Authentication Factor
Table of Contents
Authentication Factor
Authentication Factor controls
| Prisma Browser Desktop | Prisma Browser Extension | Prisma Browser for Mobile |
|---|---|---|
| Full support | No support | Partial support |
The Authentication Factor is used to configure the authentication method
used by the Prisma Access Browser to trigger authentication for step-up MFA
authentication, browser lockscreen and unlocking the password manager. A single
authentication factor is used for all actions.
The Authentication factor is triggered by one of the following actions (if
configured):
- Web access > Require MFA
- Login controls . Login Form > MFA
- Data controls > Data Leak Prevention > File Download > Prompt > Require MFA
- Data controls > Data Leak Prevention > File Upload > Prompt > Require MFA
- Browser Security > Browser Session > Browser Lock
- From Strata Cloud Manager, select ConfigurationPrisma Browser PolicyControlsBrowser SecuritySelect Authentication Factor.Select one of the following options:
- PIN Code
- Configure the PIN code length (between 6-8 digits, to comply
with National Institute for Science and Technology
guidelines) and the number of attempts that can be made
before the account will be locked out.
- The default PIN code length is 6 digits
- Simple, weak, or commonly-guessed PIN codes (for example 111111, 123456) cannot be used.
- If the user is locked out, or they forget their PIN code,
they need to re-authenticate with their identity provider to
reset the PIN code. PIN codes are not synced between devices. Users need to create a separate PIN code on each device.
- Configure the PIN code length (between 6-8 digits, to comply
with National Institute for Science and Technology
guidelines) and the number of attempts that can be made
before the account will be locked out.
- Passkey
- Select the type of passkey that the users can create:
- Internal authenticator - Passkeys stored locally on the device such as Windows Hello or macOS keychain
- External authenticator - Passkeys stored externally,
on other devices, such as the user’s mobile phone,
security key (for example, a yubikey), or smartcard
Passkeys are not synced between devices. Users need to create a separate Passkey on each device.
- Select the type of passkey that the users can create:
- IdP Authentication
- Prisma Browser authentication profile – Re-authenticates the user with the same IdP authentication profile they used to log in to Prisma Browser.
- Choose profile – Gives admins flexibility by allowing them to
choose a dedicated authentication profile with different IdP
authentication factors from the standard Prisma Browser
login process (e.g. require Microsoft Authenticator). All Prisma Browser users must be provisioned in the identity provider and assigned to the application in the selected authentication profile. Otherwise, they will be unable to complete actions that require MFA.
To configure a dedicated profile:- Follow the instructions to create a new application in the identity
provider that will be used to authenticate users (Entra ID, Okta,
Other IdP)When creating an authentication type in CIE, select Dynamic service provider metadata
- Create a SAML authentication profile in CIE associated to the application you created in the identity provider.
- Choose the newly created profile in the Authentication Factor control.
- Use isolated browser session (incognito) - Starts each authentication attempt in a clean and isolated session, without cookies or cache. Admins can turn it off if they need to retain other cookies during IdP MFA. Turning this option off is required to enable pass-through authentication via Microsoft SSO - as an isolated browser session doesn't support it. This feature is enabled by default.
- Force Re-authentication - Prevents silent re-authentication by
requiring users to enter credentials each time.they have an active
IdP session
- Asks the identity provider to forcibly re authenticate (ForceAuthn=true) the user even if they had a pre-existing session with the IdP.
Click Set.