Pay-As-You-Go (PayGo)
Focus
Focus
Prisma Browser

Pay-As-You-Go (PayGo)

Table of Contents


Pay-As-You-Go (PayGo)

Onboard a child tenant for Prisma Browser using the PayGo monthly postpaid billing model.
Where Can I Use This?What Do I Need?
  • Strata Multitenant Cloud Manager
  • Multitenant Superuser or Multitenant Manage User role
  • PayGo activated on your root tenant
  • Available credits in your PayGo credit pool
After activating the PayGo SKU on the absolute root tenant, you can create child tenants and activate Prisma Browser on them. The PayGo activation enables PayGo workflows in the MSP Portal, allowing you to onboard multiple tenants and configure different packages and quantities for each tenant.
Prisma Browser provides browser-based security for users accessing SaaS and web applications. It is suitable for tenants that require secure web access without the full network security capabilities of Prisma Access SASE. Use this workflow to onboard customers who require browser-level protection or to offer a lightweight security solution as part of your managed service portfolio. The minimum user allocation is 1 mobile user.
You perform this from the root tenant where the PayGo SKU is activated. The onboarding workflow creates a new child Tenant Service Group (TSG) in the tenant hierarchy and provisions Prisma Browser, Cloud Identity Engine, and Partner Premium Support for the new tenant.
Packages activated on the child tenant are included in the monthly postpaid billing based on the packages activated each day during the billing cycle.
To onboard a child tenant with PayGo billing:
  1. Select ConfigurationWorkflowsTenant OnboardingActivate New Tenant with PayGo Postpaid Billing Model and click Start Onboarding.
  2. Choose Prisma Browser Core from the available packages and click Next.
  3. Step 1 - Set up the tenant.
    1. In Tenant Name, enter a unique name for the child tenant.
    2. For Tenant Industry Vertical, choose the industry segment for this tenant.
    3. In Domain, enter the tenant's primary email domain.
    4. For Region, choose the SLS location where you want to deploy this tenant. This must match the CIE region of the root tenant if you choose to use MSP IdP.
    5. In User Quantity, enter the number of mobile users (minimum 1).
    6. (Optional) Enable Private App Access to provide access to private applications.
  4. Step 2 - Configure the Identity Provider.
    1. Select the Identity Provider type:
      • MSP IdP—The tenant uses the MSP's shared identity provider. The MSP sets up users and groups within their IdP and integrates the IdP with CIE at the root tenant, which authenticates users in the child tenant. Cloud Identity Engine resolves the MSP directory, domains, and user groups for this tenant.
      • Tenant Specific IdP—The tenant uses its own identity provider. Enter the IdP configuration details (SAML or OIDC settings), including metadata URL, domain, and user group mappings
    2. Entity ID and ACS URL are auto-populated.
    3. For Vendor, choose the Identity Provider, such as Entra, Okta, PingOne, CyberArk, Google, or PingFederate, and set up the identity provider.
    4. Identity Provider Metadata URL: enter the metadata URL you generated at the Identity Provider and verify the URL. The Identity Provider ID and SSO URL fields are populated using the URL you provided. If you see any issues with the information in these fields, correct it on the IdP vendor site and upload the metadata again.
  5. Review the onboarding summary and click Onboard to provision the tenant.
    Tenant provisioning is asynchronous and takes a few minutes. During this time, the system creates the child TSG, provisions Prisma Browser, configures CIE with your IdP settings, and applies a best-practice security policy. Once complete, the tenant status changes to Onboarding Complete in the Business dashboard. If provisioning fails, the Business dashboard displays the error in the tenant status column.
  6. After provisioning completes, verify the tenant activity details and activity logs.
    1. Select the newly created tenant from the tenant hierarchy.
    2. Review the Activity Details panel to confirm the onboarding status, allocated package, and mobile user quantity.
    3. Select Activity Log to view the chronological record of all actions performed on this tenant, including the onboarding event with timestamp, user, and description.