Onboard a Tenant for Prisma Access
Focus
Focus
Prisma Access

Onboard a Tenant for Prisma Access

Table of Contents

Onboard a Tenant for Prisma Access

Create a child tenant and activate Prisma Access packages using the PayGo monthly postpaid billing model.
Where Can I Use This?What Do I Need?
  • Strata Multitenant Cloud Manager
  • Multitenant Superuser or Multitenant Manage User role
  • PayGo activated on your root tenant
  • Available credits in your PayGo credit pool
After activating PayGo on your absolute root tenant, you can create child tenants and allocate Prisma® Access packages to them using monthly postpaid billing. PayGo unlocks activation flows with no quantity limit—you can create multiple tenants with different packages and quantities. All billing is postpaid, metered daily, and invoiced monthly.
Prisma Access provides full SASE functionality, including secure access to the internet, SaaS, and private applications for mobile users and remote networks. Use this workflow when onboarding a new customer who requires comprehensive network security with mobile user protection and gateway connectivity. You perform this task from the root tenant where the PayGo is activated. The onboarding workflow creates a new child Tenant Service Group (TSG) in your tenant hierarchy and provisions Strata Cloud Manager, Strata Logging Service (SLS), Cloud Identity Engine (CIE), Prisma Access, and Partner Premium Support for the new tenant.
You choose between two packages based on your tenant's security requirements and scale:
PackageMinimum UsersIncluded CapabilitiesKey Differentiator
SASE SWG50 mobile usersPrisma Access Agent, Strata Logging Service (SLS), Partner Premium SupportPrivate App Access available as an optional add-on.
SASE ENT100 mobile usersPrisma Browser, Prisma Access Agent, SLS, Partner Premium SupportPrivate App Access included by default (no add-on required).
  1. Select ConfigurationWorkflowsTenant Onboarding > Activate New Tenant with PayGo Postpaid Billing Model.
  2. Choose the SASE package for this tenant.
    Choose SASE SWG or SASE ENT from the available packages and click Next.
  3. Configure the tenant details.
    1. In Tenant Name, enter a unique name for the child tenant.
    2. For Tenant Industry Vertical, choose the industry segment for this tenant.
    3. In Domain, enter the tenant's primary email domain.
    4. For Region, choose the geographic region for the tenant's data residency.
  4. Configure the mobile user quantity and add-ons.
    1. In Mobile Users, enter the number of mobile users (minimum 50 for SASE SWG, minimum 100 for SASE ENT).
    2. (Optional) Enable available add-ons based on the tenant's requirements.
      Add-onAvailable ForDescription
      Private App AccessSASE SWG onlyProvides access to private applications (ZTNA). Already included in SASE ENT.
      Additional Gateway LocationsSASE SWG, SASE ENTRemoves the 2-gateway-location limit and allows all available Prisma Access locations.
      ADEM/AIOpsSASE SWG, SASE ENTAutonomous Digital Experience Management for monitoring user connectivity and network performance.
      Remote NetworksSASE SWG, SASE ENTSite-to-site connectivity for branch offices. Site types: Very Small (25 Mbps), Small (50 Mbps), Medium (250 Mbps), Large (1 Gbps), Extra Large (2.5 Gbps). Minimum 2 sites required.
  5. Configure the Identity Provider (IdP) for user authentication.
    Only Tenant-Specific IdP is supported for Prisma Access tenants. MSP-shared IdP is not supported.
    1. Entity ID and ACS URL are auto-populated.
    2. For Vendor, choose the identity provider, such as Entra, Okta, PingOne, CyberArk, Google, or PingFederate, and set up the identity provider.
    3. In Identity Provider Metadata URL, enter the metadata URL generated by your identity provider and click Verify URL.
      The Identity Provider ID and SSO URL fields are automatically populated based on the URL you provide. If the information in these fields is incorrect, update it on your IdP vendor's site and upload the metadata again.
  6. Configure the Mobile User setup.
    1. In Portal Hostname, specify the gateway FQDN (Fully Qualified Domain Name) for each selected location.
      The Prisma Access Agent uses this FQDN to connect users to the nearest gateway.
    2. For Location Setup, select the gateway locations or specify the coordinates for mobile user traffic.
      These locations determine where user traffic is processed and encrypted. Without the Unlimited Gateway Locations add-on, you can select a maximum of 2 gateway locations. With the add-on, you can select unlimited regions.
    3. Review the selected locations and click Next.
  7. Review the onboarding summary and click Onboard to provision the tenant.
    Tenant provisioning is asynchronous and takes a few minutes. During this time, the system creates the child TSG, provisions Strata Cloud Manager with mobile agent enabled, pushes a best-practice security configuration, and configures CIE with your IdP settings. Once complete, the tenant status changes to Onboarding Complete in the Business dashboard. If provisioning fails, the Business dashboard displays the error in the tenant status column.
  8. Verify the tenant activity details and activity logs after provisioning completes.
    1. Select the newly created tenant from the tenant hierarchy.
    2. Review the Activity Details panel to confirm the onboarding status, allocated package, mobile user quantity, and gateway locations.
    3. Select Activity Log to view the chronological record of all actions performed on this tenant, including the onboarding event with timestamp, user, and description.