Strata Cloud Manager
Manage: Authentication Setup
Table of Contents
Expand All
|
Collapse All
Strata Cloud Manager Docs
-
- Strata Copilot
- Command Center: Strata Cloud Manager
-
- Dashboard: Build a Custom Dashboard
- Dashboard: Executive Summary
-
- WildFire Dashboard: Filters
- WildFire Dashboard: Total Samples Submitted
- WildFire Dashboard: Analysis Insights
- WildFire Dashboard: Session Trends For Samples Submitted
- WildFire Dashboard: Verdict Distribution
- WildFire Dashboard: Top Applications Delivering Malicious Samples
- WildFire Dashboard: Top Users Impacted By Malicious Samples
- WildFire Dashboard: Top Malware Regions
- WildFire Dashboard: Top Firewalls
- Dashboard: DNS Security
- Dashboard: AI Runtime Security
- Dashboard: IoT Security
- Dashboard: Prisma Access
-
- Application Experience Dashboard: Mobile User Experience Card
- Application Experience Dashboard: Remote Site Experience Card
- Application Experience Dashboard: Experience Score Trends
- Application Experience Dashboard: Experience Score Across the Network
- Application Experience Dashboard: Global Distribution of Application Experience Scores
- Application Experience Dashboard: Experience Score for Top Monitored Sites
- Application Experience Dashboard: Experience Score for Top Monitored Apps
- Application Experience Dashboard: Application Performance Metrics
- Application Experience Dashboard: Network Performance Metrics
- Dashboard: Best Practices
- Dashboard: Compliance Summary
-
- Prisma SD-WAN Dashboard: Device to Controller Connectivity
- Prisma SD-WAN Dashboard: Applications
- Prisma SD-WAN Dashboard: Top Alerts by Priority
- Prisma SD-WAN Dashboard: Overall Link Quality
- Prisma SD-WAN Dashboard: Bandwidth Utilization
- Prisma SD-WAN Dashboard: Transaction Stats
- Prisma SD-WAN Dashboard: Predictive Analytics
- Dashboard: PAN-OS CVEs
- Dashboard: CDSS Adoption
- Dashboard: Feature Adoption
- Dashboard: On Demand BPA
- Manage: IoT Policy Recommendation
- Manage: Enterprise DLP
- Manage: SaaS Security
- Manage: Prisma Access Browser
- Reports: Strata Cloud Manager
-
-
- Strata Cloud Manager Release Information
-
- New Features in February 2025
- New Features in January 2025
- New Features in December 2024
- New Features in November 2024
- New Features in October 2024
- New Features in September 2024
- New Features in August 2024
- New Features in July 2024
- New Features in June 2024
- New Features in May 2024
- New Features in April 2024
- New Features in March 2024
- New Features in February 2024
- New Features in January 2024
- New Features in November 2023
- New Features in October 2023
- New Features in September 2023
- Known Issues
- Addressed Issues
- Getting Help
Manage: Authentication Setup
Learn to setup and configure Authentication Rules and Profiles.
Where Can I Use This? | What Do I Need? |
---|---|
|
One of these:
→ The features and capabilities available to you in Strata Cloud Manager depend on which license(s) you are
using.
|
To set up authentication with Prisma Access in Strata Cloud Manager, first add your
authentication service(s) to Prisma Access. Then specify the traffic for which you
want to require authentication. Build on these settings to add more authentication
features, like MFA, authentication sequences, or enable Prisma Access to create and
update IP address to username mappings.
Here’s how to get started—all the settings you need to enable authentication with
Prisma Access are in one place: ManageIdentity ServicesAuthentication.

- Authentication Rules Here’s where you specify the traffic for which you want to require authenticationPart of setting up an Authentication Rule includes adding an authentication profile to the rule. When Prisma Access detects traffic that matching an authentication rule, it applies the authentication methods and settings defined in the authentication profile to the matching traffic. The profile is what defines how the users will be required to authenticate.
- Go to ManageIdentity and Access ServicesAuthenticationAuthentication Rule and Add Authentication Rule.
- Define the users, services, and URL categories that require authentication.
- Set the rule action to Authenticate and choose the Profile that defines the authentication method you want to use for traffic that matches this rule.
- Authentication Profile Add your authentication services here, and define authentication settingsConnect Prisma Access to the services you want to use to authenticate users—SAML, TACACS+, RADIUS, LDAP, or Kerberos—and define authentication settings (for example, set a limit for failed login attempts).If you are using an on-premise authentication service, you must first create a service connection to connect the on-premise authentication service to Prisma Access. Then, return here to set up your authentication profile.Go to ManageIdentity and Access ServicesAuthenticationAuthentication ProfileAdd Profile and start by setting the profile Auth Type:You’ll be prompted to add details about the authentication service you chose that will enable Prisma Access to connect to the service, and read user credentials and role permissions. Additional settings to customize authentication are provided in the profile, and might vary depending on the type of authentication you’re setting up.
- MFA Servers Specify the MFA vendor you’re usingTo use multiple methods to authenticate users to sensitive applications, start by adding the MFA vendors you want to use (Add MFA Server). Prisma Access provides a list of MFA vendors for you to choose from.
- Authentication Portal Set up the authentication portal (also known as Captive Portal) for users at remote network sites, and enable Prisma Access to create IP address to username mappingsFor first-factor authentication (login and password), users at remote network sites must authenticate through the authentication portal. If the authentication succeeds, Prisma Access displays an MFA login page for each additional authentication factor that’s required. Prisma Access uses the credentials users submit to create and update IP address to username mappings. This means that you’ll always know who at a remote network site is accessing web content and enterprise applications.
- Authentication Sequence Rank authentication profiles in the order you want Prisma Access to try themSelect ManageIdentity and Access ServicesAuthenticationAuthentication Profile and Add Authentication Sequence to rank your authentication profiles. Prisma Access checks each of them in sequence until one successfully authenticates the user.