Enable Dynamic Privilege Access for Prisma Access Through Common Services
Focus
Focus
Prisma Access

Enable Dynamic Privilege Access for Prisma Access Through Common Services

Table of Contents

Enable Dynamic Privilege Access for Prisma Access Through Common Services

Learn how to activate Dynamic Privilege Access for your Prisma Access (Managed by Strata Cloud Manager) tenants through Common Services.
Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Strata Cloud Manager)
  • Prisma Access license with mobile user subscription
  • Activation link
  • Strata Logging Service
  • Cloud Identity Engine
  • Prisma Access Agent
  • Role: Multitenant Superuser or Superuser with access to the Customer Support Portal
With Dynamic Privilege Access, IT administrators can map end users to several customer projects. An authorized user is allowed access to only one customer project at a time.
Dynamic Privilege Access is an optional feature during the activation of a new Prisma Access tenant. After you enable this feature and the tenant is activated, DPA is set for the life of the tenant, and you can't disable it.
The option to enable DPA is available only once during the first activation of a new Prisma Access tenant. After the tenant is activated, the option is hidden for all the following activations, including add-ons and renewals. It's not available for existing tenants.
  1. Contact your Palo Alto Networks account representative to activate this functionality for your tenant.
  2. Activate the license for your Prisma Access (Managed by Strata Cloud Manager).
  3. Select the check box for Dynamic Privilege Access.
  4. Agree to the Terms and Conditions.
  5. Activate Now. The products and add-ons that you're activating (such as Prisma Access or Strata Logging Service) are now provisioned. As the subscriptions are activating, the progress status will display. When the process is complete, the tenant status displays as Up. You now have a tenant provisioned with instances of the products that you purchased. The tenant has one user — the account that you used when you began this process.
  6. To complete the remaining product setup, you must access the products you purchased and perform any required post-installation configuration. For information about your products, see:
  7. Add user access and assign roles.
    Provide access to users as Project Admin based on projects.