Use the Password Manager
Focus
Focus

Use the Password Manager

Table of Contents

Use the Password Manager

Store, organize, and autofill credentials for web applications using the Prisma Browser Password Manager.
Where Can I Use This?What Do I Need?
  • Strata Cloud Manager
  • Prisma Browser standalone
  • Prisma Access with Prisma Browser bundle license or Prisma Browser standalone license
  • Password Manager enabled in policy
  • Connectivity to *.cyberark.cloud and *.idaptive.app

Access the Password Manager

The Password Manager is accessible from multiple locations within the Prisma Browser:
  • Toolbar — Click the Password Manager icon (key icon) in the browser toolbar.
  • Browser menu — Select Passwords and autofillPassword Manager from the browser menu.
  • Settings — Navigate to the toolbar customization panel and enable the Password Manager toggle.
The Password Manager opens in a side panel displaying the account inventory.

View and Manage Accounts

The Password Manager side panel displays all stored accounts. Each account shows the web application name (or URL) and associated username.
  • Search — Enter text in the search field to filter accounts by name or username.
  • Sort — Select the sort option to order accounts by frequency of use.
  • Filter — Select filter chips to display only Accounts or Remote Connections.

Account Details

Select an account from the inventory to view its details in the Details tab:
  • URL — The login page address. Click the external link icon to open the URL, or the copy icon to copy it.
  • Match detection — Controls how the Password Manager identifies this account on web pages. Click + Match detection to select a type:
    • Base domain (default) — Matches any URL containing the same base domain, ignoring subdomains and paths (e.g., example.com matches www.example.com/login and app.example.com).
    • Regular expression — Matches URLs fitting a custom pattern (e.g., https://*.example.com matches any subdomain).
    • Exact match — The browser URL must match the configured URL exactly.
    • Hostname — Matches all pages sharing the same hostname, ignoring paths but not subdomains (e.g., app.example.com matches app.example.com/settings but not www.example.com).
  • Auto-login — Enable to automatically sign in when visiting this account's URL.
  • Username — The login username or email.
  • Password — The login password (masked, with strength indicator).
  • Authentication Key — Stores a TOTP secret for accounts that require two-factor authentication. Paste the key (also called "setup key" or "two-factor secret") from the target application's MFA enrollment page. Once saved, the Password Manager automatically generates and fills the time-based code (valid for 30 seconds) during sign-in. If autofill is unavailable, right-click the code field and select the Password Manager context menu to copy the verification code.
  • Description — Optional text describing the account.
  • Tags — Optional tags for organizing accounts (under "More (optional)").
  • Note — Optional free-text notes (under "More (optional)").

Add Accounts

Add an Account from the Catalog

The Password Manager includes a catalog of known web applications. Applications added from the catalog support automatic login — the Password Manager knows the login page structure and can fill credentials without additional configuration.
  1. Open the Password Manager side panel.
  2. Click AddAccount.
  3. Browse or search the catalog for the web application.
  4. Select the application and enter credentials (username and password).
  5. Click Add account.

Add a Custom Account

For web applications not in the catalog, add a custom account manually:
  1. Open the Password Manager side panel.
  2. Click AddAccount.
  3. Select + Add custom account.
  4. Enter the account details:
    • Account name — A descriptive name.
    • URL — The login page address.
    • Match detection — Optionally select how the Password Manager matches this URL (Base domain, Regular expression, Exact match, or Hostname). Defaults to Base domain.
    • Auto-login — Optionally enable automatic sign-in.
    • Username — The login username or email.
    • Password — The login password.
    • Authentication Key — If the application requires two-factor authentication, paste the TOTP secret key from the application's MFA setup page.
    • Description, Tags, Note — Optional metadata for organization.
  5. Click Save.

Auto-Login and Prompt to Save

Auto-Login

When a user opens an account from the Password Manager inventory, the Prisma Browser navigates to the login URL and enters the credentials automatically. A "Signing in..." dialog displays during the process.
If an account has Auto-login enabled, the Prisma Browser automatically signs in when the user visits the account URL without requiring interaction.

