Strata Cloud Manager
New Strata Cloud Manager Management Features (October 2025)
Table of Contents
Expand All
|
Collapse All
Strata Cloud Manager Docs
New Strata Cloud Manager Management Features (October 2025)
See the new configuration management features we've added to Strata Cloud Manager in
October 2025.
Here's the new configuration management features we've added to Strata Cloud
Manager in October 2025; we use a scheduled upgrade to deliver these features to you and
they are supported with the Cloud Manager 2025.R5.0 release version. Check your Strata
Cloud Manager in-product notifications for updates on the release upgrade schedule. You
can verify which Strata Cloud Manager release version you're running by navigating to
your configuration overview, and checking the
Cloud Management Version.
Configuration Management Support by Region
October 27, 2025 Supported on:
|
Strata Cloud Manager for Configuration Management is a solution that is defined and
controlled based on the region where it is deployed. You can deploy Strata Cloud
Manager in the locations of your choosing, based on data location preferences and
where you have the most users. This selection of locations allows for optimized
performance, adherence to data residency requirements, and tailored user experiences
based on geographical proximity. For this reason, we are rolling out region-specific
support for Strata Cloud Manager as soon as we are able to do so for each region.
You can now deploy Strata Cloud Manager in the following additional regions for
Configuration Management support in the Strata Cloud Manager 2025.R5.0 release:
Brazil, Italy, Korea, Poland, and Spain.
The Global Configuration search feature is now available across the following
regions: United States, Europe, and Singapore.
Migration Catalog in Strata Cloud Manager
|
October 27, 2025
Supported for Strata Cloud Manager.
|
Migration Catalog addresses the lack of
uniform workflows and discoverability across various migration efforts by providing
a single, centralized location for all migration-related activities in Strata Cloud
Manager. This catalog serves as a launching point for migration workflows, offering
visibility into available migration options and their prerequisites, which helps
administrators better understand Strata Cloud Manager’s migration capabilities.
When you access the Migration Catalog, you can view and select the
Panorama-managed NGFW migration. The catalog implements a consistent user experience
across different migration workflows based on a common stepper flow, similar to the
existing Panorama-based NGFW migration. This standardization makes it easier for you
to understand and navigate through the migration process regardless of which
specific migration you are performing.
For migration options, the catalog explains the high-level workflow and
prerequisites needed for successful configuration migration into Strata Cloud
Manager. This transparency helps you prepare adequately before initiating any
migration process, reducing the likelihood of encountering issues during migration
and increasing the chances of a smooth transition to Strata Cloud Manager.
Panorama to Strata Cloud Manager Migration for NGFWs
|
October 27, 2025
Supported for:
|
If you use Panorama to manage your organizations NGFWs, you can migrate your configurations to Strata
Cloud Manager for the benefits of cloud management.
Strata Cloud Manager enables you to migrate your organizations NGFW
hierarchy and configurations:
- Complete migration visibility and control — Accept and validate Panorama running configurations with pre-migration identification of unsupported elements.
- Flexible migration options — Choose partial or complete configuration migration based on your requirements.
- Conflict prevention — Automatic detection and display of previously migrated elements during subsequent migrations.
- Automated validation — Minimize the risk of configuration errors that could impact network security.
- Configuration continuity — Maintain your previous configurations throughout the migration process.
For the benefits of moving to Strata Cloud Manager, click here.
Shared Configuration Management
|
October 27, 2025
Supported for:
|
Shared configuration management eliminates the complexity of managing security
policies across multiple Palo Alto Networks services by allowing other Palo Alto
Networks services to subscribe to and receive configuration
objects from Strata Cloud Manager. Shared configuration management allows
you to independently implement features without introducing inconsistencies or
delays by providing a unified way for subscribers like Prisma SD-WAN Controller or
Branch Sites for Prisma SD-WAN Ion devices
to access and use Strata Cloud Manager managed NGFW and Prisma Access
configurations.
Palo Alto Networks services can access Strata Cloud Manager configuration objects on
a read-only basis while maintaining proper synchronization and usage tracking.
Shared configurations enable you to share Security Profiles such as Threat
Prevention, Anti-Spyware, Vulnerability Protection, URL Filtering, and DNS Security
with Prisma SD-WAN Controller instances. You can track which shared objects are
actively referenced by external services, and Strata Cloud Manager automatically
blocks deletion of configuration objects that are currently in use by external
subscribers to prevent configuration conflicts.
When making pushes to other services, reverting those pushes should be avoided as it
may cause issues with your configuration.
Zero Touch Provisioning NGFW Installer Web Application
|
October 27, 2025
Supported for:
|
You can now activate Palo Alto Networks NGFWs at branch locations using
the ZTP NGFW Activation web app that extends the
existing Zero Touch Provisioning (ZTP) capabilities to mobile devices.
This solution enables field installers to complete NGFW onboarding and activation
without requiring technical expertise or detailed knowledge of customer network
configurations. The web app is browser-based and supports both iOS and Android
devices, eliminating the need for separate native applications while maintaining
full compatibility with existing ZTP workflows.
The ZTP NGFW Activation web app allows for QR code scanning functionality
on Gen 5 or newer hardware that automatically populates device-specific information
including Serial Numbers and Claim Keys directly from labels affixed to the NGFW
hardware. When you scan a QR code using your mobile device's camera, the QR code
contains an embedded URL that redirects you to the ZTP Activation Page along with
the Serial Number and Claim Key data. The application automatically populates these
fields from the scanned QR code data, and you simply need to initiate the ZTP
activation process for the device.
You gain access to all existing ZTP activation features through the web
app, including the ability to view activation history for devices processed within
the last seven days and monitor the status of firewalls during the provisioning
process. The application maintains the same security and authentication requirements
as the desktop ZTP portal while optimizing the user interface for smartphones.
This web app addresses deployment scenarios where installers work across
multiple branch locations and may need to activate NGFWs for different customers
without carrying laptops or requiring detailed technical documentation. The solution
reduces the complexity of field deployments while maintaining the security and
configuration management oversight that network security teams require for firewall
provisioning workflows.