Application Tags and Classification
Table of Contents
Application Tags and Classification
Organize applications by assigning custom tags and trust-level classifications in
the Prisma Browser management console.
| Where Can I Use This? | What Do I Need? |
|---|---|
|
|
Application Tags and Classification enables administrators to organize and
categorize the application inventory using custom metadata. Tags provide a flexible
labeling system for business-specific context, while classifications assign a trust
level that reflects how the organization treats each application.
Tags and classifications are stored locally in the Prisma Browser and apply
across all application types: Catalog, Custom, Private, Remote Connection, and Local
Desktop. All changes follow the Draft/Publish workflow and are fully tracked in the
Audit Trail.
Tags and classifications are currently managed locally
within the Prisma Browser. Bidirectional synchronization with Strata Cloud Manager is planned for a future release, enabling unified tag
management across the Palo Alto Networks ecosystem.
Tags vs. Classification vs. Categories
Tags, classifications, and categories serve different purposes:
- Categories - Industry-standard application categorization (e.g., Social Media, Collaboration). A closed list maintained by Palo Alto Networks that cannot be modified.
- Classification - Trust-level assessment of an application. Single-select from a fixed set: Sanctioned, Tolerated, Unsanctioned, Unclassified. Selecting a new classification replaces the previous one.
- Tags - Flexible, business-specific labels (e.g., "Finance", "High-Risk", "Project-X"). Multi-select with up to 10 tags per application. Administrators create and manage tags freely.
Manage Tags
Administrators can create, rename, and delete custom tags from the Manage Tags
panel. Tags are available for assignment to any application after creation.
Create a Tag
- From Strata Cloud Manager, select ConfigurationPrisma BrowserApplications.Click Manage Tags.Click Add Tag.Enter a tag name (maximum 127 characters). Tag names are case-sensitive.Click Save.The new tag appears in Draft state. Publish the configuration to make the tag available for rule evaluation.
Rename a Tag
- From Strata Cloud Manager, select ConfigurationPrisma BrowserApplications.Click Manage Tags.Locate the tag and click the edit icon.Enter the new name.Click Save.
Delete a Tag
A tag cannot be deleted if it is currently assigned to an application or referenced in a policy rule. Remove all assignments and rule references before deleting.- From Strata Cloud Manager, select ConfigurationPrisma BrowserApplications.Click Manage Tags.Locate the tag and click the delete icon.Confirm the deletion.
Assign Classification
Classification assigns a trust level to an application. The available classifications are:- Sanctioned - Approved for organizational use.
- Tolerated - Permitted but not officially endorsed.
- Unsanctioned - Not approved for use; may require policy enforcement.
- Unclassified - No trust determination has been made.
To assign a classification:- From Strata Cloud Manager, select ConfigurationPrisma BrowserApplications.Select an application to open its details.Click the Classification field.Select the appropriate classification from the dropdown.
Click Save.The classification change appears as a draft. Publish the configuration to apply.Default Classifications
When the feature is enabled, the Prisma Browser assigns default classifications to existing applications:Application Type Default Classification Remote Connection, Private Sanctioned Catalog, Custom, Local Desktop Unclassified Assign Tags to an Application
To assign tags to a single application:- From Strata Cloud Manager, select ConfigurationPrisma BrowserApplications.Select an application and open the Details tab.Click the Tags field.Select one or more tags from the dropdown, or type to search.To create a new tag inline, type the tag name and select Create "[name]".Click Save.A maximum of 10 tags can be assigned to a single application.
Bulk Tag and Classify Applications
Administrators can assign or remove tags and classifications for multiple applications simultaneously.To perform a bulk operation:- From Strata Cloud Manager, select ConfigurationPrisma BrowserApplications.Select multiple applications using the checkboxes.Click Set Classification & Tags in the toolbar.
Modify the classification or tags as needed:- Classification - Select the new value. This applies to all selected applications.
- Tags - Add or remove tags. Added tags are appended to each application's existing tags.
Click Save.
All changes enter Draft state. The changes need to be publisged to apply..Edit Tags in Application Usage
Tags and classifications can also be updated directly from the Application Usage view.The Application Usage view always displays the latest draft state, not the published state.- From Strata Cloud Manager, select ConfigurationPrisma BrowserApplication Usage.Locate the application in the table.Click the classification badge or tags cell to edit inline.
Make changes and click Save.Unpublished changes display a visual draft indicator. A Review Changes link appears next to the indicator for users with publish permissions.Draft/Publish Workflow for Tags
All tag and classification changes follow the Prisma Browser Draft/Publish model:- Changes are saved as a draft.
- Drafts are visible immediately in the console but do not affect policy enforcement.
- An administrator with publish permissions reviews pending changes via Review Changes.
- After publishing, tag assignments take effect in policy rule evaluation and events enrichment.
Tags and Classification in Events
After publishing, tags and classifications are surfaced in the Events table:- Tags column - Displays the tags assigned to the application associated with each event.
- Classification column - Displays the classification of the application.
- Filters - Use the column picker and filter controls to filter events by tag or classification.
For more information, see Prisma Browser Investigations.Limitations
- Tags and classifications are stored locally in the Prisma Browser. Changes made in the Prisma Browser do not synchronize to Strata Cloud Manager or other Palo Alto Networks products.
- Bidirectional synchronization with Strata Cloud Manager is planned for a future release.
- Maximum of 10 tags per application.
- Maximum of 10,000 tags per tenant.
- Tag names are limited to 127 characters and are case-sensitive.
- Tag-based rule creation (using tags as conditions in policy rules via dynamic application groups) is planned for a near-term release.
Audit Trail
All tag and classification operations are logged in the Audit Trail:Action Audit Entry Create tag Tag "[Tag Name]" was created Rename tag Tag "[Tag Name]" updated: Name changed from "[Old]" to "[New]" Delete tag Tag "[Tag Name]" was deleted Assign/remove tags Application "[App Name]" was updated, tags changed from: "[Old Tags]" to: "[New Tags]" Change classification Application "[App Name]" was updated, classification changed from: "[Old]" to: "[New]" Bulk operations produce one audit entry per application, all with the same timestamp.