| Where Can I Use This? | What Do I Need? |
- NGFW (Managed by Panorama or Strata Cloud Manager)
- Prisma Access (Managed by Panorama or Strata Cloud Manager)
Prisma Browser
|
|
Activate the Next-Generation
CASB for Prisma Access and NGFW (CASB-X) license to get access to
the following data security cloud services offered by Palo Alto Networks for your
NGFW and Prisma Access tenants:
AI Access Security™
Enterprise Data Loss Prevention (E-DLP)
SaaS Security—Data Security (SaaS API), SaaS Security Inline, SaaS Security Posture Management (SSPM), and Behavior
Threats.
SaaS Agent Security
Before you can successfully activate the CASB-X license, you must have at least one Prisma Access tenant or NGFW associated with your Customer Support Portal (CSP) account.
You receive an email from Palo Alto Networks after purchasing
your CASB-X license. Click Login to
Activate in the email to activate the license for one of the
following use cases:
First Time Activation - Single Tenant—Create a new
tenant for a single CSP account
and activate the
CASB-X license.
First Time Activation - Multi-CSP and Multitenant—Create a
multitenant hierarchy and activate
the
CASB-X license for one or more newly created
subtenants when your account has access to multiple CSP accounts.
Return Visit Activation—Activate the
CASB-X
license for an existing single tenant or multitenant CSP account. Also
applies when you
transition from a single tenant
CSP to a multitenant CSP and if want to activate
CASB-X
for a
newly added tenant.
You cannot activate CASB-X if you already have the CASB
add-on bundle, or the add-ons associated with the bundle, activated on your
tenant. You cannot activate CASB-X if you do not have
Strata Logging Service activated on your tenant.
Activate CASB-X For a Single Customer Support Portal Account
Tenant
Learn how to activate your CASB-X application for the first time
if you have only one Customer Support Portal (CSP) account.
Associate
Prisma Access or
NGFW with your CSP account.
You must have at least one Prisma Access tenant or NGFW
associated with your CSP account to successfully activate the CASB-X license.
Allocate the product to the
Recipient of your choice.
The name provided matches your CSP account for convenience. You can use
the name provided or change it.
Select a
Region where you want to deploy your product.
The web interface shows if you have
Prisma Access and
NGFW available in this tenant where you can apply
CASB-X.
Agree to the terms and conditions, and
Activate.
A single default tenant is autocreated behind the scenes, and the product is
activated in the tenant.
This tenant, and any others created by this CSP account, have the
Superuser role created by default.
CASB-X activation is now complete for
Prisma Access. To apply
CASB-X on NGFW, you must go to the Device
Association tab to select the devices and apply the
CASB-X
license:
Activate CASB-X For a Customer Support Portal Account with Multiple
Tenants
Activate the Next-Generation
CASB for Prisma Access and NGFW (CASB-X) for a newly created a multitenant hierarchy
when your account has access to multiple Customer Support Portal (CSP) accounts.
Associate
Prisma Access or
NGFW with your CSP account.
You must have at least one Prisma Access tenant or NGFW
associated with your CSP account to successfully activate the CASB-X license.
Allocate the product to the
Recipient of your choice.
You can allocate your entire license to one recipient or you can share it
with multiple recipients in a tenant hierarchy.
What is a tenant?
If you need just one tenant, use or rename the tenant provided. The
name provided matches your Customer Support Portal account for
convenience.
(
Optional) This step applies if you are a managed security
service provider (MSSP), a distributed enterprise customer, or need
multiple tenants. After you create the first tenant, you can
Allocate to subtenant and use or rename the
tenant provided.
A subscription gets allocated on a tenant or a sub-tenant. This step
is for choosing a tenant where you want to allocate a license, not
for building a complete tenant hierarchy. You can create only a
tenant and subtenant here, and you can choose to allocate a license
to that subtenant.
Select
Done.
Select a
Region where you want to deploy your product.
The web interface shows if you have
Prisma Access and NGFW available
in this tenant where you can apply
CASB-X.
Agree to the terms and conditions, and
Activate.
This tenant, and any others created by this CSP account, have the
Superuser role created by default.
CASB-X activation is now complete for
Prisma Access. To apply
CASB-X on NGFW, you must go to the Device
Association tab to select the devices and apply the
CASB-X
license:
Return Visit CASB-X Activation
Learn how to activate the Next-Generation
CASB for Prisma Access and NGFW (CASB-X) license for an existing single
tenant or multitenant Customer Support Portal (CSP) account.
Select a
Recipient tenant or subtenant.
You can hover over each tenant to see if the tenant or subtenant already has
an active CASB-X license.
Verify the correct
Region displays. This selection is
based off the selected tenant or subtenant.
Review the
Assign Licenses section to review any
additional data security licenses included with your the
CASB-X license and whether you have
Prisma Access
tenants and
NGFW available to which you can apply the
CASB-X license.
For the
Data Loss Prevention tenant, select
None.
Selecting None creates a new Enterprise DLP
tenant. If you have already activated a trial or EVAL license, you must
create a new production Enterprise DLP.
Agree to the terms and conditions, and
Activate.
You successfully activated the
CASB-X license. You must now
apply the
CASB-X licenses to your
Prisma Access tenants
or
NGFW to begin your new data security services.