Prisma Browser for MSPs - Activation and Onboarding
Focus
Focus
Prisma Browser

Prisma Browser for MSPs - Activation and Onboarding

Table of Contents

Prisma Browser for MSPs - Activation and Onboarding

MSP Activation and On-boarding article
Where Can I Use This?What Do I Need?
  • Strata Multitenant Cloud Manager
  • Strata Cloud Manager
  • Activation link for your product
  • Standalone Prisma Browser License
  • Activation link for Prisma Browser
  • Strata Cloud Manager Pro License
  • CIE (Cloud Identity Engine) (Included, and spun up during activation)
  • Customer Support Portal Account
  • Identity & Access role: Multitenant Superuser or Superuser
The Prisma Browser for MSPs is only available to our MSSP partners managed service providers. To access this feature, you need to be a partner registered with the Nextwave Partner program. For more information, refer to the NextWave Partner Community. To access this feature, contact your account representative.
Prisma Browser for MSPs provides a unified, multi-tenant interface, enabling Managed Service Providers to efficiently deliver secure, browser-based access to their customers. This model is designed for scalability and operational efficiency, allowing MSPs to centralize license activation, deployment monitoring, and policy management across multiple customer environments.

Hierarchical Tenant Model

Prisma Browser for MSP utilizes a hierarchical tenant model to structure the management, licensing, and configuration inheritance across customer environments. This hierarchy is composed of two primary levels: the root tenant and the child tenants.

Root Tenant

The root tenant serves as the primary administrative container in the MSP hierarchy. It can be the MSP's own root tenant or a child tenant acting as a parent to other customers.
  • Licensing - This is the only place where the Prisma Browser license is activated. The license pool is automatically inherited by all associated child tenants, eliminating the need for separate activation at lower levels.
  • Central Administration - Administrators allocate license capacity, enforce shared or baseline security policies, and monitor the overall status of all associated child tenants.
  • Visibility - The root tenant’s dashboard provides a central view of deployment health, onboarding progress, and service performance across the entire group of managed customers.
  • Creation - Child tenants are created and managed directly from this root tenant via the MSP portal.

Child Tenant

Each child tenant represents an individual customer deployment, ensuring strict isolation and dedicated environments.
  • Isolation and Independence - child tenants operate as fully independent environments with dedicated users, devices, policy settings, security telemetry, and onboarding workflows. No customer can view or access another customer's data.
  • License Consumption - child tenants automatically consume licenses from the root tenant's license pool. If a child tenant is deleted, the licenses it consumed are automatically returned to the root tenant's available pool.
  • Management - While fully isolated from each other, child tenants remain manageable from the root tenant, ensuring MSPs can efficiently support multiple customers while upholding strong separation and privacy controls.

MSP Root Tenant Creation

This initial procedure establishes your MSP presence in Strata Cloud Manager and activates your master license. This is typically a one-time setup.

Step 1: Create the MSP Root Tenant

  1. Log into the Strata Cloud Manager.
  2. Create a root or child tenant that will act as the root tenant.
  3. Review the Prisma Browser Prerequisites before you activate the Prisma Browser.

Step 2: Activate the Prisma Browser Licence

  1. Activate the Standalone Prisma Browser license on the root tenant. Locate the activation "magic link" you received via email after purchasing the PAB Standalone SKU.
  2. Activate the Standalone Prisma Browser License on the root tenant. Click the link to initiate the activation workflow.
  3. Add child tenants to the tenant where you activated the Prisma Browser licences. Follow the on-screen prompts to claim the license against your MSP root tenant created in Step 1.
  4. Continue with Onboarding and Configuring the Prisma Browser. Remember that for Standalone licences, you only need to configure the following sections:
    1. Users
    2. Enforce SSO Applications
    3. Download and Distribute
    4. Browser Policy