Enforcing Access Control with Prisma Browser for Intune
Focus
Focus
Prisma Browser

Enforcing Access Control with Prisma Browser for Intune

Table of Contents

Enforcing Access Control with Prisma Browser for Intune

Enforcing Acccess Control - part of Intune
Where Can I Use This?What Do I Need?
To enforce robust enterprise mobility security on iOS, organizations can combine Microsoft Entra Conditional Access with Prisma Browser for Intune's native device compliance signal. Under this access control strategy, end users retain the flexibility to utilize Safari or secondary browsers for general internet browsing, while sensitive, corporate-sanctioned cloud applications (such as Microsoft 365 and SharePoint) are restricted exclusively to Prisma Browser for Intune on Intune-enrolled, compliant devices.
This posture is established through three interconnected Conditional Access policies working in tandem:
  • Policy 1 — Mobile Application Access Protection: Permits native mobile applications to authenticate when protected by an Intune App Protection Policy (APP) for non-Auth-Proxy traffic pathways.
  • Policy 2 — Device Compliance Enforcement: Mandates an explicit device compliance check prior to granting user authentication to Prisma Browser for Intune itself.
  • Policy 3 — Auth Proxy Perimeter Control: Grants access to sanctioned cloud resources when web traffic is explicitly routed through the dedicated Prisma Browser Auth Proxy egress infrastructure without requiring redundant app-level grants.
In combination, authentication requests to sanctioned corporate cloud applications succeed only if they originate from the verified Prisma Browser Auth Proxy egress IP addresses (Policy 3) or from approved native productivity apps containing an active App Protection Policy payload (Policy 1). Any unmanaged browser vector—including native Safari or Google Chrome—lacking these verified credentials will be systematically blocked.
Architecture Note: While this framework mirrors the Named Location and grant-control architecture implemented by standard enterprise browsers, a critical distinction exists on iOS: the "Require app protection policy" grant control cannot be directly applied to Prisma Browser for Intune due to WebKit rendering architecture restrictions, which prevent embedding the Intune SDK context into web views. Consequently, Policy 2 leverages the "Require device to be marked as compliant" grant control, which Prisma Browser for Intune fully supports when paired with the Microsoft Enterprise SSO extension configuration.

Prerequisite: Configure the Prisma Browser Auth Proxy Named Location

Policies 1 and 3 rely on a designated Named Location within Microsoft Entra ID representing the dedicated egress IP infrastructure of the Prisma Browser Auth Proxy. Admins must configure this network range prior to policy creation:
See “IP-Based Enforcement Using an Authentication Gateway” in the Prisma Browser tech docs: https://docs.paloaltonetworks.com/prisma-access-browser/integrations/first-party-integrations/ip-based-enforcement-using-an-authentication-gateway
In summary: Navigate within Strata Cloud Manager to Workflow > Prisma Browser > SSO Enforcement to provision dedicated egress IP addresses. Next, import these addresses into the Microsoft Entra Admin Center under Protection > Conditional Access > Named Locations as a trusted network object. Retain the exact object name for assignment within Policies 1 and 3.
Screenshot Placeholder: [Strata Cloud Manager – dedicated egress IP addresses]
Screenshot Placeholder: [Microsoft Entra Admin Center – Named Locations, showing the Auth Proxy IP range]

Policy 1 — Allow App Protection Policy for Non-Auth-Proxy Traffic

This policy ensures native Microsoft 365 client applications (such as Outlook, Teams, and OneDrive) that leverage their embedded Intune App Protection Policy framework retain uninterrupted access to corporate resources, even when their traffic does not pass through the Auth Proxy egress nodes.
  • Log in to the Microsoft Entra Admin Center.
  • Navigate to Conditional Access > Policies.
  • Click New policy and give it a descriptive name (e.g., “Allow App Protection Policy for Non-Auth-Proxy Traffic”).
  • Assignments > Users: Under Include, select the users or target groups.
  • Target resources > Cloud apps: Under Include, choose Select apps, then search for and select the sanctioned cloud apps (e.g., Office 365, SharePoint Online, Exchange Online).
  • Network: Under Exclude, choose Selected networks and locations, then select the Prisma Browser Auth Proxy Named Location configured above.
  • Conditions > Device platforms: Set Configure to Yes. Under Include, select Android and iOS. Click Done.
  • Conditions > Client apps: Set Configure to Yes. Check Mobile apps and desktop clients only (uncheck Browser). Click Done.
  • Access controls > Grant: Select Grant access. Check Require app protection policy. Click Select.
  • Enable policy: Set to Report-only first to monitor impact. Once verified via Entra sign-in logs, switch to On.
Screenshot Placeholder: [Conditional Access policy – Allow App Protection Policy for Non-Auth-Proxy Traffic, Grant controls step]

