| Where Can I Use This? | What Do I Need? |
- Prisma Access (Managed by Strata Cloud Manager)
- Prisma Access (Managed by Panorama)
- NGFW (Managed by Panorama)
|
- Check the prerequisites for the deployment you're
using
- macOS 14 and later desktop devices
- Contact your Palo Alto Networks account representative to
activate the Prisma Access Agent feature
|
To set up the Prisma Access Agent on macOS devices, you will need to deploy an
installation package to the target endpoint. During the installation process, macOS
will prompt for various system permissions including system extension approval,
notification permissions, and Full Disk Access permissions for Prisma Access Agent processes.
For a streamlined deployment that
eliminates the need for end-user interaction or manual configuration by you, Palo
Alto Networks offers the V3 version of the configuration profiles, which consist of
two unified configuration profiles to aid in your deployment of
Prisma Access Agent. One configuration profile contains specifications for
Prisma Access Agent. The other configuration profile contains specifications
for
Endpoint DLP. Both configuration files
must be installed for
Prisma Access Agent. When the agent installer runs, it
automatically installs Endpoint DLP—the extensions must already be authorized or
macOS will prompt users to approve them.
You can use these profiles with Jamf Pro to deploy the Prisma Access Agent to
your managed macOS endpoints. The V3 configuration profiles are compatible with all
versions of Prisma Access Agent for macOS.
The Prisma Access Agent configuration profiles include the following
payloads:
- Content Filter
Payload type:
com.apple.webcontent-filter
- Notifications
Payload type:
com.apple.notificationsettings
- Privacy Preferences Policy Control
Payload type:
com.apple.TCC.configuration-profile-policy
- System Extensions
Payload type:
com.apple.system-extension-policy
- VPN
Payload type: com.apple.vpn.managed
The macOS System Settings window does not show Full Disk
Access permissions granted to the Prisma Access Agent by the configuration
profile.
The following procedure shows how to deploy Prisma Access Agent on macOS
endpoints using both unified configuration profile files from Palo Alto Networks.
Ensure that you perform the steps consecutively as described below. If you change
the order, the configuration profiles might not be available at the time the agent
requires them, which could cause unexpected behavior.