Focus

New Features - Prisma Access Agent - 25.6.1


Granular Certificate Selection for Prisma Access Agent

Release Date: October 2025 | Last Updated: May 2026

Prisma Access Agent now provides granular certificate selection controls to address issues where the agent might select incorrect certificates for authentication, which leads to inaccurate User-ID™ mapping. This enhancement enables you to specify which certificate store to search and which Extended Key Usage (EKU) Object Identifiers (OIDs) to use when selecting certificates for authentication. By leveraging these granular controls, you can ensure that the agent uses the appropriate user certificate rather than defaulting to a machine certificate, which could otherwise map device identifiers instead of usernames to your policy rules.

You can configure the certificate lookup store to search exclusively in the user store, exclusively in the machine store, or to search the user store first and then fall back to the machine store if needed. This flexibility helps in scenarios where you want to enforce user-specific authentication or when you need to accommodate devices with certificates in different stores. Additionally, you can specify one or more EKU OIDs that must be present in certificates to ensure valid authentication, enabling you to filter certificates based on their intended purpose.

These settings are valuable in shared-device environments where you need to ensure proper user identification, or in organizations with strict security policies that require user-specific certificates for authentication. By enforcing the use of user certificates, you can maintain accurate user identity mapping throughout your security infrastructure, ensuring that your access controls and security policies work as intended.

LDAP Support for Prisma Access Agent in Panorama Managed Deployments

Release Date: October 2025 | Last Updated: May 2026

Prisma® Access Agent extends Lightweight Directory Access Protocol (LDAP) authentication support to Panorama® Managed Prisma Access and Next-Generation Firewall (NGFW) deployments, enabling you to leverage your existing GlobalProtect® Portal LDAP authentication infrastructure, eliminating the need to reconfigure authentication methods when migrating to Prisma Access Agent.

Similar to Strata Cloud Manager deployments, you can now configure the Prisma Access Agent in Panorama managed deployments to authenticate users against your existing directory services through the GlobalProtect Portal. This integration provides a seamless authentication experience for your users while maintaining your existing policies. The feature supports all standard LDAP configuration options, including Base Distinguished Name (DN), Bind DN, multiple LDAP servers, Secure Socket Layer/Transport Layer Security (SSL/TLS) secure connections, and server certificate verification for Secure Sockets Layer (SSL) sessions. You can also combine LDAP authentication with client certificate authentication using AND/OR logic to meet your specific security requirements.

Prisma Access Agent Support for macOS Tahoe and Windows 11 Version 25H2

Release Date: October 2025 | Last Updated: May 2026

You can now deploy Prisma® Access Agent on macOS Tahoe 26 and Windows 11 version 25H2 to extend secure access capabilities to users running the latest operating system versions. This expanded OS support ensures your organization maintains consistent security policy rules and remote access functionality as users upgrade to newer platform releases. You benefit from continued endpoint protection and secure connectivity when your workforce uses the latest macOS or Windows environments.

The additional OS compatibility addresses common deployment scenarios where users require access to corporate resources from recently updated devices. You can implement zero trust network access (ZTNA) policy rules across mixed environments without compatibility gaps that might otherwise force users to delay OS upgrades or create security exceptions.