Windows Account Based SSO Authentication
Focus
Focus
Prisma Browser

Windows Account Based SSO Authentication

Table of Contents

Windows Account Based SSO Authentication

This article discusses using the new Account based SSO Authentication
Where Can I Use This?What Do I Need?
  • Strata Cloud Manager
  • Standalone Prisma Browser
  • Prisma Access with Prisma Access Browser bundle license or Prisma Access Browser standalone license
  • Role: Prisma Access Browser Roles
  • Microsoft 365
This feature is available for Microsoft Windows and macOS devices.
Because this feature uses local logged in users for authentication against web applications, we advise that you use this feature on managed devices only, to avoid unexpected logins from unmanaged domains.
Enable browser logins using Windows accounts linked to Microsoft Entra ID. Devices must be Entra ID joined, Hybrid AD joined, or Entra ID registered.
  • Passwordless Authentication - Enables secure access for users without traditional passwords, improving accessibility and reducing friction.
  • Stronger Admin Controls - Allows IT admins to enforce authentication through corporate-managed SSO accounts, minimizing unauthorized access and reducing reliance on passwords.
Taking advantage of this new capability, Prisma Access Browser now has a method for incorporating the Microsoft solution into our commitment to secure solutions that align with modern enterprise needs, especially as hybrid and remote work models grow.

Prisma Browser Sign-in Configuration

Enable browser logins using Windows accounts linked to Microsoft Entra ID. Devices must be: Entra ID joined, Hybrid AD joined, or Entra ID registered.

Option 1: Manual Username Entry

Use this option if users should manually enter their username (e.g., richarddorlinger@example.com). When they log in, their credentials are authenticated against the local machine, ensuring the entered username matches the locally logged-in user.
To configure this feature, set the following local registry key on managed devices:
reg add "HKLM\Software\Policies\Palo Alto Networks\PrismaAccessBrowser" /v ForceEnableMsSSO /t REG_DWORD /d 1 /f

Option 2: Fully Automatic Sign- In

You can enable fully automatic sign-in to Prisma Browser on managed devices. When configured, the browser signs users in automatically using their OS-level credentials. No username entry required.
Use this option for a seamless experience where the browser automatically signs users in using their OS-level credentials without requiring any username entry. The browser reads the signed-in user's identity from the operating system and locks authentication to that account.
In addition to the registry key mentioned above, add the following key to managed devices:
reg add "HKLM\Software\Policies\Palo Alto Networks\PrismaAccessBrowser" /v ForceEnableMsSSOAutoLogin /t REG_DWORD /d 1 /f
With automatic sign-in enabled, Prisma Browser uses the operating system's user identity to log users into their profile on startup—no credentials required.
This locks the browser to the OS account and prevents users from signing in with a different account.
If the user's identity exists across multiple tenants, a tenant picker prompt is displayed. If automatic authentication cannot complete, the browser falls back to standard login where users enter their username without a password.

Automatic Web Application Sign-In Using Microsoft Entra ID

You can leverage Prisma Access Browser’s capabilities to enable seamless authentication during Microsoft SSO flows for web applications.
How It Works:
Enable the Microsoft SSO control when you create a Browser Customization rule. From Strata Cloud Manager, select Configuration>Prisma Browser> Policy>Profiles>Browser Customization, and select Microsoft Auto-SSO.
Once this is done, your users will be able to navigate to web applications and experience automatic sign-in using Microsoft SSO, authenticated via corporate Active Directory connections.

Support for Microsoft Entra on macOS Devices

Prisma Browser now supports Microsoft Enterprise SSO plug-in for Apple devices. This allows users to seamlessly authenticate to Microsoft Entra web apps.
What you need to do:
  1. Deploy and configure the Enterprise Single Sign On plug-in for Apple configured on macOs devices. The information can be found on the Microsoft Entra site.
  2. Make sure that the device is enrolled and has the Intune Company Portal, version 5.2504.0 or higher.
  3. Make sure that the minimum Prisma Browser version is 136.