Prisma Access Browser
Deploy the Prisma Access Browser via MDM
Table of Contents
Expand All
|
Collapse All
Prisma Access Browser Docs
Deploy the Prisma Access Browser via MDM
Learn about deployment methods for the Prisma Access Secure Enterprise Browser (Prisma Access Browser)
based on your organization’s policies and preferences. You can use self-service, MSI
installer, Jamf, or Intune.
| Where Can I Use This? | What Do I Need? |
|---|---|
|
|
You can choose from a variety of deployment methods for the Prisma Access Browser based on your organization’s policies and preferences.
Select the method that you prefer for deployment:
Deploy Prisma Access Browser Using Jamf
Jamf is a comprehensive management system for Apple macOS and iOS
devices. With Jamf, you can proactively manage the entire lifecycle of Apple
devices. This includes deploying and maintaining software, responding to
security threats, distributing settings, and analyzing inventory data.
Deploying the Prisma Access Browser using Jamf is easy - just follow these 2
steps.
- Open the Jamf Dashboard and select Settings.
- Select Computer ManagementScripts.On the Scripts page, select New.On the New Script page, on the General tab, enter the Display Name - a name for the script. Use any name that meets your organizational requirements.Select the Script tab.
- Download and edit the Installomator script.
- Locate the line: DEBUG=1, and change it to: DEBUG=0..
- Locate the label: prism9. Enter
the following script before this label:.pabrowser) name="Prisma Access Browser" type="dmg" if [[ $(arch) != "i386" ]]; then printlog "Architecture: arm64 (not i386)" downloadURL=$(curl -s https://bfe078e7921507bb.talon-sec.com/sparkle/PAB/stable-a64/appcast.xml | grep -Eo 'url="(.*)"' | cut -d '"' -f2 | tail -n1) appNewVersion=$(curl -s https://bfe078e7921507bb.talon-sec.com/sparkle/PAB/stable-a64/appcast.xml | grep -Eo 'sparkle:shortVersionString="(.*)"' | cut -d '"' -f2 | tail -n1) else printlog "Architecture: i386" downloadURL=$(curl -s https://bfe078e7921507bb.talon-sec.com/sparkle/PAB/stable/appcast.xml | grep -Eo 'url="(.*)"' | cut -d '"' -f2 | tail -n1) appNewVersion=$(curl -s https://bfe078e7921507bb.talon-sec.com/sparkle/PAB/stable/appcast.xml | grep -Eo 'sparkle:shortVersionString="(.*)"' | cut -d '"' -f2 | tail -n1) fi expectedTeamID="XZMH593AYG" ;;
- Click the Options tab. Under Parameter 4, enter the Application name. Select Save.
- The script is saved; you can now create a new Policy.
Create the Policy.- In the Jamf Dashboard, select ComputersPoliciesNew.On the Policies page, select New.On the New Policy page, enter the Display Name for the policy.Select Scripts.In the Configure Scripts field, click Configure.On the New Policy page, select the Script and click Add.In the Parameter Values section, select the Application Name field, and enter pabrowser.Save.The Script is added to the policy.
Deploy Prisma Access Browser Using Intune
Learn how to deploy Prisma Access Secure Enterprise Browser (Prisma Access Browser) using Intune.Microsoft Intune is a cloud-based endpoint management solution. It manages user access to organizational resources and simplifies app and device management across your many devices, including mobile devices, desktop computers, and virtual endpoints.- Open the Microsoft Intune Admin Center.Select AppsAll apps.Click + Add.In the Select app type window, select Line-of-business app.Click Select.In the App information step, click Select app package file.In the App package file window, browse to the MSI installation file, named PrismaAccessBrowserSetup.msi.Click Ok.Enter all the needed properties.
- Enter a name for the app. This will be visible in the Intune list and in the Company Portal.
- Provide a brief description of the app and its benefits for users. This description will be available in the Company Portal, where you can use rich text formatting to enhance it.
- Enter the name of the app’s publisher, which appears in the Company Portal.
- App install context – Select the Device.
- Show this as a featured app in the Company Portal – we recommend that you select Yes so that it will be easier for your users to find.
