Prisma Access Browser
Integrate Prisma Access Browser with Google Workspace
Table of Contents
Expand All
|
Collapse All
Prisma Access Browser Docs
Integrate Prisma Access Browser with Google Workspace
Learn how to integrate the Prisma Access Browser with Google Workspace.
Where Can I Use This? | What Do I Need? |
---|---|
|
|
You can use Google Workspace with custom or third-party applications to enrich
existing Google Workspace services or to use new features with Google Workspace.
After you integrate Prisma Access Browser with Google Workspace, your users will be
able to open only the applications that you’ve assigned to the Prisma Access Browser.
Before you begin, ensure that you complete the following tasks:
- Deploy the Context-Aware Access feature in Google Workspace, which is available for Enterprise and Education accounts or with Cloud Identity Premium.
- Set up SSO authentication to Prisma Access Browser with Google.
- Enable the Google Workspace integration in Strata Cloud Manager and obtain the Prisma Access Browser certificate:
- Go to ManageConfigurationPrisma Access BrowserAdministrationIntegrationsServices.Scroll to Google Workspace Integration and expand it.Click Enabled.In part 1, select Prisma Access Browser Certificate. The certificate will download.Add the certificate for Prisma Access Browser in the Google Admin console.
- Go to Google Admin consoleDevicesNetworks.Click Certificates, then ADD CERTIFICATE, and upload the Prisma Access Browser certificate that you downloaded.Select Endpoint Verification and click ADD.Create a new access level in the Google Admin console.
- Go to Google Admin ConsoleSecurityAccess and data controlContext-Aware Access.If Context-Aware Access is disabled, enable it.Click Access levels, then CREATE NEW ACCESS LEVEL.Name the new access level Prisma Access Browser or any other name of your choice.Select ADVANCED and paste the following text:evice.certificate1s.exists(cert, cert.is_valid && cert.root_ca_fingerprint == "kiLbsQhDpeCsDkM6ox2oHiaxOiQQ45u8FV1AmeQxc9E")Assign the new access level to your apps.
- Go to Google Admin ConsoleSecurityAccess and data controlContext-Aware Access.Click Assign access levels.Select one or more apps in the list and click Assign.Select the newly Prisma Access Browser access level that you created in Step 3.Validate the integration on an endpoint.
- Install the Prisma Access Browser on an endpoint.Wait for the new Google Workspace configuration to complete, usually 5 minutes.From the Prisma Access Browser, sign in to an assigned app and test the following:
- Make sure that you can successfully sign in to an application that uses the Google Workspace SSO.
- Make sure that you can't sign in to the application from a different browser.
After you complete the validation, and your users will be able to open only the applications that you’ve assigned to the new access level using the Prisma Access Browser.