Software NGFW Credit Distribution and Management
Focus
Focus
Cloud NGFW for Azure

Software NGFW Credit Distribution and Management

Table of Contents

Software NGFW Credit Distribution and Management

Interchange and allocate credits among your Cloud NGFW resources regardless of the Cloud deployment method.
Where Can I Use This?What Do I Need?
  • Cloud NGFW for Azure
  • Cloud NGFW subscription
  • Palo Alto Networks Customer Support Portals (CSP) account
  • Azure Marketplace subscription
You can procure and associate Software NGFW credits to your Cloud NGFW tenants by paying an upfront cost for a long-term contract of one, two, or three years. You can procure these credits directly from Palo Alto Networks and its partners. Your Palo Alto Networks sales teams and its partners can send these credits to you directly or by using the Cloud provider marketplace private offers. These private offers (also referred to as Azure Private Offers, or Azure Multiparty Private Offers) allow you to take advantage of Cloud Marketplace benefits such as consolidated billing, and their spend commitments (Azure MACC).
Software NGFW credits allow you to consume Cloud NGFW resources in your tenant at a lower cost than PAYG rates, up to a specific capacity until your contract expires and automated or configurable renewals. Software NGFW credits fund your consumption of Cloud NGFW resources and their related usage of CDSS and centralized management (Panorama, Strata Cloud Manager, and Strata Logging Service).
Consider the following when using Software NGFW credits:
  • Software NGFW credits are term-based. Terms can be defined for any amount of time between one and five years. Both allocated and unallocated credits expire at the end of the agreed-upon term.
  • If your monthly average consumption exceeds the purchased credits, overages are charged at PAYG rates.
  • If you add Software NGFW credits during a free-trial period, your contract starts immediately and overrides the free trial.
  • Use the Cloud NGFW pricing estimator to help you determine pricing for your Cloud NGFW tenant.
  • You can procure credits for Cloud NGFW and all the CDSS services you intend to use for Cloud NGFW.

Start Using Software NGFW Credits with Cloud NGFW

Once you book the order for credits, they become active immediately, and an email is sent to enable you to start using your credits; for example, if you purchased credits for a one year term on September 6, 2026, the credits are active that day while the term lasts, in the case of this example, until September 5, 2027. The person listed as the administrative contact in the quote receives the activation email. The email provides details about the subscription, the credit pool ID, the subscription start and end date, the number of credits purchased, and the description of the default credit pool. You can use these details to activate credits in your Customer Support Portal (CSP) account.
Palo Alto Networks recommends retaining this email to access information related to your account.
Cloud NGFW will only begin consuming credits AFTER the DP is associated. Failure to do so will result in continued PAYG billing.
You will select one of your CSP accounts for the credit pool during activation. Once your credit pool is active, you can manage and allocate the credits to your Cloud NGFW tenants using the Credit Management Application described below.
  1. In the email, click Activate.
  2. After clicking Activate, you’re redirected to the CSP. Select the CSP account in which you want to activate the credits.
  3. Select Start Activation to start using your credits by depositing them into the CSP and allocating the credits.
  4. Select the Palo Alto Networks Customer Support portal account (you can search by account number or name) where you want to deposit the credits and clickDeposit Credits:
  5. You can view your deposited credits in the customer support portal (CSP):
    1. In the CSP, within the left navigation panel go to Product, select Software/Cloud NGFW Credits.
    2. Use the Account Selector to ensure that you're viewing the correct account, then click Cloud NGFW Credits to display the credit pools associated with the account.
  6. Click Go to Cloud NGFW Credits to access the Cloud NGFW Credit Management application in the Palo Alto Networks hub.

Manage Credits

The Cloud NGFW Credit Management Application provides a single location where you can manage your purchased credit pools, create deployment profiles and associate them with your Cloud NGFW tenants. The credit configuration process depends on whether you are deploying Cloud NGFW credit allocations or Software NGFW credit allocations. Follow the appropriate section below for your deployment type.

Option A: When Using Cloud NGFW Credits

  1. In the Hub, click Cloud NGFW Credit Management to display the app:
    The Cloud NGFW Credit Management application displays the credit pools associated with the CSP account:
    Each credit pool, displayed as an individual tile, provides two options:
    • Check Details. Use this option to display information about the credit pool. If a deployment profile already exists, it appears in the Deployment Profile table:
    • Create Deployment Profile. Use this option to create a deployment profile to consume activated credits from the pool.
    Before you create a deployment profile, estimate the number of firewalls that will use the configuration. You don’t have to deploy all the firewalls at once.
  2. Click Create Deployment Profile. In the Create Deployment Profile screen, specify the following information:
    1. In the Name field, use the drop-down menu to select the Credit Pool ID from the list of available options. Enter the corresponding name for the credit pool ID.
    2. Select the Cloud Type (either Amazon Web Services or Microsoft Azure).
    3. Use the drop-down menu to select the Cloud NGFW Serial Number.
      If you don’t see a Cloud NGFW Serial number in the drop-down, ensure that you’re subscribed to the Cloud NGFW service, and that the tenant isn’t associated with another CSP account.
    4. Specify the Number of Credits you want to allocate from the credit pool; the number of available credits from the credit pool appears.
    5. (Optional) Include a description.
    6. Click Save.
    After you have successfully created the deployment profile, the CNGFW Credits page displays the newly created profile along with the number of allocated credits:

