| Where Can I Use This? | What Do I Need? |
If you configure the
Prisma Agent to authenticate users via SAML
authentication, the agent will by default use the
Prisma Agent embedded browser for SAML
authentication. If you don't want to use the embedded browser for SAML
authentication, you can configure the agent to use the endpoint's default system
browser, such as Chrome, Firefox, or Safari.
In addition, on any browser that supports the Web Authentication (WebAuthn) API, you
can use Universal 2nd Factor (U2F) security tokens such as YubiKeys for multi-factor
authentication (MFA) to identify providers (IdPs) such as Azure or Okta.
If you use the default system browser for SAML
authentication, the browser tab remains open upon successful authentication. If the
user does not close the browser tab each time after authentication, multiple browser
tabs can remain open.