Policy 2 — Require Device to Be Marked as Compliant for Prisma Browser Login

This policy establishes perimeter security for the Prisma Browser for Intune enterprise application, ensuring that only managed devices fully enrolled in Intune and validated against compliance baselines can successfully complete authentication.
  • Log in to the Microsoft Entra Admin Center.
  • Navigate to Conditional Access > Policies.
  • Click New policy and give it a descriptive name (e.g., “Require Compliant Device for Prisma Browser Login”).
  • Assignments > Users: Under Include, select the users or target groups.
  • Target resources > Resources (formerly cloud apps): Under Include, choose Select resources > Select specific resources, then search for and select Prisma Browser (the verified third-party enterprise app; App ID edc4bc6b-9e08-4c12-91dc-2a3421facd71).
  • Conditions > Device platforms: Set Configure to Yes. Under Include, select Android and iOS. Click Done.
  • Access controls > Grant: Select Grant access. Check Require device to be marked as compliant. Under For multiple controls, select Require all the selected controls. Click Select.
  • Enable policy: Set to Report-only first to monitor impact. Once verified via Entra sign-in logs, switch to On.
Screenshot Placeholder: [Conditional Access policy – Require Compliant Device for Prisma Browser Login, Grant controls step]

Policy 3 — Allow Cloud Apps via the Prisma Browser Auth Proxy

This policy authorizes session requests to corporate cloud applications whenever traffic is verified as egressing from the trusted Prisma Browser Auth Proxy network. The network trust context established by the Auth Proxy satisfies conditional access without demanding separate app-level controls.
  • Log in to the Microsoft Entra Admin Center.
  • Navigate to Conditional Access > Policies.
  • Click New policy and give it a descriptive name (e.g., “Allow Cloud Apps via Prisma Browser Auth Proxy”).
  • Assignments > Users: Under Include, select the same users or target groups as Policy 1.
  • Target resources > Cloud apps: Under Include, choose Select apps, then select the same sanctioned cloud apps as Policy 1.
  • Network: Under Include, choose Selected networks and locations, then select the Prisma Browser Auth Proxy Named Location.
  • Conditions > Device platforms: Set Configure to Yes. Under Include, select Android and iOS. Click Done.
  • Access controls > Grant: Select Grant access. Leave grant controls unset — the network condition alone is sufficient.
  • Enable policy: Set to Report-only first to monitor impact. Once verified via Entra sign-in logs, switch to On.
Screenshot Placeholder: [Conditional Access policy – Allow Cloud Apps via Prisma Browser Auth Proxy, Network condition step]

Why This Blocks Safari and Other Browsers, But Allows Prisma Browser

  • Prisma Browser for Intune: can access the device management certificate → compliant → Allowed.
  • Safari: cannot access the device management certificate → non-compliant → Blocked.
  • Chrome and other browsers: cannot access the device management certificate → non-compliant → Blocked.
  • Native Microsoft 365 apps (Outlook, Teams, OneDrive): prove compliance via their own Intune SDK integration → compliant → Allowed (covered by Policy 1).

Validation

After creating all three policies:
  • Monitor each policy in Report-only mode for at least 24–48 hours.
  • Review sign-in logs in Entra ID > Sign-ins to verify: Prisma Browser for Intune access to sanctioned cloud apps succeeds; Safari and other browser access to the same apps is blocked (no matching allow policy); native Microsoft 365 apps (Outlook, Teams, OneDrive) are unaffected.
  • Look for any unexpected blocks (e.g., legitimate apps being denied).
  • Once confident, switch all three policies to On.
Testing checklist:
  • Open a sanctioned app (e.g., SharePoint) in Prisma Browser for Intune → should load successfully.
  • Open the same app in Safari → should be blocked.
  • Open the same app in Chrome → should be blocked.
  • Open OneDrive/Outlook native app → should work normally (covered by Policy 1).
Limitations:
  • Managed devices only: this approach requires devices to be enrolled in Intune (MDM). It does not apply to unmanaged BYOD devices using MAM-only.
  • WebKit limitation: On iOS, the “Require app protection policy” grant control does not work for Prisma Browser for Intune itself, because WebKit-based rendering does not carry the Intune SDK context — this is why Policy 2 uses “Require device to be marked as compliant” instead.