Pay-As-You-Go (PayGo)
Onboard a child tenant for Prisma Browser using the PayGo monthly postpaid
billing model.
| Where Can I Use This? | What Do I Need? |
- Strata Multitenant Cloud Manager
|
- Multitenant Superuser or Multitenant Manage User role
- PayGo activated on your root tenant
- Available credits in your PayGo credit pool
|
After activating the PayGo SKU on the absolute root tenant, you can create child
tenants and activate Prisma Browser on them. The PayGo activation enables PayGo
workflows in the MSP Portal, allowing you to onboard multiple tenants and configure
different packages and quantities for each tenant.
Prisma Browser provides browser-based security for users accessing SaaS and web
applications. It is suitable for tenants that require secure web access without the
full network security capabilities of Prisma Access SASE. Use this workflow to
onboard customers who require browser-level protection or to offer a lightweight
security solution as part of your managed service portfolio. The minimum user
allocation is 1 mobile user.
You perform this from the root tenant where the PayGo SKU is activated. The
onboarding workflow creates a new child Tenant Service Group (TSG) in the tenant
hierarchy and provisions Prisma Browser, Cloud Identity Engine, and Partner Premium
Support for the new tenant.
Packages activated on the child tenant are included in the monthly postpaid billing
based on the packages activated each day during the billing cycle.
To onboard a child tenant with PayGo billing:
- Select and click Start Onboarding.
- Choose Prisma Browser Core from the available packages and
click Next.
- Step 1 - Set up the tenant.
- In Tenant Name, enter a unique name for the child
tenant.
- For Tenant Industry Vertical, choose the industry
segment for this tenant.
- In Domain, enter the tenant's primary email
domain.
- For Region, choose the SLS location where you want to
deploy this tenant. This must match the CIE region of the root tenant if you
choose to use MSP IdP.
- In User Quantity, enter the number of mobile users
(minimum 1).
- (Optional) Enable Private App Access to
provide access to private applications.
- Step 2 - Configure the Identity Provider.
- Select the Identity Provider type:
- MSP IdP—The tenant uses the MSP's shared identity
provider. The MSP sets up users and groups within their IdP
and integrates the IdP with
CIE at the root tenant, which authenticates
users in the child tenant. Cloud Identity Engine
resolves the MSP directory, domains, and user groups for this
tenant.
- Tenant Specific IdP—The tenant uses its own identity
provider. Enter the IdP configuration details (SAML or OIDC
settings), including metadata URL, domain, and user group
mappings
- Entity ID and ACS URL are
auto-populated.
- For Vendor, choose the Identity Provider,
such as Entra, Okta, PingOne, CyberArk, Google, or PingFederate, and
set up the identity
provider.
- Identity Provider Metadata URL: enter the metadata
URL you generated at the Identity Provider and verify the URL. The Identity
Provider ID and SSO URL fields are populated using the URL you provided. If
you see any issues with the information in these fields, correct it on the
IdP vendor site and upload the metadata again.
- Review the onboarding summary and click Onboard to provision
the tenant.
Tenant provisioning is asynchronous
and takes a few minutes. During this time, the system creates the child TSG,
provisions Prisma Browser, configures CIE with your IdP settings, and
applies a best-practice security policy. Once complete, the tenant status
changes to Onboarding Complete in the Business dashboard.
If provisioning fails, the Business dashboard displays the error in the tenant
status column.
- After provisioning completes, verify the tenant activity details and activity
logs.
- Select the newly created tenant from the tenant hierarchy.
- Review the Activity Details panel to confirm the
onboarding status, allocated package, and mobile user quantity.
- Select Activity Log to view the chronological
record of all actions performed on this tenant, including the onboarding
event with timestamp, user, and description.