Option B: When Using Software NGFW Credits

Configuring Software NGFW credits requires two steps: creating a parent deployment profile in the Customer Support Portal (CSP), then configuring a child deployment profile in the Credit Management System (CMS) Hub App.
Step 1: Create a Parent Deployment Profile (CSP)
  1. Log in to your Palo Alto Networks Customer Support Portal (CSP).
  2. In the left navigation menu, expand Products and select Software/Cloud NGFW Credits.
  3. Click Create New Profile.
  4. Provide a descriptive name, select your target unified pool SKU, and specify CNGFW as the primary service type.
  5. Enter your desired credit capacity and click Submit.
    The global unallocated support balance will show a reduction equal to your input amount plus the 18% support overhead block.
  6. Copy the automatically generated DP Authorization Code (AuthCode) from the profile grid for confirmation tracking.
  7. Click Create Deployment Profile.
Step 2: Configure a Child Deployment Profile on Credit Management System (CMS Hub App)
  1. Log in to the CMS Hub App.
    The dashboard automatically fetches your updated unallocated details from backend IT microservices. A credit pool container matching your CSP configuration appears, labeled with your DP AuthCode.
  2. Click Create Deployment Profile on the target credit pool row.
  3. Select Microsoft Azure as your cloud infrastructure provider.
  4. Enter the target Azure Tenant ID and assign a specific credit allocation limit to this tenant.
  5. Check or uncheck the Enable Smart Credit Buffer checkbox depending on your overage preferences.
    During Deployment Profile setup or modification on CMS, use a manual checkbox control (Enable SmartCredit Buffer) to alter buffer access rules.
    • Enable Smart Credit Buffer enabled (default): If an overage occurs, the tenant automatically draws from the central unallocated credit buffer. If the buffer has a sufficient balance, it covers the entire overage, resulting in zero direct marketplace PAYG charges for that billing period.
    • Enable Smart Credit Buffer disabled: Enforces strict budgetary isolation for an individual environment (such as an isolated lab or testing tenant). If consumption breaches the assigned limit, the system bypasses the unallocated pool and routes the overage directly to Azure Marketplace PAYG billing.
    If multiple active Azure tenants exceed their allocated budgets in the same hour, the system satisfies requests using a first-come, first-served strategy based on when each billing microservice reaches the validation step. If the total shared overage exceeds the available buffer, any remaining uncovered consumption overflows to standard marketplace PAYG tracking.
  6. Click Save.

Manage Deployment Profiles in Credit Management System (CMS)

After you create your deployment profile you can edit (add or remove allocated credits), delete it, or view an audit trail. Before modifying your deployment profile, ensure that you understand the following terms—consumption and allocation in the context of Software NGFW credits:
  • Consumption—the number for Software NGFW credits used by a deployment profile to license deployed firewalls and subscriptions.
  • Allocation—the total number of Software NGFW credits assigned to a particular deployment profile.
Edit a Deployment Profile
To edit an existing deployment profile:
  1. In the Cloud NGFW Credits page, select the deployment profile you want to edit.
  2. In the Edit Deployment Profile screen, change the Number of Credits.
    The number of available credits appears below the Number of Credits field.
  3. After changing the number of credits, click Save.

View an Audit Trail

The Cloud NGFW Credit Management application provides an audit trail that allows you to track changes made to a deployment profile. This information includes:
  • Date and time when the deployment profile was modified.
  • The serial number associated with the deployment profile.
  • The profile name.
  • The status, for example, edited.
  • Modified by indicates the user who edited the deployment profile.
  • The description describes the nature of the change.
To view an audit trail, in the Cloud NGFW Credits page, click Audit Trail.

Tracking Tenant Usage Details on CMS Hub

The Cloud Next-Generation Firewall (CNGFW) platform automatically monitors and streams tenant information and credit usage statistics to a backend data lake maintained by Palo Alto Networks.
  1. Log in to the CMS Hub App and select Chart View to display an interactive layout that visualizes real-time and historical peaks.
  2. Click Table View in the top-right corner of the dashboard to track historical consumption by date period across all columns.