Private Web Application Access for Secure Agentless Access
Focus
Focus
Prisma Access

Private Web Application Access for Secure Agentless Access

Table of Contents

Private Web Application Access for Secure Agentless Access

You can enable secure, agentless access to private web applications for unmanaged users, simplifying onboarding and enhancing enterprise security with browser-based access.
Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Strata Cloud Manager)
  • Prisma Access (Managed by Panorama)
  • Minimum Prisma Access version: 6.1 Preferred
  • Minimum PAN-OS dataplane version: 11.2.7
  • Prisma Access license with a Mobile User subscription
  • Cloud Identity Engine (CIE) for user authentication
  • Service Connection (SC), or ZTNA Connector, or Colo-Connect for private app connectivity
  • Network Administrator or Superuser role
For modern enterprises, secure access is a requirement for all devices, with the trend of the workforce (FTEs, contractors, partners) using their own devices to access sensitive data. This extended workforce accessing enterprise applications on unmanaged devices presents unique challenges, as traditional solutions like Mobile Device Management (MDM) or endpoint agents are often not applicable, leading to potential loss of sensitive data and possibly loss of productivity.
Providing secure access to unmanaged devices without installing additional software remains a significant hurdle. Mandatory installation of agents, VPN clients, or other software on endpoints is often not viable for unmanaged users such as contractors, vendors, and BYOD employees who either lack administrative rights, have conflicting software already installed, or prefer not to install additional software for privacy reasons. This challenge is particularly acute for federal contractors working on government-furnished equipment (GFE), where installation of third-party software or browser extensions is strictly prohibited by security policies. This challenge was previously addressed for SSH, RDP, and VNC applications through the Secure Agentless Access (formerly Secure Agentless Access) solution.
Private Web Application Access now extends this capability, enabling secure, browser-based access to internal HTTP or HTTPS applications for unmanaged devices and users. This feature leverages the existing Secure Agentless Access architecture to include private web resources. The primary goal is to simplify administration and enhance productivity for the extended workforce by eliminating the need for client software or agents on end-user devices, thereby providing a streamlined and secure access solution where traditional endpoint agents or MDM are not applicable.