| Where Can I Use This? | What Do I Need? |
- Prisma Access (Managed by Strata Cloud Manager)
- Prisma Access (Managed by Panorama)
- NGFW (Managed by Panorama)
|
- Check the prerequisites for the deployment you're
using
- macOS 14 and later desktop devices
- Contact your Palo Alto Networks account representative to
activate the Prisma Access Agent feature
|
Create and deploy configuration profiles for Prisma Access Agents that define
how the Prisma Access Agent is configured on managed macOS devices. For
example, you can set up the configuration profile to automatically load system
extensions to provide a seamless experience for users running the Prisma Access Agent to access the internet, SaaS applications, and private
applications and resources in your organization.
You will need to create two
configuration profiles: one for
Prisma Access Agent, and the other for
Endpoint DLP. Both configuration files
must be installed for
Prisma Access Agent. When the agent installer runs, it
automatically installs Endpoint DLP—the extensions must already be authorized or
macOS will prompt users to approve them.
This configuration profiles will automatically load the following extensions on a
managed endpoint:
- PAA Network Extension (com.paloaltonetworks.pang.networkextension)
- PAA Security Extension (com.paloaltonetworks.pang.securityextension)
- Endpoint DLP enforcer extension (com.paloaltonetworks.pangdlp.enforcer)
- Endpoint DLP network filter extension
(com.paloaltonetworks.pangdlp.netfilterdlp)
After you deploy the agent, you can run the
systemextensionsctl
list command on an endpoint to verify that the extensions have been
loaded. For example:
If you previously deployed other Palo Alto Networks apps such as GlobalProtect™
and Cortex® XDR® to your endpoints, when deploying the system extensions via
mobile device management (MDM) software, the configuration profiles for Prisma Access Agent and the other Palo Alto Networks apps must include the
Allowed System Extension and Removable
System Extension settings. If only one of the profiles has the
removable system extension, the uninstallation of Prisma Access Agent
won’t complete.
The following procedure is based on the Prisma Access Agent unified
configuration profiles (V3).