects when a user has connected to a network with a captive portal and opens the captive portal authentication page in its embedded browser, enabling users to authenticate without bypassing security policies. This approach enhances security by containing the captive portal interaction within the controlled environment of the embedded browser, mitigating risks associated with external browser use.
By using captive portal support with Prisma Access Agent's embedded browser functionality, you ensure that your mobile workforce maintains secure access to corporate resources across diverse network environments. It prevents scenarios where employees are unable to access the internet or corporate resources due to undetected captive portals, while also addressing security concerns related to captive portal interactions. This solution significantly reduces connectivity-related support tickets, improves overall user productivity, and provides an integrated, secure experience for your remote and traveling employees while maintaining the stringent security standards your organization requires.
Prisma Access Agent Embedded Browser Support for SAML Authentication
Managing SAML authentication across various web browsers poses significant challenges for administrators, often resulting in a cumbersome user experience with annoying pop-ups and redirection issues between the access agent and browser.
The Prisma® Access Agent embedded browser addresses this issue by integrating a dedicated browser directly into the agent, providing your users with a consistent in-app experience for Prisma Access Agent logins, simplifying administration, and significantly enhancing security posture. By keeping the authentication process within the application, you eliminate the need for external browser interactions, reduce the risk of user confusion, and mitigate potential security vulnerabilities associated with browser redirections. This internal processing environment ensures strict adherence to conditional access policies, which also simplifies administrative overhead.
With support for various authentication methods and compatibility with existing Prisma Access Agent features, the embedded browser significantly improves both security and usability in your remote access infrastructure.
Seamless LDAP Authentication for Prisma Access Agent
Organizations transitioning to Prisma® Access Agent face challenges when their existing authentication infrastructure uses LDAP/LDAPS, as Prisma Access Agent previously only supported SAML and certificate authentication through Cloud Identity Engine (CIE). This can create significant adoption barriers, especially in regions where LDAP usage is prevalent. LDAP support for Prisma Access Agent addresses this challenge by enabling you to leverage your existing GlobalProtect® portal LDAP authentication infrastructure, eliminating the need to reconfigure authentication methods when migrating to Prisma Access Agent.
With LDAP authentication support, you can now configure your Prisma Access Agent to authenticate users against your existing directory services through the GlobalProtect portal. This integration provides a seamless authentication experience for your users while maintaining your existing security policies. The feature supports all standard LDAP configuration options, including Base DN, Bind DN, multiple LDAP servers, SSL/TLS secure connections, and server certificate verification for SSL sessions. You can also combine LDAP authentication with client certificate authentication using AND/OR logic to meet your specific security requirements.
The enhanced user experience includes support for saved user credentials, enabling seamless authentication across device states such as sleep-wake cycles, hibernation, and network transitions. When properly configured, users won't need to repeatedly enter their credentials after logging into their operating system.
By supporting LDAP authentication through the GlobalProtect portal, Prisma Access Agent provides you with a smoother migration path from GlobalProtect to Prisma Access Agent, preserving your authentication setup while enabling you to transition to a newer access agent. This feature is valuable for existing deployments where reconfiguring authentication methods would otherwise increase deployment complexity and time.
Transparent Proxy Support for Prisma Access Agent
Prisma® Access Agent now supports transparent proxy connections, offering always-on internet security and private app access for your mobile users. This feature enables seamless coexistence with third-party VPN agents, enhancing your organization's security posture. You can use it to secure all internet traffic from browser and nonbrowser apps, even when users are disconnected from the tunnel. The solution forwards internet traffic to Prisma Access, preventing users from bypassing Prisma Access.
You can support various scenarios including users connecting from home, branch offices, or public Wi-Fi. It's compatible with endpoints running third-party VPNs in full or split tunnel modes. The feature prevents conflicts on endpoints and offers admin controls to maintain smooth operation. You will find this useful for maintaining consistent security across diverse networks. It supports continuous trust verification for mobile users through device posture checks. By implementing this functionality, you can enforce security policies regardless of user location or connection method, strengthening your overall security stance and strengthening your overall security posture with always-on connectivity.