Prisma Browser Sign-in Configuration
Enable browser logins using Windows accounts linked to Microsoft Entra ID.
Devices must be: Entra ID joined, Hybrid AD joined, or Entra ID registered.
Option 1: Manual Username Entry
Use this option if users should manually enter their username (e.g.,
richarddorlinger@example.com). When they log in, their credentials are
authenticated against the local machine, ensuring the entered username matches
the locally logged-in user.
To configure this feature, set the following local registry key on managed
devices:
reg add "HKLM\Software\Policies\Palo Alto Networks\PrismaAccessBrowser"
/v ForceEnableMsSSO /t REG_DWORD /d 1 /f
Option 2: Fully Automatic Sign- In
You can enable fully automatic sign-in to Prisma Browser on managed devices. When
configured, the browser signs users in automatically using their OS-level
credentials. No username entry required.
Use this option for a seamless experience where the browser
automatically signs users in using their OS-level credentials without requiring
any username entry. The browser reads the signed-in user's identity from the
operating system and locks authentication to that account.
In addition to the registry key mentioned above, add the following key
to managed devices:
reg add "HKLM\Software\Policies\Palo Alto Networks\PrismaAccessBrowser"
/v ForceEnableMsSSOAutoLogin /t REG_DWORD /d 1 /f
With automatic sign-in enabled, Prisma Browser uses the operating
system's user identity to log users into their profile on startup—no credentials
required.
This locks the browser to
the OS account and prevents users from signing in with a different
account.
If the user's identity exists across multiple tenants, a tenant picker prompt is
displayed. If automatic authentication cannot complete, the browser falls back
to standard login where users enter their username without a password.
Automatic Web Application Sign-In Using Microsoft Entra ID
You can leverage Prisma Access Browser’s capabilities to enable
seamless authentication during Microsoft SSO flows for web applications.
How It Works:
Enable the Microsoft SSO control when you create a Browser
Customization rule. From Strata Cloud Manager, select Configuration>Prisma Browser>
Policy>Profiles>Browser Customization, and select
Microsoft Auto-SSO.
Once this is done, your users will be able to navigate to web
applications and experience automatic sign-in using Microsoft SSO, authenticated
via corporate Active Directory connections.
Support for Microsoft Entra on macOS Devices
Prisma Browser now supports Microsoft Enterprise SSO plug-in for Apple
devices. This allows users to seamlessly authenticate to Microsoft Entra web
apps.
What you need to do:
- Deploy and configure the Enterprise Single Sign On plug-in for Apple
configured on macOs devices. The information can be found on the Microsoft Entra site.
- Make sure that the device is enrolled and has the Intune Company Portal,
version 5.2504.0 or higher.
- Make sure that the minimum Prisma Browser version is
136.