| Where Can I Use This? | What Do I Need? |
- Prisma Access (Managed by Strata Cloud Manager)
- Prisma Access (Managed by Panorama)
- NGFW (Managed by Panorama)
|
- Check the prerequisites for the deployment you're
using
- macOS 14 and later desktop devices
- Contact your Palo Alto Networks account representative to activate the Prisma Agent feature
|
To set up the Prisma Agent on macOS devices, you will need to deploy an
installation package to the target endpoint. During the installation process, macOS
will prompt for various system permissions including system extension approval,
notification permissions, and Full Disk Access permissions for Prisma Agent processes.
For a streamlined deployment that eliminates the need for end-user interaction or
manual configuration by you, Palo Alto Networks offers the V3 version of the
configuration profiles, which consist of two unified configuration profiles to aid
in your deployment of
Prisma Agent. One configuration profile contains
specifications for
Prisma Agent. The other contains specifications for
Endpoint DLP. Both profiles contain system extension payloads that macOS requires MDM to
pre-authorize before the installer runs. Without pre-authorization, macOS prompts
users to manually approve each extension.
Deploy the Prisma Agent
configuration profile before installing either package. If you are deploying the Prisma Agent plus Endpoint DLP package
(PrismaAccessAgentInstaller_<version>.pkg),
also deploy the Endpoint DLP profile before running the installer. The Endpoint DLP
profile is not required for the standard Prisma Agent package
(PrismaAccessAgentInstaller_NoDLP_<version>.pkg).
The Endpoint DLP agent requires a separate license and remains inactive
until you activate the license.
You can use these profiles with Jamf Pro to deploy the Prisma Agent to
your managed macOS endpoints. The V3 configuration profiles are compatible with all
versions of Prisma Agent for macOS.
The Prisma Agent configuration profiles include the following
payloads:
- Content Filter
Payload type:
com.apple.webcontent-filter
- Notifications
Payload type:
com.apple.notificationsettings
- Privacy Preferences Policy Control
Payload type:
com.apple.TCC.configuration-profile-policy
- System Extensions
Payload type:
com.apple.system-extension-policy
- VPN
Payload type: com.apple.vpn.managed
The macOS System Settings window does not show Full Disk
Access permissions granted to the Prisma Agent by the configuration
profile.
The following procedure shows how to deploy Prisma Agent on macOS
endpoints using the unified configuration profile files from Palo Alto Networks.
Ensure that you perform the steps consecutively as described below. If you change
the order, the configuration profiles might not be available at the time the agent
requires them, which could cause unexpected behavior.