Automate With Proactive Plans
Focus
Focus
Strata Cloud Manager

Automate With Proactive Plans

Table of Contents

Automate With Proactive Plans

Enable and configure proactive plans so the Network Security Agent acts autonomously in response to incidents, schedules, and events in Strata Cloud Manager.
Where Can I Use This?What Do I Need?
  • Strata Cloud Manager
  • Strata Cloud Manager Pro
  • This feature is currently in Beta and available on request. Contact your account team to enable the feature.
  • Superuser role (for agent administration, onboarding, and managing permissions)
  • Network Administrator or Security Administrator role (for agent interaction)
Palo Alto Networks provides a library of pre-built proactive plans. You enable the plans relevant to your environment and associate each one with a trigger and Virtual Assistant Identity. When the trigger fires, the agent executes the plan using the Virtual Assistant identity you assigned. Context can be added to proactive plans. Results appear in Action Center, where users can review outcomes, approve pending write actions, and review execution summaries based on the plan's visibility settings.
Trigger Types
Trigger TypeHow It FiresExample
IncidentResponds to a specific Strata Cloud Manager incident signature.Tunnel-down detection triggers automatic troubleshooting.
ScheduledRuns at a defined recurring frequency (daily, weekly, monthly, or custom).Weekly posture audit scans for unused objects.
EventFires from an asynchronous internal API.New Unit 42 threat advisory triggers impact assessment.
Example: Pre-Built Proactive Plans
The following table lists examples of pre-built proactive plans available from Palo Alto Networks. Each plan is disabled by default and requires a Superuser to enable it.
PlanExpert AgentTrigger TypeDescription
Threat Advisory Impact AssessmentThreatEventEvaluates your security posture against newly published Unit 42 threat advisories and identifies coverage gaps.
CVE Exposure CheckThreatEventAssesses your environment for exposure to newly disclosed CVEs and generates remediation plans for unprotected attack vectors.
SD-WAN Link Health MonitorTroubleshootingIncidentResponds to SD-WAN link degradation events by diagnosing the affected circuit and recommending failover or remediation actions.

Configure Proactive Plans

  1. Select Strata Copilot and select Proactive Plans.
  2. Review the list of available plans. Each entry shows the plan name, trigger type, visibility, plan type, and current status (Active or Inactive).
  3. To enable a plan, toggle its status to Active.
  4. Configure the trigger settings:
    • For Incident triggers, select the incident signature that fires the plan.
    • For Scheduled triggers, set the frequency (daily, weekly, monthly, or custom interval).
    • For Event triggers, confirm the event source (for example, Unit 42 advisory feed).
  5. Assign a Virtual Assistant Identity identity to the plan.
    Select the identity that has the minimum required permissions for the plan's tasks. Avoid assigning Superuser identity unless the plan requires Superuser-level access.
  6. Select the role under Visibility of the proactive plan.
  7. Save.

Create Custom Proactive Plans

Create custom proactive plans in Strata™ Copilot to automate security operations and response workflows in Strata Cloud Manager. You can create a custom proactive plan by duplicating a pre-built plan. Copy an existing Palo Alto Networks® plan and modify the trigger, name, and description to match your requirements.
  1. Select Strata Copilot in Strata Cloud Manager and select Proactive Plans.
  2. To view the plan you want to copy, under Actions, select View next to that plan.
  3. Select the copy icon to copy the proactive plan.
  4. Enter a Name and a Description.
  5. Edit the trigger settings:
    • For Incident triggers, choose the incident signature that fires the plan.
    • For Scheduled triggers, set the frequency (such as daily, weekly, monthly, or a custom interval).
    • For Event triggers, confirm the event source (for example, the Unit 42® advisory feed).
  6. Assign a Virtual Assistant Identity identity to the plan.
    Select the identity that has the minimum required permissions for the plan's tasks. Avoid assigning Superuser identity unless the plan requires Superuser-level access.
  7. Select the role under Visibility of the proactive plan.
  8. Save.