How does account protection work
Account
Protection introduces an additional security layer for unmanaged
services by enhancing password management through the
Protected Access
Broker. The process is as follows:
- Password creation / reset via Protected Access Broker:
- Users must create or reset their passwords exclusively through
the Protected Access Broker.
- Without resetting the password via PAB, users can’t log in to
the application through the enterprise browser.
- Secure password generation:
- Prisma Browser employs a proprietary algorithm to generate a
secure password by combining:
- User-Selected Password: A password chosen by the
user, which is never stored in PAB.
- Secret Token: A unique, system-generated token
created by Prisma Browser, which is not disclosed to
the user.
- Password Swapping:
- PAB replaces the user-selected password with the combined secure
password.
- The combined password is then set as the new application
password during the password reset process.
Key Benefits - Users retain knowledge only of their selected password, while the Prisma Browser securely stores and appends the secret token
during authentication.
- On subsequent logins, Prisma Browser appends its secure token to the
user password, ensuring authentication success.
- Access Restriction: Logins from non-enterprise browsers are
blocked because the secure token is absent, ensuring that access is
limited to the enterprise browser environment.§
Administrative Control
You can enforce Prisma Browser policy rules, including visibility and security measures, for unmanaged,
third-party, and non-SSO-enabled services.
- Supported Login Methods: Only password-based
authentication methods are supported.
- Password Reset Requirement: The application must support
resetting user passwords before login (e.g., via a "Forgot Password"
feature).
- Shared Account Handling: For shared accounts, the same secure
token is applied for all users. This configuration must be explicitly
selected when enabling Account Protection for such applications.
This process ensures stronger security for unmanaged services while
maintaining usability and control.