Focus
Strata Cloud Manager

Application Catalog

Table of Contents

Application Catalog

Classify and tag Palo Alto Networks–provided applications at the container level so settings apply automatically to all underlying App-Ids.
Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Strata Cloud Manager)
  • NGFW (Managed by Strata Cloud Manager)
  • At least one of these licenses is needed to manage your configuration with Strata Cloud Manager; for unified management of NGFWs and Prisma Access, you'll need both NGFW and Prisma Access licenses:
Strata Cloud Manager normalizes application names and consolidates application management into a unified view, so you no longer need to navigate across multiple pages to find the information required to configure security policy.
The ConfigurationApplication Catalog page in Strata Cloud Manager gives you a single location to view and manage all Palo Alto Networks-provided applications, with consistent naming across all services.
Unified Application Dictionary (UAD)-normalized names extend to all policy and configuration pages, so you see the same application name regardless of which page you are on. Security Policy Rules, Application Groups, Application Filters, SD-WAN, QoS, Application Override, Policy Based Forwarding, and WildFire® and Antivirus profiles all display the UAD product name, removing the need to cross-reference application names when building or troubleshooting policies.
From the ConfigurationApplication Catalog page, you can access application details, manage tags, review content updates, and classify applications. The application grid includes a Classification column that lets you designate each application as Sanctioned, Unclassified, or Tolerated. The predefined applications side panel provides comprehensive added unclassified metadata detail, including security and privacy attributes, compliance information, identity and access management capabilities, and GenAI-specific details, so you can review application attributes without leaving the page.
The Application Catalog gives you a consolidated view of all Palo Alto Networks–provided applications. You can review application details, assess risk, and apply a Sanctioned, Tolerated, or Unsanctioned classification or a custom tag directly from the catalog. Strata Cloud Manager automatically propagates your classification or tag to all underlying App-IDs.
Classifications you apply in AI Access are also synchronized with the Application Catalog. When you modify an application classification in AI Access, the updated classification appears in the Application Catalog and the Application-Tagging snippet is updated with the corresponding application tags automatically, keeping governance consistent across both surfaces.
The Application Catalog includes only Palo Alto Networks–provided applications. Custom applications you create in ConfigurationNGFW and Prisma AccessObjectsApplications do not appear in the catalog and do not affect the application count.
The Application Catalog stores two types of application data in the global Application-Tagging snippet:
  • Classification: Determines the app's policy status. Only one classification can be active per container: Sanctioned, Tolerated, or Unclassified. Applying a new classification automatically removes the previous one. An application with no classification is Untagged by default.
  • Tags: Descriptive labels used to organize and filter applications for policy. A container can carry multiple tags simultaneously. Includes system-generated predefined tags (for example, Web App, Enterprise VoIP), and admin-defined custom tags.
When you classify or tag applications in the Application Catalog, Strata Cloud Manager writes those classifications and tags to the Application-Tagging snippet. The Application-Tagging snippet is a predefined snippet associated with the global scope that stores all application classification and tag data across Strata Cloud Manager. Conversely, classification and tag changes you make to predefined applications in ConfigurationNGFW and Prisma AccessObjectsApplications are also reflected in the Application Catalog. Both surfaces read from and write to the same Application-Tagging snippet. Storing application data in a single global snippet makes it available across all product areas, including Security policy app filters, Activity Insights, and SaaS Inline.
The Application-Tagging snippet is now accessible as the Common container under Shared Configuration in the navigation. Strata Cloud Manager, Prisma® Browser, and Activity Insights all read from and write to this single source, so application classifications remain consistent across your environment.

Classify and Tag Applications

Use the Application Catalog to review application details and classify or tag applications to govern their use across your organization.
Use the Application Catalog to classify applications based on how your organization wants to govern their use. Strata Cloud Manager automatically propagates your classification or tag to all underlying App-IDs, so you don't need to configure each one individually.
  1. Log in to Strata Cloud Manager.
  2. Select ConfigurationApplication Catalog.
    The application catalog lists all Palo Alto Networks-provided applications. The total application count appears above the table.
  3. Review application details using the following columns:
    • Name: Normalized product name of the application.
    • App-ID Name: Underlying identifier used in security policy enforcement.
    • Classification: Governance status: Unclassified, Tolerated, Sanctioned, or Untagged.
    • Tags: Predefined system tags and any custom tags you've applied.
    • Category: Broad application grouping, such as SaaS or business-systems.
    • Subcategory: More specific grouping within the application's category.
    • Risk: Score from 1 (lowest) to 5 (highest), based on file sharing capability, misuse potential, and evasion behavior.
    • Application Type: Type of content the application handles.
    • Technology: How the application communicates over the network, such as browser-based or client-server.
    • Standard Ports: Default network ports the application uses.
    • Characteristics: Behavioral security attributes, such as Evasive, Excessive Bandwidth, or Vulnerability.
  4. (Optional) Use the Search bar to filter by category, subcategory, technology, risk, tags, or characteristics.
  5. (Optional) Click the > arrow next to a container to expand it and view its functional App-IDs. The number in parenthesis indicates how many functional App-IDs the container has.
  6. Select an application name to open the Application Details panel.
    The Application Details panel displays any applied tags as badges at the top, followed by these sections:
    • General: Basic identification and classification details.
    • Security and Privacy: Attributes to help you assess whether the application meets your security policy rules.
    • Identity and Access Management: Authentication and access control capabilities.
    • Compliance: Whether the application meets key standards and regulatory requirements.
    • GenAI: Details specific to generative AI applications.
    • Additional: Supplementary metadata.
  7. (Optional) To classify or tag one or more applications, select their checkboxes and click Add/Edit Tag.
    The Edit Application Tags panel opens with two sections:
    • Edit Classification: Select one classification. Only one is active at a time; selecting a new one removes the previous.
      • Unsanctioned: Explicitly prohibited or blocked.
      • Tolerated: Permitted but not IT-managed; typically restricted to certain user groups.
      • Sanctioned: Explicitly approved for business use.
      • Untagged: Removes any existing classification.
    • Edit Tags—Add or remove tags. When multiple applications are selected, choose to add new tags alongside existing ones or replace all existing tags. Predefined tags cannot be edited.
    Select the classification or tags to apply and click Save. The Classification and Tags columns update immediately. All functional App-IDs under the container inherit the assignment automatically.
  8. (Optional) To remove all tags from a classified application, select its checkbox and click Remove Tag.
  9. Push Config to push your configuration changes to your network.