- Select the appropriate Logo for the application.
Click Next.Select the Assignments for this app.- For Available for enrolled devices, select Add group, and select the required Entra groups assigned to the application.
- If you select Add all users, then the Entra assignment will include all Entra users in your organization.
Click Next.Review all the settings and click Create to create the new app, or Previous to make changes.Creating the app might take a few additional minutes. The application will be available for use after this step.Set Prisma Access Browser Mobile as the Default Browser for Intune-managed Apps
If you are using Intune to manage your deployment, you can set Prisma Access Browser Mobile as the default browser. Intune empowers you to set a default browser for organization-managed apps. This can be applied globally through App Protection Policies, or selectively for specific, critical applications. This is particularly relevant for mobile devices (iOS and Android), as they are often employee-owned. However, enforcing a company browser as the default for all apps might raise employee concerns.This requires an Intune Plan 1 license.- Browse to the Intune Admin Portal → App Protection Policies → Select the policy you want to modify or create.At the Data Protection step, select "Restrict web content transfer with other apps", and enter Unmanaged browser(Optional) For iOS devices: In the Unmanaged browser protocol field, enter pab://.This requires Prisma Access Browser iOS version 1.4046 or later.(Optional) For Android devices:
- In the Unmanaged Browser ID field, enter com.talonsec.talon.In the Unmanaged Browser Name field, enter PA Browser.
Deploy Prisma Access Browser Using Workspace ONE
How to deploy the Prisma Access Browser in a Workspace ONE environment.Workspace ONE is a digital platform that delivers and manages any app on any device by integrating access control, application management, and unified endpoint management. The platform allows IT to deliver a digital workspace that includes the devices and apps of the business's choice, without sacrificing the security and control that IT professionals need.To deploy the Prisma Access Browser, follow the appropriate steps for your operating system.Deploy for Windows
Create an Internal Application using the Windows Installer.- Download the Windows MSI Installer. The installer can be downloaded using the following link: Windows Prisma Access Browser Installer.In the Workspace One application, add an Internal Application with the MSI file.In the Details section, enter the following:
- Custom Processor Architecture - 64-bit.In the Add Application - PrismaAccessBrowserSetup.exe v n.n.n.n window, select the Deployment Options.Enter the following information:
- Admin Privileges - Select Yes.
Save and Assign.Deploy for Mac
Create an Internal Application using the macOS installer. You can download the installer, found here: Latest macOS Prisma Access Browser.Using the VMware Workspace ONE Admin Assistant tool, create a package as follows on a machine running macOS:- Download the latest Mac Browser from the URL (Latest macOS Prisma Access Browser)Use the VMware Workspace ONE Admin Assistant tool to create a package.
- On a Mac machine, download the tool from this URL: Admin AssistantRun the tool, and drag and drop the latest Prisma Access Browser into the app.After “Parsing”, the app should produce a package containing a .DMG and .PLIST file.Create an Internal Application using the output of the previous step.
Deploy using IGEL
deploy PAB using IGELPrisma Browser installation and update over IGEL OS is performed via the IGEL App Portal. For more information, refer to the IGEL App Portal.
Deploy using Linux
directions on deploying PAB using LinuxDistribution Agnostic Installation- Installation of the latest version on either Ubuntu/Fedora (MD5: eaeb2552cdffe5842debb6c8b7f5cffd):curl -fsS https://updates.talon-sec.com/linux/prisma-access-browser/install.sh | sudo bash
Ubuntu- Dynamic list of Prisma Browser Linux (.deb) stable versions can be found here. New stable versions are released on a weekly basis and will be reflected in the list.
