Strata Cloud Manager
Best Practices
Table of Contents
Expand All
|
Collapse All
Strata Cloud Manager Docs
-
- Strata Copilot
- Command Center: Strata Cloud Manager
-
- Dashboard: Build a Custom Dashboard
- Dashboard: Executive Summary
-
- WildFire Dashboard: Filters
- WildFire Dashboard: Total Samples Submitted
- WildFire Dashboard: Analysis Insights
- WildFire Dashboard: Session Trends For Samples Submitted
- WildFire Dashboard: Verdict Distribution
- WildFire Dashboard: Top Applications Delivering Malicious Samples
- WildFire Dashboard: Top Users Impacted By Malicious Samples
- WildFire Dashboard: Top Malware Regions
- WildFire Dashboard: Top Firewalls
- Dashboard: DNS Security
- Dashboard: AI Runtime Security
- Dashboard: IoT Security
- Dashboard: Prisma Access
-
- Application Experience Dashboard: Mobile User Experience Card
- Application Experience Dashboard: Remote Site Experience Card
- Application Experience Dashboard: Experience Score Trends
- Application Experience Dashboard: Experience Score Across the Network
- Application Experience Dashboard: Global Distribution of Application Experience Scores
- Application Experience Dashboard: Experience Score for Top Monitored Sites
- Application Experience Dashboard: Experience Score for Top Monitored Apps
- Application Experience Dashboard: Application Performance Metrics
- Application Experience Dashboard: Network Performance Metrics
- Dashboard: Best Practices
- Dashboard: Compliance Summary
-
- Prisma SD-WAN Dashboard: Device to Controller Connectivity
- Prisma SD-WAN Dashboard: Applications
- Prisma SD-WAN Dashboard: Top Alerts by Priority
- Prisma SD-WAN Dashboard: Overall Link Quality
- Prisma SD-WAN Dashboard: Bandwidth Utilization
- Prisma SD-WAN Dashboard: Transaction Stats
- Prisma SD-WAN Dashboard: Predictive Analytics
- Dashboard: PAN-OS CVEs
- Dashboard: CDSS Adoption
- Dashboard: Feature Adoption
- Dashboard: On Demand BPA
- Manage: IoT Policy Recommendation
- Manage: Enterprise DLP
- Manage: SaaS Security
- Manage: Prisma Access Browser
- Reports: Strata Cloud Manager
-
-
- Strata Cloud Manager Release Information
-
- New Features in February 2025
- New Features in January 2025
- New Features in December 2024
- New Features in November 2024
- New Features in October 2024
- New Features in September 2024
- New Features in August 2024
- New Features in July 2024
- New Features in June 2024
- New Features in May 2024
- New Features in April 2024
- New Features in March 2024
- New Features in February 2024
- New Features in January 2024
- New Features in November 2023
- New Features in October 2023
- New Features in September 2023
- Known Issues
- Addressed Issues
- Getting Help
Best Practices
The best practices dashboard and reports measure your
security posture against Palo Alto Networks’ best practice guidance.
Where Can I Use This? | What Do I Need? |
---|---|
|
|
What does this dashboard show you?
The dashboard shows aggregated data per Prisma Access and NGFW/Panorama
associated with your tenant.
Navigate to Strata Cloud ManagerDashboardsMore DashboardsBest Practices dashboard to measure your security posture against Palo Alto
Networks’ best practice guidance. Importantly, the best practices assessment
includes checks for the Center for Internet Security’s Critical Security Controls
(CSC). CSC checks are called out separately from other best practice checks, so you
can easily pick out and prioritize updates that will bring you up to CSC
compliance.
How can you use the data from the dashboard?
While best practice guidance aims to help you bolster your security posture, findings
in this report can also help you to identify areas where you can make changes to
more effectively manage your environment.

The best practice dashboard is divided into five sections:
- SummaryGives you a comprehensive view of all the failed checks for a device across the configuration types (Security, Network, Identity, and Service Setup), View historical trend charts for BPA checks and assess your best practice adoption rate for key feature areas.
- SecurityShows the rules, rulebases, or profiles that are failing best practice and CSC checks for the selected device and location. When available, CLI remediations allow you to resolve issue with your policy rules. CLI remediations are generated using TSF data you upload when generating an On-Demand BPA Report.
- RulebasesLooks at how your policy is organized, and whether configuration settings that apply across many rules align with best practices (including CSC checks).
- RulesShows you the rules failing best practice and CSC checks. See where you can take quick action to fix failed checks. Rules are sorted based on session count, so you can start by reviewing and updating the rules that are impacting the most traffic.
- ProfilesShows you how your profiles stack up against best practices, including CSC checks. Profiles perform advanced inspection for traffic matched to a security or decryption rule.
- IdentityShows whether the authentication enforcement settings (authentication rule, authentication profile, and authentication portal) for a device meet the best practices and comply with CSC checks.
- NetworkChecks whether the application override rules and network settings align with best practice and CSC checks.
- Service SetupSee how the subscriptions you have enabled on your devices are aligning with the best practice and CSC checks. You can review the WildFire setup, GlobalProtect portal and GlobalProtect gateway configurations here and fix the failed checks.
Share, Download, and Schedule Reports for a Dashboard
You can download, share, and schedule reports covering the data the dashboard
displays in PDF and .csv formats displays, and CLI remediations in .txt format.
Find these icons in the top right of the dashboard:
