Private Web Application Access for Secure Agentless Access
You can enable secure, agentless access to private web applications for unmanaged
users, simplifying onboarding and enhancing enterprise security with browser-based
access.
| Where Can I Use This? | What Do I Need? |
- Prisma Access (Managed by Strata Cloud Manager)
- Prisma Access (Managed by Panorama)
|
Minimum Prisma Access version: 6.1 Preferred Minimum PAN-OS dataplane version: 11.2.7 Prisma Access license with a Mobile User
subscription Cloud Identity Engine (CIE) for user
authentication Service Connection (SC), or ZTNA Connector, or
Colo-Connect for private app connectivity Remote Browser Isolation (RBI) license for data controls
for SaaS applications - Network Administrator or Superuser role
|
For modern enterprises, secure access is a requirement for all devices, with
the trend of the workforce (FTEs, contractors, partners) using their own devices to
access sensitive data. This extended workforce accessing enterprise applications on
unmanaged devices presents unique challenges, as traditional solutions like Mobile
Device Management (MDM) or endpoint agents are often not applicable, leading to
potential loss of sensitive data and possibly loss of productivity.
Providing secure access to unmanaged devices without installing additional
software remains a significant hurdle. Mandatory installation of agents, VPN clients, or
other software on endpoints is often not viable for unmanaged users such as contractors,
vendors, and BYOD employees who either lack administrative rights, have conflicting
software already installed, or prefer not to install additional software for privacy
reasons. This challenge is particularly acute for federal contractors working on
government-furnished equipment (GFE), where installation of third-party software or
browser extensions is strictly prohibited by security policies. This challenge was
previously addressed for SSH, RDP, and VNC applications through the Secure Agentless
Access (formerly Secure Agentless Access) solution.
Private Web Application Access now extends this capability, enabling secure,
browser-based access to internal HTTP or HTTPS applications for unmanaged devices and
users. This feature leverages the existing Secure Agentless Access architecture to
include private web resources. The primary goal is to simplify administration and
enhance productivity for the extended workforce by eliminating the need for client
software or agents on end-user devices, thereby providing a streamlined and secure
access solution where traditional endpoint agents or MDM are not applicable.
You can optionally enable Remote Browser Isolation (RBI)
for private web applications to add an additional layer of data protection. When
isolation is enabled, private web application content is rendered in a secure,
cloud-hosted browser environment rather than directly on the user's device. This ensures
that sensitive corporate data from internal applications never reaches the unmanaged
endpoint.
To enable isolation, you configure the application URL
under a custom URL category, mark it for isolation in a URL Access Management profile,
associate the profile with a profile group, and bind the profile group to a security
policy. A Remote Browser Isolation (RBI) license is required in addition to the Secure
Agentless Access (SAA) license.
App isolation is optional for private web applications. Without the RBI license and
isolation configuration, private web applications function normally through direct
browser-based access without isolation.