Important
Palo Alto Networks is rolling out a new, unified activation experience in
stages. For supported SASE products, you might see the new activation console
now, or you maybe directed to use the Hub for activation until the update
reaches your tenant.
| Where Can I Use This? | What Do I Need? |
|
|
Or any of the following licenses that include the SaaS Agent Security license:
- CASB-X
- CASB-PA
- SaaS Security Posture Management license
|
Activating the SaaS Agent Security license enables your organization to
address the unique security problems created by AI agents on SaaS platforms. The
service helps close visibility gaps and combat "Shadow AI," which often leave
security teams unable to properly track and govern AI agent usage. SaaS Agent Security also enables your data security administrators address
the risks of misconfigured agents with overly permissive access and protects against
runtime threats like prompt injection. By providing a comprehensive view of all AI
agents and their security postures, SaaS Agent Security ensures end-to-end
auditability and simplifies the generation of high-level reports for governance.
Additionally, SaaS Agent Security provides enhanced security and compliance
by preventing unauthorized access and misuse of privileges. SaaS Agent Security ensures that an organization's AI agent usage adheres
to best security practices through continuous monitoring and risk assessment, which
contributes to automated compliance. Activating the SaaS Agent Security
license also improves operational efficiency by providing automated enforcement
workflows that can remediate or terminate high-risk agents. This reduces the need
for manual intervention and speeds up incident response by allowing security teams
to create actionable tickets directly from security findings. Furthermore, SaaS Agent Security enables proactive threat mitigation by identifying and
flagging potential vulnerabilities in real-time before they can be exploited.
Activate the SaaS Agent Security License for CASB-X,
CASB-PA, and SSPM
Activate the CASB-X, CASB-PA, or SaaS Security Posture Management to get
access to SaaS Agent Security.
Contact your
Palo Alto Networks sales representative to purchase the
CASB-X, CASB-PA, or
SaaS Security Posture Management (SSPM)
license.
Activate the license.
Log in to
Strata Cloud Manager and select .
You can get started with SaaS Agent Security if you successfully
activated your CASB-X, CASB-PA, or SSPM license.
Get started with
SaaS Agent Security.
(
Optional)
Onboard the SSPM app for your
AI Agent Platform.
Onboarding the SSPM app enables SaaS Agent Security to map
user information to identity names obtained from SSPM. If you don't
onboard the corresponding SSPM app, SaaS Agent Security
security displays a string of random numeric characters instead of
specific user names or user email addresses. You aren't required to
onboard an SSPM app before onboarding an AI agent Platform.
Example of SaaS Agent Security User Information When You
Onboard an SSPM App
Example of SaaS Agent Security User Information When You
Don't Onboard an SSPM App
-