Set Up Privileged Remote Access Profiles
Focus
Prisma Access

Set Up Privileged Remote Access Profiles

Table of Contents

Set Up Privileged Remote Access Profiles

Create Privileged Remote Access profiles that define what capabilities should be enabled when the user is accessing an app from the PRA portal.
Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Panorama or Strata Cloud Manager)
  • Prisma Access 5.2.1
  • Minimum Prisma Access dataplane version: 11.2.4
  • Prisma Access license with a Mobile User subscription
  • Privileged Remote Access add-on license
After you configured the apps your users can access from the Privileged Remote Access (PRA) portal, set up profiles that define the actions your users can perform when they access an app, such as copying, pasting, downloading, and uploading content.
You can define different actions depending on the type of protocol that is used to access an app.
For example, you can disable the copy and paste functions for RDP apps for a particular profile. When you associate this profile later with a PRA portal policy, the policy will automatically enable only the capabilities defined in the profile.
To set up a PRA profile:
  1. Navigate to the PRA Profiles page.
    • For Prisma Access (Managed by Strata Cloud Manager):
      1. Log in to Strata Cloud Manager as the administrator.
      2. Select ConfigurationPrivileged Remote AccessProfiles.
    • For Prisma Access (Managed by Panorama):
      1. Launch Privileged Remote Access from the Cloud Services plugin on Panorama by selecting PanoramaCloud ServicesPrivileged Remote Access.
      2. Click Get Started.
      3. Select ConfigurationPrivileged Remote AccessProfiles.
  2. You can view the list of profiles on the PRA Profiles table. By default, PRA provides a read-only profile (Default PRA Profile) that defines the actions a user can perform when using any apps that are defined in a PRA policy or any user-defined apps that you don't manage.
  3. To create a new profile, click Add Profile.
  4. Enter a Name for the profile and optionally provide a Description (Optional).
  5. Select the actions that your users can take when accessing an app in a PRA session. You can set controls for RDP, SSH, or VNC sessions.
    • RDP PROFILE—Set the following functions to Enabled or Disabled:
      • Copy—Copies content from the remote app or the user's local machine. (Default: Enabled)
      • Paste—Pastes content copied from the remote app to the local machine, or pastes content copied from the local machine to the remote app. (Default: Enabled)
      • File Upload—Uploads files from the local machine to the remote application. The maximum permitted file size is 100 MB. (Default: Disabled)
      • File Download—Downloads files from the remote application to the local machine. The maximum permitted file size is 100 MB. (Default: Disabled)
      • Audio Passthrough—Enables users to hear audio from the remote app on their device. If you disable this setting, no audio from the remote app is transmitted to the user's device. Applies only to RDP apps. (Default: Disabled)
    • SSH PROFILE—Set the following functions to Enabled or Disabled:
      • Copy—Copies content from the remote app or the user's local machine. (Default: Enabled)
      • Paste—Pastes content copied from the remote app to the local machine, or pastes content copied from the local machine to the remote app. (Default: Enabled)
      • File Upload—Uploads files from the local machine to the remote application. The maximum permitted file size is 100 MB. (Default: Disabled)
      • File Download—Downloads files from the remote application to the local machine. The maximum permitted file size is 100 MB. (Default: Disabled)
    • VNC PROFILE—Set the following functions to Enabled or Disabled:
      • Copy—Copies content from the remote app or the user's local machine. (Default: Enabled)
      • Paste—Pastes content copied from the remote app to the local machine, or pastes content copied from the local machine to the remote app. (Default: Enabled)
      • File Upload—Uploads files from the local machine to the remote application. The maximum permitted file size is 100 MB. (Default: Disabled)
      • File Download—Downloads files from the remote application to the local machine. The maximum permitted file size is 100 MB. (Default: Disabled)
  6. (Optional) If you need to restore the PRA profile to its initial settings, Reset it.
  7. Save your profile settings. Your profile is saved to the PRA Profiles table.