Enforcing Access Control with Prisma Browser for Intune
Enforcing Acccess Control - part of Intune
| Where Can I Use This? | What Do I Need? |
To enforce robust enterprise mobility security on iOS, organizations can
combine Microsoft Entra Conditional Access with Prisma Browser for Intune's native
device compliance signal. Under this access control strategy, end users retain the
flexibility to utilize Safari or secondary browsers for general internet browsing, while
sensitive, corporate-sanctioned cloud applications (such as Microsoft 365 and
SharePoint) are restricted exclusively to Prisma Browser for Intune on Intune-enrolled,
compliant devices.
This posture is established through three interconnected Conditional Access
policies working in tandem:
- Policy 1 — Mobile Application Access Protection: Permits native mobile
applications to authenticate when protected by an Intune App Protection Policy
(APP) for non-Auth-Proxy traffic pathways.
- Policy 2 — Device Compliance Enforcement: Mandates an explicit device
compliance check prior to granting user authentication to Prisma Browser for
Intune itself.
- Policy 3 — Auth Proxy Perimeter Control: Grants access to sanctioned
cloud resources when web traffic is explicitly routed through the dedicated
Prisma Browser Auth Proxy egress infrastructure without requiring redundant
app-level grants.
In combination, authentication requests to sanctioned corporate cloud
applications succeed only if they originate from the verified Prisma Browser Auth Proxy
egress IP addresses (Policy 3) or from approved native productivity apps containing an
active App Protection Policy payload (Policy 1). Any unmanaged browser vector—including
native Safari or Google Chrome—lacking these verified credentials will be systematically
blocked.
Architecture Note: While this framework mirrors the Named Location and
grant-control architecture implemented by standard enterprise browsers, a critical
distinction exists on iOS: the "Require app protection policy" grant control cannot be
directly applied to Prisma Browser for Intune due to WebKit rendering architecture
restrictions, which prevent embedding the Intune SDK context into web views.
Consequently, Policy 2 leverages the "Require device to be marked as compliant" grant
control, which Prisma Browser for Intune fully supports when paired with the Microsoft
Enterprise SSO extension configuration.
Prerequisite: Configure the Prisma Browser Auth Proxy Named Location
Policies 1 and 3 rely on a designated Named Location within Microsoft Entra
ID representing the dedicated egress IP infrastructure of the Prisma Browser Auth
Proxy. Admins must configure this network range prior to policy creation:
See “IP-Based Enforcement Using an Authentication Gateway” in the Prisma
Browser tech docs:
https://docs.paloaltonetworks.com/prisma-access-browser/integrations/first-party-integrations/ip-based-enforcement-using-an-authentication-gateway
In summary: Navigate within Strata Cloud Manager to Workflow > Prisma
Browser > SSO Enforcement to provision dedicated egress IP addresses. Next,
import these addresses into the Microsoft Entra Admin Center under Protection >
Conditional Access > Named Locations as a trusted network object. Retain the
exact object name for assignment within Policies 1 and 3.
Screenshot Placeholder: [Strata Cloud Manager – dedicated egress IP
addresses]
Screenshot Placeholder: [Microsoft Entra Admin Center – Named Locations,
showing the Auth Proxy IP range]
Policy 1 — Allow App Protection Policy for Non-Auth-Proxy Traffic
This policy ensures native Microsoft 365 client applications (such as
Outlook, Teams, and OneDrive) that leverage their embedded Intune App Protection
Policy framework retain uninterrupted access to corporate resources, even when their
traffic does not pass through the Auth Proxy egress nodes.
Log in to the Microsoft Entra Admin Center.
Navigate to Conditional Access > Policies.
Click New policy and give it a descriptive name (e.g., “Allow App
Protection Policy for Non-Auth-Proxy Traffic”).
Assignments > Users: Under Include, select the users or target
groups.
Target resources > Cloud apps: Under Include, choose Select apps,
then search for and select the sanctioned cloud apps (e.g., Office 365,
SharePoint Online, Exchange Online).
Network: Under Exclude, choose Selected networks and locations,
then select the Prisma Browser Auth Proxy Named Location configured
above.
Conditions > Device platforms: Set Configure to Yes. Under Include,
select Android and iOS. Click Done.
Conditions > Client apps: Set Configure to Yes. Check Mobile apps
and desktop clients only (uncheck Browser). Click Done.
Access controls > Grant: Select Grant access. Check Require app
protection policy. Click Select.
