New Features - Prisma Agent - 26.3
Advanced Internal Host Detection for Prisma Agent
To protect against attackers who spoof reverse DNS responses to bypass tunnel enforcement, Prisma® Agent now validates the internal gateway's TLS certificate as part of internal host detection.
To strengthen the security of network detection, the agent now adds certificate-based validation of the internal gateway after the reverse DNS lookup succeeds. Because the gateway's identity is cryptographically bound to its certificate, this additional step provides stronger assurance that the endpoint is genuinely on the internal network before the tunnel is suppressed.
This behavior is automatic. No additional configuration is required — if you have Internal Host Detection and internal gateways configured in Agent Settings, advanced internal host detection activates automatically. If you have Internal Host Detection configured without internal gateways, the agent continues to use only the reverse DNS lookup.
This feature applies only to the Internal Host Detection configuration in Agent Settings. You enable advanced internal host detection by configuring Internal Host Detection and internal gateways in Agent Settings.
Jamf MDM Posture Checks for Prisma Agent on macOS
If your organization uses Jamf to manage macOS devices, you can now enforce MDM compliance checks for Prisma® Agent tunnel authorization, extending the same compliance-based access control that Microsoft Intune provides for Windows devices to your macOS fleet.
You configure the Jamf integration in your MDM integration settings by providing your Jamf instance Host URL, a client ID, and a client secret. The Endpoint Manager polls Jamf at configurable intervals to sync device compliance status and performs real-time queries when a device is not found in its cache or shows as non-compliant. Devices that are not enrolled in Jamf or fail compliance checks are blocked from establishing a tunnel. If Endpoint Manager detects that a device is out of compliance at the time of polling, any active tunnels are torn down and the user is notified.
Multi-Region Redundancy for Prisma Agent
Prisma® Agent now maintains secure connections and enforces security policies automatically during Endpoint Manager outages, eliminating disruptions caused by a cloud region failure.
Endpoint Manager now runs simultaneously across multiple geographic regions. If a region becomes unavailable, traffic routes automatically to a healthy region within minutes — your users stay connected, policies stay enforced, and application access through Prisma Access gateways continues without interruption. No manual steps are required during or after the transition.
This multi-region design also improves resilience beyond regional outages. If agents lose all cloud connectivity — for example, at a remote site with an extended network outage — Prisma Agent enforces the last cached security policy for up to 7 days, so users can continue working safely without re-authenticating. When connectivity returns, agents pace their reconnection automatically to avoid overwhelming the service.
Staged upgrade rollouts resume automatically after service restoration, and regional failovers respect your tenant's data residency configuration, so traffic stays within its designated geographic boundary during failover.
Prisma Agent Service Continuity describes full agent behavior during outages, including how to manage configuration commits and rollouts after a failover.
Preferred Gateway Selection for Prisma Agent
Prisma® Agent automatically selects the best-performing gateway for users through Best Location — and now users also have the flexibility to pin a specific location using preferred gateway selection, giving them consistent connectivity to the gateway that works best for their needs. Users set their preferred gateway by selecting a location from the Location drop-down; a star icon appears next to the selected location to indicate it is pinned. The agent then reconnects to that location after network changes, sleep/wake cycles, reboots, and other external factors such as WebSocket connection issues and token expiry — without requiring users to reselect it each time. To return to automatic selection, users choose Best Location, which clears the preferred gateway. This feature is available on Windows and macOS endpoints.
Self-Healing for Prisma Agent Connectivity Issues
Prisma® Agent now includes self-healing, which automatically applies remediation steps when a user reports a connectivity problem — helping users get back online faster and reducing the help desk tickets that unresolved connectivity issues generate.
When a user selects Report An Issue from the agent, the agent immediately applies local actions to restore the connection. At the same time, it collects and uploads the user's diagnostics for AI-powered analysis. Based on the specific errors identified, the system can instruct the agent to apply additional remediation steps. The user's connection may be temporarily interrupted during this process — no action is required.
After remediation completes, a dialog prompts users to indicate whether the fix resolved the issue. If the issue persists, the uploaded diagnostics remain available in Endpoint Management for your review.
Self-healing runs automatically — no additional steps are required from users beyond reporting the issue. It is available on Windows and macOS desktop devices. You enable self-healing from the Strata Cloud Manager agent settings, independently of other Endpoint Insights features.
To learn more, see Self-Healing for Prisma Agent.