Manual/One-time installation- Install the package using the downloaded .deb file. sudo apt install prisma-access-browser-stable_<version_number>-1_amd64.deb
Package Repository (via MDM/Local)- Create a new repository file under /etc/apt/sources.list.d
echo "deb [arch=amd64] https://updates.talon-sec.com/ linux/prisma-access-browser/deb/ stable main" | sudo tee /etc/apt/sources.list.d/ prisma-access-browser.listImport the GPG key (before using the repository)wget -q -O - https://updates.talon-sec.com/linux/prisma-access-browser/linux_signing_key.pub | sudo tee /etc/apt/trusted.gpg.d/pab.asc >/dev/nullUpdate the package listsudo apt updateInstall Prisma Browsersudo apt install prisma-access-browser-stablePrisma Browser Removalsudo apt remove prisma-access-browser-stableFedora
- Dynamic list of Prisma Browser Linux (.rpm) stable versions can be found here. New stable versions are released weekly and are reflected in the list.
- Manual/one time installation
- Install the package using the downloaded .deb file:sudo dnf install prisma-access-browser-stable-<version_number>-1.x86_64.rpmwhen using sudo yum install prisma-access-browser-stable-<version_number>-1.x86_64.rpm
- Install the package using the downloaded .deb file:
● Package repository (via MDM/Local)○ Create a new repository file under/etc/yum.repos.d/package-name.repowith the following content:[prisma-access-browser]name=prisma-access-browserbaseurl=https://updates.talon-sec.com/linux/prisma-access-browser/rpm/stable/x86_64enabled=1gpgcheck=1gpgkey=https://updates.talon-sec.com/linux/prisma-access-browser/linux_signing_key.pub○ [Optional - as already referenced in the repo file]manually import the keysudo rpm --import https://updates.talon-sec.com/linux/prisma-access-browser/linux_signing_key.pub○ Clear the cachesudo dnf clean all○ Install the packagesudo dnf install prisma-access-browser-stable- Prisma Access Browser RemovalPackage removal
sudo dnf remove prisma-access-browser-stableDistribution agnostic installation- Installation of the latest version on either Ubuntu/Fedora (MD5: eaeb2552cdffe5842debb6c8b7f5cffd):curl -fsS https://updates.talon-sec.com/linux/prisma-access-browser/install.sh | sudo bash
Ubuntu● Dynamic list of PAB Linux (.deb) stable versions can be found here. A new stable version is released on a weekly basis and will be reflected in the list.● Manual/one time installation○ Install the package using the downloaded .deb filesudo apt install prisma-access-browser-stable_<version_number>-1_amd64.deb● Package repository (via MDM/Local)○ Create a new repository file under /etc/apt/sources.list.d/echo "deb [arch=amd64] https://updates.talon-sec.com/linux/prisma-access-browser/deb/ stable main" | sudo tee /etc/apt/sources.list.d/prisma-access-browser.list○ Import the GPG key (before using the repository)wget -q -O - https://updates.talon-sec.com/linux/prisma-access-browser/linux_signing_key.pub | sudo tee /etc/apt/trusted.gpg.d/pab.asc >/dev/null○ Update the package listsudo apt update○ Install Prisma Access Browsersudo apt install prisma-access-browser-stable- Prisma Access Browser RemovalPackage removal
sudo apt remove prisma-access-browser-stableFedora● Dynamic list of PAB Linux (.rpm) stable versions can be found here. A new stable version is released on a weekly basis and will be reflected in the list.● Manual/one time installation○ Install the package using the downloaded .deb filesudo dnf install prisma-access-browser-stable-<version_number>-1.x86_64.rpmWhen usingyum sudo yum install prisma-access-browser-stable-<version_number>-1.x86_64.rpm● Package repository (via MDM/Local)○ Create a new repository file under/etc/yum.repos.d/package-name.repowith the following content:[prisma-access-browser]name=prisma-access-browserbaseurl=https://updates.talon-sec.com/linux/prisma-access-browser/rpm/stable/x86_64enabled=1gpgcheck=1gpgkey=https://updates.talon-sec.com/linux/prisma-access-browser/linux_signing_key.pub○ [Optional - as already referenced in the repo file]manually import the keysudo rpm --import https://updates.talon-sec.com/linux/prisma-access-browser/linux_signing_key.pub○ Clear the cachesudo dnf clean all○ Install the packagesudo dnf install prisma-access-browser-stable- Prisma Access Browser RemovalPackage removal
sudo dnf remove prisma-access-browser-stable