Enable policy: Set to Report-only first to monitor impact. Once
verified via Entra sign-in logs, switch to On.
Screenshot Placeholder: [Conditional Access policy – Allow App Protection
Policy for Non-Auth-Proxy Traffic, Grant controls step]
Policy 2 — Require Device to Be Marked as Compliant for Prisma Browser
Login
This policy establishes perimeter security for the Prisma Browser for
Intune enterprise application, ensuring that only managed devices fully enrolled in
Intune and validated against compliance baselines can successfully complete
authentication.
Log in to the Microsoft Entra Admin Center.
Navigate to Conditional Access > Policies.
Click New policy and give it a descriptive name (e.g., “Require
Compliant Device for Prisma Browser Login”).
Assignments > Users: Under Include, select the users or target
groups.
Target resources > Resources (formerly cloud apps): Under Include,
choose Select resources > Select specific resources, then search for and
select Prisma Browser (the verified third-party enterprise app; App ID
edc4bc6b-9e08-4c12-91dc-2a3421facd71).
Conditions > Device platforms: Set Configure to Yes. Under Include,
select Android and iOS. Click Done.
Access controls > Grant: Select Grant access. Check Require device
to be marked as compliant. Under For multiple controls, select Require all
the selected controls. Click Select.
Enable policy: Set to Report-only first to monitor impact. Once
verified via Entra sign-in logs, switch to On.
Screenshot Placeholder: [Conditional Access policy – Require Compliant
Device for Prisma Browser Login, Grant controls step]
Policy 3 — Allow Cloud Apps via the Prisma Browser Auth Proxy
This policy authorizes session requests to corporate cloud applications
whenever traffic is verified as egressing from the trusted Prisma Browser Auth Proxy
network. The network trust context established by the Auth Proxy satisfies
conditional access without demanding separate app-level controls.
Log in to the Microsoft Entra Admin Center.
Navigate to Conditional Access > Policies.
Click New policy and give it a descriptive name (e.g., “Allow Cloud
Apps via Prisma Browser Auth Proxy”).
Assignments > Users: Under Include, select the same users or target
groups as Policy 1.
Target resources > Cloud apps: Under Include, choose Select apps,
then select the same sanctioned cloud apps as Policy 1.
Network: Under Include, choose Selected networks and locations,
then select the Prisma Browser Auth Proxy Named Location.
Conditions > Device platforms: Set Configure to Yes. Under Include,
select Android and iOS. Click Done.
Access controls > Grant: Select Grant access. Leave grant controls
unset — the network condition alone is sufficient.
Enable policy: Set to Report-only first to monitor impact. Once
verified via Entra sign-in logs, switch to On.
Screenshot Placeholder: [Conditional Access policy – Allow Cloud Apps via
Prisma Browser Auth Proxy, Network condition step]
Why This Blocks Safari and Other Browsers, But Allows Prisma Browser
Prisma Browser for Intune: can access the device management
certificate → compliant → Allowed.
Safari: cannot access the device management certificate →
non-compliant → Blocked.
Chrome and other browsers: cannot access the device management
certificate → non-compliant → Blocked.
Native Microsoft 365 apps (Outlook, Teams, OneDrive): prove
compliance via their own Intune SDK integration → compliant → Allowed
(covered by Policy 1).
Validation
After creating all three policies:
Monitor each policy in Report-only mode for at least 24–48
hours.
Review sign-in logs in Entra ID > Sign-ins to verify: Prisma
Browser for Intune access to sanctioned cloud apps succeeds; Safari and
other browser access to the same apps is blocked (no matching allow policy);
native Microsoft 365 apps (Outlook, Teams, OneDrive) are unaffected.
Look for any unexpected blocks (e.g., legitimate apps being
denied).
Once confident, switch all three policies to On.
Testing checklist:
Open a sanctioned app (e.g., SharePoint) in Prisma Browser for
Intune → should load successfully.
Open the same app in Safari → should be blocked.
Open the same app in Chrome → should be blocked.
Open OneDrive/Outlook native app → should work normally (covered by
Policy 1).
Limitations:
Managed devices only: this approach requires devices to be enrolled
in Intune (MDM). It does not apply to unmanaged BYOD devices using
MAM-only.
WebKit limitation: On iOS, the “Require app protection policy”
grant control does not work for Prisma Browser for Intune itself, because
WebKit-based rendering does not carry the Intune SDK context — this is why
Policy 2 uses “Require device to be marked as compliant” instead.