This feature ensures that access to applications
integrated with Google Workspace is only possible using the Prisma Browser.Prisma Access comes with a dedicated Public Key Infrastructure (PKI)
used for enforcement. Once enabled, each browser is provisioned with a
dedicated, unique client certificate issued by the PKI (each tenant has a unique
root CA used to sign the client certificates). Certificate enforcement ensures
login to the identity provider is only allowed when the client certificate
signed by the dedicated root CA is provided. Renewals are generated in the
browser using a private key dedicated to each tenant. The certificate renews
automatically.
You need to set up the following prerequisites before
configuring this option:
- Google Workspace Context-Aware Access feature, available for Enterprise or
Education accounts, or with Cloud Identity Premium.
- Setting up SSO Authentication for Prisma Access with Group.