Application Catalog
Classify and tag Palo Alto Networks–provided applications at the container level so
settings apply automatically to all underlying App-Ids.
| Where Can I Use This? | What Do I Need? |
|
|
- At least one of these licenses is needed to manage your
configuration with Strata Cloud Manager; for unified
management of NGFWs and Prisma Access, you'll need both NGFW
and Prisma Access licenses:
|
Strata Cloud Manager normalizes application names and consolidates application management
into a unified view, so you no longer need to navigate across multiple pages to find the
information required to configure security policy.
The page in Strata Cloud Manager gives you a single location to view and
manage all Palo Alto Networks-provided applications, with consistent naming across all
services.
Unified Application Dictionary (UAD)-normalized names extend to all policy and
configuration pages, so you see the same application name regardless of which page you
are on. Security Policy Rules, Application Groups, Application Filters, SD-WAN, QoS,
Application Override, Policy Based Forwarding, and WildFire® and Antivirus profiles all
display the UAD product name, removing the need to cross-reference application names
when building or troubleshooting policies.
From the page, you can access application details, manage tags, review content
updates, and classify applications. The application grid includes a
Classification column that lets you designate each
application as Sanctioned, Unclassified,
or Tolerated. The predefined applications side panel provides
comprehensive added unclassified metadata detail, including security and privacy
attributes, compliance information, identity and access management capabilities, and
GenAI-specific details, so you can review application attributes without leaving the
page.
The Application Catalog gives you a consolidated view of all Palo Alto Networks–provided
applications. You can review application details, assess risk, and apply a Sanctioned,
Tolerated, or Unsanctioned classification or a custom tag directly from the catalog.
Strata Cloud Manager automatically propagates your classification or tag to all
underlying App-IDs.
Classifications you apply in AI Access are also synchronized with the Application
Catalog. When you modify an application classification in AI Access, the updated
classification appears in the Application Catalog and the Application-Tagging snippet is
updated with the corresponding application tags automatically, keeping governance
consistent across both surfaces.
The Application Catalog includes only Palo Alto Networks–provided applications. Custom
applications you create in do not appear in the catalog and do not affect the application
count.
The Application Catalog stores two types of application data in the global
Application-Tagging snippet:
When you classify or tag applications in the Application Catalog,
Strata Cloud Manager writes those classifications and tags to the
Application-Tagging snippet. The
Application-Tagging snippet is a predefined snippet
associated with the global scope that stores all application classification and tag data
across Strata Cloud Manager. Conversely, classification and tag changes you make to
predefined applications in are also reflected in the Application Catalog.
Both surfaces read from and write to the same
Application-Tagging snippet. Storing application data in a
single global snippet makes it available across all product areas, including Security
policy app filters, Activity Insights, and SaaS Inline.
The Application-Tagging snippet is now accessible as the
Common container under Shared
Configuration in the navigation. Strata Cloud Manager, Prisma® Browser,
and Activity Insights all read from and write to this single source, so application
classifications remain consistent across your environment.
Classify and Tag Applications
Use the Application Catalog to review application details and classify or tag
applications to govern their use across your organization.
Use the Application Catalog to classify applications based on how your
organization wants to govern their use. Strata Cloud Manager automatically
propagates your classification or tag to all underlying App-IDs, so you don't
need to configure each one individually.
Log in to
Strata Cloud Manager.
Select .
The application catalog lists all Palo Alto Networks-provided
applications. The total application count appears above the table.
Review application details using the following columns:
Name: Normalized product name of the
application.
App-ID Name: Underlying identifier used in
security policy enforcement.
Classification: Governance status:
Unclassified, Tolerated, Sanctioned, or Untagged.
Tags: Predefined system tags and any
custom tags you've applied.
Category: Broad application grouping, such
as SaaS or business-systems.
Subcategory: More specific grouping within
the application's category.
Risk: Score from 1 (lowest) to 5
(highest), based on file sharing capability, misuse potential,
and evasion behavior.
Application Type: Type of content the
application handles.
Technology: How the application
communicates over the network, such as browser-based or
client-server.
Standard Ports: Default network ports the
application uses.
Characteristics: Behavioral security
attributes, such as Evasive, Excessive Bandwidth, or
Vulnerability.
(
Optional) Use the
Search bar to filter by
category, subcategory, technology, risk, tags, or characteristics.
(
Optional) Click the
> arrow next to a
container to expand it and view its functional App-IDs. The number in
parenthesis indicates how many functional App-IDs the container has.
Select an application name to open the
Application
Details panel.
The Application Details panel displays any applied
tags as badges at the top, followed by these sections:
General: Basic identification and
classification details.
Security and Privacy: Attributes to help
you assess whether the application meets your security policy
rules.
Identity and Access Management:
Authentication and access control capabilities.
Compliance: Whether the application meets
key standards and regulatory requirements.
GenAI: Details specific to generative AI
applications.
Additional: Supplementary metadata.
(
Optional) To classify or tag one or more applications, select
their checkboxes and click
Add/Edit Tag.
The Edit Application Tags panel opens with two
sections:
Edit Classification: Select one
classification. Only one is active at a time; selecting a new
one removes the previous.
Unsanctioned: Explicitly
prohibited or blocked.
Tolerated: Permitted but not
IT-managed; typically restricted to certain user
groups.
Sanctioned: Explicitly approved
for business use.
Untagged: Removes any existing
classification.
Edit Tags—Add or remove tags. When
multiple applications are selected, choose to add new tags
alongside existing ones or replace all existing tags. Predefined
tags cannot be edited.
Select the classification or tags to apply and click
Save. The
Classification and
Tags columns update immediately. All
functional App-IDs under the container inherit the assignment
automatically.
(
Optional) To remove all tags from a classified application,
select its checkbox and click
Remove Tag.
-