Use the Prisma Agent App (Managed Devices)
Focus
Focus
Prisma Agent

Use the Prisma Agent App (Managed Devices)

Table of Contents

Use the Prisma Agent App (Managed Devices)

Use the Prisma Agent App Managed Devices for Android Endpoints.
Where Can I Use This?What Do I Need?
  • Prisma Agent
  • Android 10 and later versions
  • Internet access
If your Android endpoint is managed by a mobile device management (MDM) system, your administrator may have automatically pushed the Prisma Agent to your endpoint and configured the agent.
  1. Open the Prisma Agent app by tapping the PA Agent icon.
  2. The agent will connect based on the connect method configured by your Prisma Agent administrator. The Prisma Agent supports the following connect methods:
    • Always-On
      In an Always-On configuration, Prisma Agent automatically connects as soon as end users log in. You can optionally enable Lockdown Mode to enforce all network traffic through the Prisma Agent and block traffic that does not go through the Prisma Agent.
    • On-Demand
      In an on-demand configuration, end users must manually connect Prisma Agent through the application. Traffic is routed through the Prisma Agent app only after the end users initiate and establish the connection.
    • Per-App
      In a per-app configuration, you can specify the managed apps that can route traffic through Prisma Agent when connected. If using an allowlist, only the specified apps will be routed through Prisma Agent. If using a blocklist, all traffic will be routed through Prisma Agent except for the specified apps.
  3. If your agent is always-on, you'll receive a notification to authenticate with your identity provider.
    1. Tap the notification to proceed.
    2. Enter your organization credentials to authenticate to the app:
  4. If your agent is on-demand, manually connect to the agent.
    1. Connect by clicking the lock icon.
    2. Enter your organization credentials to authenticate to the app:
  5. After authentication is complete, the connection is established and the app displays the status as Connected.
  6. For Prisma Agents agents with on-demand or per-app configurations, tap Disconnect on the app when you no longer need to access resources through the Prisma Agent.
    For Prisma Agents with always-on configurations, you won't be able to disconnect the agent due to your organization's IT policy.
  7. If you connect to a network that requires captive portal authentication, such as public Wi-Fi at hotels, cafes, or airports, you will receive a notification.
    1. Tap on the notification to proceed.
    2. The captive portal login page will appear in the embedded browser. Enter your credentials or accept the terms of service as required by the network provider.