Private Web Application Access for Secure Agentless Access
You can enable secure, agentless access to private web applications for unmanaged
users, simplifying onboarding and enhancing enterprise security with browser-based
access.
| Where Can I Use This? | What Do I Need? |
- Prisma Access (Managed by Strata Cloud Manager)
- Prisma Access (Managed by Panorama)
|
Minimum Prisma Access version: 6.1 Preferred Minimum PAN-OS dataplane version: 11.2.7 Prisma Access license with a Mobile User
subscription Cloud Identity Engine (CIE) for user
authentication Service Connection (SC), or ZTNA Connector, or
Colo-Connect for private app connectivity - Network Administrator or Superuser role
|
For modern enterprises, secure access is a requirement for all devices, with
the trend of the workforce (FTEs, contractors, partners) using their own devices to
access sensitive data. This extended workforce accessing enterprise applications on
unmanaged devices presents unique challenges, as traditional solutions like Mobile
Device Management (MDM) or endpoint agents are often not applicable, leading to
potential loss of sensitive data and possibly loss of productivity.
Providing secure access to unmanaged devices without installing additional
software remains a significant hurdle. Mandatory installation of agents, VPN clients, or
other software on endpoints is often not viable for unmanaged users such as contractors,
vendors, and BYOD employees who either lack administrative rights, have conflicting
software already installed, or prefer not to install additional software for privacy
reasons. This challenge is particularly acute for federal contractors working on
government-furnished equipment (GFE), where installation of third-party software or
browser extensions is strictly prohibited by security policies. This challenge was
previously addressed for SSH, RDP, and VNC applications through the Secure Agentless
Access (formerly Secure Agentless Access) solution.
Private Web Application Access now extends this capability, enabling secure,
browser-based access to internal HTTP or HTTPS applications for unmanaged devices and
users. This feature leverages the existing Secure Agentless Access architecture to
include private web resources. The primary goal is to simplify administration and
enhance productivity for the extended workforce by eliminating the need for client
software or agents on end-user devices, thereby providing a streamlined and secure
access solution where traditional endpoint agents or MDM are not applicable.