Activate the Enterprise DLP License for Prisma Access
Focus
Focus
Enterprise DLP

Activate the Enterprise DLP License for Prisma Access

Table of Contents


Activate the Enterprise DLP License for Prisma Access

Activate the Enterprise Data Loss Prevention (E-DLP) license for your Prisma Access (Managed by Panorama or Strata Cloud Manager).
  1. Contact your Palo Alto Networks representative to purchase the Prisma Access and Enterprise DLP licenses.
  2. Click the magic link provided to you by Palo Alto Networks when you purchased the Prisma Access license.
  3. Activate the Prisma Access license.
    • Activate the license for Prisma Access (Managed by Panorama).
    • Activate the license for Prisma Access (Managed by Strata Cloud Manager).
  4. Enable the Enterprise DLP add-on.
    • Prisma Access (Managed by Panorama) —The Enterprise DLP add-on is enabled by default when you activate the Prisma Access license.
    • Prisma Access (Managed by Strata Cloud Manager)Enable the Enterprise DLP add-on after activating the Prisma Access license.
  5. Log in to Strata Cloud Manager and verify that you can select ConfigurationData Loss Prevention.
  6. Associate your Panorama and Prisma Access tenants with the tenant service group (TSG) in which you activated Prisma Access and Enterprise DLP.
    Your Panorama and Prisma Access tenants must belong to the same TSG. This enables Panorama to synchronize Enterprise DLP configuration changes with Strata Cloud Manager and push them to your managed Prisma Access tenants.
    Use Device Associations in Strata Cloud Manager to add your Panorama and Prisma Access tenants to the TSG.
  7. (Prisma Access (Managed by Panorama) only) Install the Enterprise DLP Plugin on Panorama.
    If you manage your Prisma Access tenants from Panorama, you must install the Enterprise DLP plugin on Panorama to manage your Enterprise DLP configuration, synchronize Enterprise DLP configuration objects with Strata Cloud Manager, and push Enterprise DLP configuration changes to your Prisma Access tenants. A Panorama with the Enterprise DLP plugin installed is required.
    Install the Enterprise DLP plugin after you associate Enterprise DLP with your Panorama and NGFW. This ensures the plugin correctly maps to your TSG and prevents synchronization issues.
  8. Enable Enterprise DLP.
    Some apps, such as SharePoint and OneDrive, use HTTP/2 by default. For NGFW, Prisma Access tenants, and VM-Series firewalls managed by Panorama or by Strata Cloud Manager running PAN-OS 10.2.2 and earlier releases, you must create a decryption profile and a Security policy rule to strip out the application-layer protocol negotiation (ALPN) extension in headers. Complete these steps to successfully forward traffic to Enterprise DLP.