Access Private Apps with Prisma Browser Connector
Access Private Apps with Prisma Browser for Mobile Connector
The Prisma Browser Connector provides secure, authenticated access to private
applications across all supported operating systems. Utilizing a standardized MASQUE
tunnel mechanism, the connector creates a secure transport channel for enterprise
traffic originating from both desktop and mobile environments.
Platform Compatibility
Prisma Browser Connector is natively supported across the following
platforms:
Desktop: Windows, macOS, and Linux
Mobile: Prisma Browser Mobile (iOS and Android)
Mobile clients establish connections using the exact same MASQUE tunneling
protocol as desktop clients, ensuring consistent security posture, policy
enforcement, and authentication mechanisms across all endpoints. Both iOS and
Android platforms integrate with the Prisma Access console to maintain shared policy
rules. However, administrators should account for mobile-specific differences—such
as File Download controls skipping specific extension checks and blocking downloads
when enabled—by scoping policy rules to dedicated mobile device groups.
Prerequisites & Configuration
Trusted Certificate Authority (CA) Requirement
To successfully establish and validate MASQUE tunnels, the Certificate
Authority (CA) issuing your Connector or proxy certificate must be explicitly
registered as a trusted CA within your Prisma Browser security policies.
Configuration Checklist:- From Strata Cloud Manager, select
- Select Trusted Certificate Authorities.
- Ensure the signing CA certificate is added to either the device trust
store or the browser/internal trust store, depending on your
operational deployment model.
- Verify that the CA trust settings are pushed and applied consistently across
all platform profiles (Desktop, iOS, and Android).
Failure to import and trust the
issuing CA will result in the browser being unable to verify the Connector
endpoint. Unverified connection attempts will fail or automatically fall back
to a blocked state. Always confirm CA deployment prior to rolling out
Connector-based access to end users.
MASQUE Protocol Architecture & Tunneling
The Prisma Browser Connector utilizes MASQUE (Multiplexed Application
Substrate over QUIC Encryption) to construct secure, high-performance transport
channels over HTTP/3. MASQUE leverages QUIC to multiplex multiple flows across
streams, encrypt flow metadata, and apply a unified congestion controller. This
enables seamless proxying of TCP, UDP, and IP-based applications with minimal
latency and high resilience.
For every connection request, the browser generates a 64-bit random integer
sent via the x-panw-flow-id header to correlate connection streams and
facilitate session tracking.
Fallback Mechanisms
To guarantee connectivity across constrained or restrictive network
environments, the Prisma Browser Connector employs a multi-tiered fallback
architecture:
HTTP/2 Fallback: If QUIC/HTTP/3 traffic is blocked or
unsupported on the user's underlying network, chromium-based bad-proxy
detection automatically triggers a rollover to MASQUE over HTTP/2. Network
conditions are continuously monitored, and HTTP/3 connection attempts are
automatically re-evaluated whenever a network change event occurs (e.g.,
switching Wi-Fi networks or connecting an Ethernet cable).
Enterprise Protector (EP) Fallback: If HTTP/2 proxying is
also blocked or unavailable, traffic can route via Enterprise Protector (EP)
as a fallback mechanism. This path is controlled via feature flags and can
be enabled per tenant upon request.
Access ID (AID / ZID) Allocation & Lifecycle
Traffic authentication and user isolation rely on Access IDs (AID, formerly
ZID) allocated dynamically during session startup:
JWT Acquisition: Upon launch, the browser requests a
short-lived JSON Web Token (JWT) from the Prisma Browser backend, which is
automatically refreshed every 20 minutes.
Caching & Persistence: The backend obtains the allocated
Access ID and stores it in a Redis cache with a standard Time-To-Live (TTL)
of 3 days. Re-allocation is only triggered if the cache entry expires or if
a change in User ID or Device ID is detected.
Header Injection: All private application traffic sent over
the MASQUE proxy includes the Access ID claim within the JWT, as well as in
the dedicated x-panw-access-id (or x-panw-zerotrust-id)
request header.
Resilience: If the backend fails to respond to an allocation
request, the browser continues to authenticate and pass traffic through the
proxy without failing the underlying session.