Prompt to Save

When the Prisma Browser detects credentials entered on a login page:
  • New credentials — A prompt appears with the detected account name, username, and password. Select Yes, Add to save the account, No to dismiss, or Never for this site to suppress future prompts for this web application.
  • Updated credentials — If the credentials differ from a stored account, a prompt appears to update the existing account. Select the account to update from the dropdown, then click Update account. Alternatively, click Add new to save as a separate account.

Autofill on Login Pages

When the Prisma Browser detects a login page matching a stored account:
  • If one account matches, the credentials are available for autofill. Click the Password Manager icon in the form field to populate credentials.
  • If multiple accounts match, a selector displays available accounts. Select the desired account to initiate auto-login.

Share Accounts

Credential sharing is available only with Prisma Browser Pro. The Sharing tab does not appear for Prisma Browser Core users.
To share an account with colleagues:
  1. Open the Password Manager side panel.
  2. Select the account to share.
  3. Select the Sharing tab.
  4. Click Share.
  5. Under Shared with, click + Add to search for users or groups. Results display individual users and directory groups. Filter by All, Users, or Groups tabs.
  6. Under Access permissions, configure:
    • Launch — The recipient can use the account to sign in. Credential values are not revealed.
    • View — The recipient can view the credential values.
    • Edit — The recipient can modify the account details and credentials.
    • Owner — The recipient has full ownership, including the ability to delete or reshare.
  7. Optionally set From / To dates for time-limited access.
  8. Click Save.

Import Accounts

Import from the Legacy Password Manager

  1. Open the Password Manager side panel.
  2. Click the overflow menu (three dots) > Import.
  3. Select Prisma browser.
  4. Choose an import method:
    • Direct — Pulls accounts directly from the Legacy Password Manager installed on this browser. Select Skip duplicate accounts to avoid importing credentials that already exist.
    • Browse — Upload a CSV file previously exported from the Legacy Password Manager.
When the Password Manager is first enabled, import from the Legacy Password Manager is triggered automatically.

Import from LastPass

  1. Open the Password Manager side panel.
  2. Click the overflow menu (three dots) > Import.
  3. Select LastPass.
  4. Choose an import method:
    • Browse — Upload a CSV file exported from LastPass.
    • Direct — Enter LastPass credentials (username and password) to import directly via API.
  5. Configure options: Import shared folders, Skip adding items to any shared folders, Skip duplicate accounts.

Import from Other Sources

To import credentials from Dashlane, Google, KeePass, or another password manager:
  1. Open the Password Manager side panel.
  2. Click the overflow menu (three dots) > Import.
  3. Select the source (Dashlane, Google, KeePass, or Other).
  4. Drag a CSV file or click browse to upload. For KeePass, CSV or KDBX files are accepted. For Other, click Download to obtain the CSV template.
  5. Select Skip duplicate accounts to avoid importing credentials that already exist.

View Previous Imports

Expand the Previous Import Logs section at the bottom of the import page to review past import operations.

Generate a Password

  1. Open the Password Manager side panel.
  2. Click the overflow menu (three dots) > Generate Password.
  3. Select the Password tab for a random character string, or Passphrase tab for a word-based password.
  4. Adjust the character count (default: 16). Enable or disable character types: Lowercase, Uppercase, Numbers, Symbols.
  5. The generated password displays with a strength indicator. Click the copy icon to copy to clipboard, or the refresh icon to generate a new one.

Settings

To configure Password Manager settings, click the overflow menu (three dots) > Settings:
  • Open accounts in a new browser tab — When enabled, clicking an account in the inventory opens the login page in a new tab.
  • Enable Prompt to save on this computer — When enabled, the Prisma Browser prompts to save new credentials detected on login pages.
  • Clear Skipped Sites — Remove all entries from the "Never for this site" suppression list.
Under Advanced:
  • Enable diagnostic log — Enable verbose logging for troubleshooting.
  • Export Diagnostics Log — Download the diagnostic log for support purposes.