Authentication Factor
Focus
Focus

Authentication Factor

Table of Contents

Authentication Factor

Authentication Factor controls
Prisma Browser DesktopPrisma Browser ExtensionPrisma Browser for Mobile
Full supportNo support Partial support
The Authentication Factor is used to configure the authentication method used by the Prisma Access Browser to trigger authentication for step-up MFA authentication, browser lockscreen and unlocking the password manager. A single authentication factor is used for all actions.
The Authentication factor is triggered by one of the following actions (if configured):
  • Web access > Require MFA
  • Login controls . Login Form > MFA
  • Data controls > Data Leak Prevention > File Download > Prompt > Require MFA
  • Data controls > Data Leak Prevention > File Upload > Prompt > Require MFA
  • Browser Security > Browser Session > Browser Lock
  1. From Strata Cloud Manager, select ConfigurationPrisma Browser PolicyControlsBrowser Security
  2. Select Authentication Factor.
  3. Select one of the following options:
    • PIN Code
      • Configure the PIN code length (between 6-8 digits, to comply with National Institute for Science and Technology guidelines) and the number of attempts that can be made before the account will be locked out.
        • The default PIN code length is 6 digits
      • Simple, weak, or commonly-guessed PIN codes (for example 111111, 123456) cannot be used.
      • If the user is locked out, or they forget their PIN code, they need to re-authenticate with their identity provider to reset the PIN code.
        PIN codes are not synced between devices. Users need to create a separate PIN code on each device.
    • Passkey
      • Select the type of passkey that the users can create:
        • Internal authenticator - Passkeys stored locally on the device such as Windows Hello or macOS keychain
        • External authenticator - Passkeys stored externally, on other devices, such as the user’s mobile phone, security key (for example, a yubikey), or smartcard
          Passkeys are not synced between devices. Users need to create a separate Passkey on each device.
    • IdP Authentication
      • Prisma Browser authentication profile – Re-authenticates the user with the same IdP authentication profile they used to log in to Prisma Browser.
      • Choose profile – Gives admins flexibility by allowing them to choose a dedicated authentication profile with different IdP authentication factors from the standard Prisma Browser login process (e.g. require Microsoft Authenticator).
        All Prisma Browser users must be provisioned in the identity provider and assigned to the application in the selected authentication profile. Otherwise, they will be unable to complete actions that require MFA.
    To configure a dedicated profile:
    • Follow the instructions to create a new application in the identity provider that will be used to authenticate users (Entra ID, Okta, Other IdP)
      When creating an authentication type in CIE, select Dynamic service provider metadata
    • Create a SAML authentication profile in CIE associated to the application you created in the identity provider.
    • Choose the newly created profile in the Authentication Factor control.
    • Use isolated browser session (incognito) - Starts each authentication attempt in a clean and isolated session, without cookies or cache. Admins can turn it off if they need to retain other cookies during IdP MFA. Turning this option off is required to enable pass-through authentication via Microsoft SSO - as an isolated browser session doesn't support it. This feature is enabled by default.
    • Force Re-authentication - Prevents silent re-authentication by requiring users to enter credentials each time.they have an active IdP session
      • Asks the identity provider to forcibly re authenticate (ForceAuthn=true) the user even if they had a pre-existing session with the IdP.
    Important: When creating an authentication type in CIE, select “Dynamic service provider metadata”
  4. Click Set.