Focus

New Features - Prisma Access Agent - 26.2.2


Android 16 Design Adoption for Prisma Access Agent

Release Date: July 2026 | Last Updated: July 2026

With the release of Android 16, Prisma® Access Agent for Android has been updated to align with current Android design standards. Your users can perform tasks including connecting to gateways, switching between locations for optimal performance, sharing diagnostic logs with administrators, and viewing connection statistics. The updated interface provides navigation patterns consistent with native Android applications while supporting gesture navigation across all Android device types including tablets and ChromeOS.

IPv6 Traffic Handling for Prisma Access Agent on Linux

Release Date: June 2026 | Last Updated: July 2026

Prisma® Access Agent now selectively blocks tunnel-routed IPv6 connections on Linux, eliminating the 20–30 second timeouts that occur when IPv6 traffic enters a tunnel that lacks IPv6 support. Modern applications establish an IPv4 connection in approximately 50–300 milliseconds, so you experience no noticeable delay.

You no longer need to disable IPv6 system-wide on Linux devices before installing the agent. The agent handles only the connections the tunnel cannot support. Direct-routed IPv6 traffic and all IPv6 traffic when the tunnel is disconnected continue to work normally. Modern browsers, including Chrome and Firefox, fall back to IPv4 automatically without requiring changes to your application configuration.

When you configure forwarding profile rules for IPv6 destinations on Linux endpoints, use destination-based criteria only, because application-based matching is not supported for IPv6 traffic on Linux. No gateway configuration is required; the feature is automatic on Linux endpoints running Prisma Access Agent 26.2.2 or later.

Learn about traffic routing behavior, application compatibility, and limitations in IPv6 Traffic Handling for Prisma Access Agent on Linux.

Prisma Access Agent Forwarding Profiles for Mobile Devices

Release Date: July 2026 | Last Updated: July 2026

Mobile devices used for work often require always-on security, but routing all traffic through the gateway can introduce latency that impacts application performance and raises privacy concerns when employees use corporate-owned or personally-owned devices for personal activities. Forwarding profiles now extend to iOS, Android, and ChromeOS devices running Prisma® Access Agent, offering a subset of the functionality available for desktop devices. You create forwarding rules that match traffic based on IP address destinations and configure connectivity options to send traffic through the gateway, direct to destination, or block it. This allows you to maintain always-on connectivity while excluding specific traffic to address performance concerns and meet privacy requirements including GDPR compliance. Rules will be consolidated top-down based on the destination interface to determine the access route for traffic forwarding.

SAML with Always-On Support for Prisma Access Agent on iOS

Release Date: July 2026 | Last Updated: July 2026

Enterprises increasingly require Always-On security combined with SAML authentication for comprehensive mobile device protection. Prisma Access Agent now extends SAML authentication support with Always-On connection to iOS devices. The support is available by default when you deploy an Always-On profile to your iOS endpoints.

When your users unlock their devices, they receive a notification to authenticate and connect through the embedded browser. The solution supports multi-factor authentication prompts during the authentication process. When user sessions expire, network access is automatically blocked until they re-authenticate. This capability maintains centralized identity management through SAML providers, extending the same security controls already available on Android devices to your iOS deployments.

Wildcard Support for Source Apps in Forwarding Profiles

Release Date: June 2026 | Last Updated: July 2026

You can now use wildcard patterns in Prisma® Access Agent Forwarding Profile source application paths to accommodate applications that install in dynamic locations. This feature addresses scenarios where application paths contain version numbers, usernames, or randomized identifiers that change during updates or vary across users. You can specify wildcards using the asterisk (*) character to replace single directory components in the path, enabling a single rule to match multiple path variations. This capability reduces administrative overhead when managing applications like Microsoft Teams that embed version numbers in their installation paths, or applications that install into user-specific directories. The feature provides flexibility for modern application deployment patterns across Windows and macOS environments.

Update:

Wildcard support for source application paths is now also available on Linux endpoints, starting in version 26.2.2. Linux endpoints now support the same wildcard syntax as macOS and Windows — you can use an asterisk (*) to replace a single directory component, allowing one rule to cover applications with version-specific or distribution-specific installation paths.

iOS 26 Design Adoption for Prisma Access Agent

Release Date: July 2026 | Last Updated: July 2026

Prisma® Access Agent for iOS has adopted iOS 26 design standards to align with the latest platform requirements. The updated interface uses iOS 26 control styles, navigation patterns, and animations to match current operating system conventions. Your users can connect to gateways, select locations, troubleshoot connections, and manage settings through the updated interface. The agent maintains existing functionality while adopting the visual and interaction standards introduced in iOS 26. This update ensures the interface remains consistent with platform expectations across iOS and iPadOS devices.