Tenant Service Group (TSG) Migration of Prisma SD-WAN Users
Expand all | Collapse all
Tenant Service Group (TSG) Migration of Prisma SD-WAN Users
Learn about the migration process of Prisma SD-WAN users to TSG.
Starting from June 2023, we will begin the next phase of transitioning Prisma SD-WAN tenants
activated before June 2022 to the SASE platform. If your tenant uses third-party IDP or
Custom Roles, you will be included in this phase of migration. If your tenant was
activated after June 2022, you are already on the SASE platform and no migration is
required.
What does this migration mean?
In the backend, we are continuing the migration of Prisma SD-WAN tenants to a common TSG
structure (Tenant Service Group) starting from June 2023.
A TSG can contain instances of multiple products (For example, one TSG can
contain a Prisma SD-WAN instance, PA instance, CDL instance, and CDSS service
instance.)
Users will have access to IAM (Identity and Access Management) module for user
roles and permissions and access to APIs from a centralized API gateway.
Users will now be able to utilize the
new SASE SDK, which will support other
SASE services in addition to Prisma SD-WAN.
Current Prisma SD-WAN APIs and its endpoints will continue to function post
migration.
Users will not have any service disruption or any impact on the infrastructure
or data paths.
What will a user see after this transition?
If you use local user access, you may receive an email after the migration has
occurred with instructions to access
Prisma SASE. See the
Prisma SASE activation workflow. If
you are using a third-party IDP, you will not receive an email.
If you are identified as a user that requires to be onboarded into PANW IDP
(CSP), you will be able to log in to the Prisma SD-WAN web interface, but will
see a Login timer banner for 30 days advising you to finalize your user creation
in PANW IDP (CSP). After 30 Days, access via direct login will no longer be
allowed.