Windows Account Based SSO Authentication
Focus
Focus

Windows Account Based SSO Authentication

Table of Contents

Windows Account Based SSO Authentication

This article discusses using the new Account based sso Authentication
Where Can I Use This?What Do I Need?
  • Strata Cloud Manager
  • Standalone Prisma Browser
  • Prisma Access with Prisma Browser bundle license or Prisma Browser standalone license
  • Prisma Browser Roles
  • Microsoft 365
This feature is available for Microsoft Windows and macOS devices.
Because this feature uses local logged in users for authentication against web applications, we advise that you use this feature on managed devices only, to avoid unexpected logins from unmanaged domains.
This update supports local account-based authentication via Microsoft Single Sign-On (SSO) and Active Directory (AD) integration, addressing key needs:
  • Passwordless Authentication - Enables secure access for users without traditional passwords, improving accessibility and reducing friction.
  • Stronger Admin Controls - Allows IT admins to enforce authentication through corporate-managed SSO accounts, minimizing unauthorized access and reducing reliance on passwords.
Taking advantage of this new capability, Prisma Access Browser now has a method for incorporating the Microsoft solution into our commitment to secure solutions that align with modern enterprise needs, especially as hybrid and remote work models grow.

Prisma Browser Sign-in Configuration

You can configure browser logins on managed devices using local Windows accounts linked to Active Directory. Choose one of the options below depending on your deployment requirements.

Option 1: Manual Username Entry

Use this option if users should manually enter their username (e.g., richarddorlinger@example.com). When they log in, their credentials are authenticated against the local machine, ensuring the entered username matches the locally logged-in user.
To configure this feature, set the following local registry key on managed devices:
reg add "HKLM\Software\Policies\Palo Alto Networks\PrismaAccessBrowser" /v ForceEnableMsSSO /t REG_DWORD /d 1 /f

Option 2: Fully Automatic Sign- In

You can enable fully automatic sign-in to Prisma Browser on managed devices. When configured, the browser signs users in automatically using their OS-level credentials. No username entry required.
Use this option for a seamless experience where the browser automatically signs users in using their OS-level credentials without requiring any username entry. The browser reads the signed-in user's identity from the operating system and locks authentication to that account.
Set the following local registry key on managed devices:
reg add "HKLM\Software\Policies\Palo Alto Networks\PrismaAccessBrowser" /v ForceEnableMsSSOAutoLogin /t REG_DWORD /d 1 /f
Option 2 encompasses all functionality of Option 1. You do not need to deploy both registry keys.
If the user's identity exists across multiple tenants, a tenant picker prompt is displayed. If automatic authentication cannot complete, the browser falls back to standard login where users enter their username without a password.

Automatic Web Application Sign-In Using Microsoft Entra ID

You can leverage Prisma Access Browser’s capabilities to enable seamless authentication during Microsoft SSO flows for web applications.
How It Works:
Enable the Microsoft SSO control when you create a Browser Customization rule. From Strata Cloud Manager, select Configuration>Prisma Access Browser> Policy>Profiles>Browser Customization, and select Microsoft Auto-SSO.
Once this is done, your users will be able to navigate to web applications and experience automatic sign-in using Microsoft SSO, authenticated via corporate Active Directory connections.

Support for Microsoft Entra on macOS Devices

Prisma Browser now supports Microsoft Enterprise SSO plug-in for Apple devices. This allows users to seamlessly authenticate to Microsoft Entra web apps.
What you need to do:
  1. Deploy and configure the Enterprise Single Sign On plug-in for Apple configured on macOs devices. The information can be found on the Microsoft Entra site.
  2. Make sure that the device is enrolled and has the Intune Company Portal, version 5.2504.0 or higher.
  3. Make sure that the minimum Prisma Browser version is 136.