Allow Users to Upgrade the GlobalProtect App
Focus
Focus
Prisma Access

Allow Users to Upgrade the GlobalProtect App

Table of Contents

Allow Users to Upgrade the GlobalProtect App

How to control your mobile user access to the GlobalProtect app version for Prisma Access GlobalProtect deployments.
Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Strata Cloud Manager)
  • Prisma Access (Managed by Panorama)
  • Prisma Access license
Learn how to control your mobile user access to the GlobalProtect app version for Prisma Access GlobalProtect deployments.

Allow Users to Upgrade the GlobalProtect App (Strata Cloud Manager)

How to control your mobile user access to the GlobalProtect app version for Prisma Access GlobalProtect deployments.
You can manage mobile user access to the active GlobalProtect app version that is hosted by Prisma Access. To do this in Prisma Access (Managed by Strata Cloud Manager), configure the Upgrade Global Protect setting. For Prisma Access (Managed by Strata Cloud Manager), complete the following steps.
  1. Select ManageMobile Users to open the Mobile Users Setup page, and then locate the GlobalProtect Connection panel.
    If you're using Strata Cloud Manager, go to WorkflowsPrisma Access SetupMobile Users, and then locate the GlobalProtect Connection panel.
  2. Select GlobalProtect Setup or EnableGlobalProtect Setup if GlobalProtect is not already enabled.
  3. Select the GlobalProtect App tab, and then Add App Settings.
  4. In the App Configuration area, select a choice in Upgrade GlobalProtect App to specify whether mobile users can upgrade their GlobalProtect app version to the active version that is hosted on Prisma Access and, if they can, whether they can choose when to upgrade:
    • Allow when user accepts the upgrade Prompt (default)—Prompt users when a new version is activated and allow users to upgrade their software when it is convenient.
    • Disallow—Prevent users from upgrading the app software.
    • Allow Manually—Allow users to manually check for and initiate upgrades by selecting Check Version in the GlobalProtect app.
    • Allow Transparently—Automatically upgrade the app software whenever a new version becomes available on the portal.
    • Allow when the user is in the corporate network—Automatically upgrade the app software whenever a new version becomes available on the portal, but wait until the endpoint is connected internally to the corporate network. This prevents delays caused by upgrades over low-bandwidth connections.

Allow Users to Upgrade the GlobalProtect App (Panorama)

How to control your mobile user access to the GlobalProtect app version for Prisma Access GlobalProtect deployments.
You can manage mobile user access to the active GlobalProtect app version that is hosted by Prisma Access. To do this in Prisma Access (Managed by Strata Cloud Manager), configure the Upgrade Global Protect setting. For Prisma Access (Managed by Panorama), complete the following steps.
  1. Select NetworkGlobalProtectPortals.
  2. Select the Mobile_User_Template from the Template drop-down.
  3. Select GlobalProtect_Portal to edit the Prisma Access portal configuration.
  4. Select the Agent tab and select the app configuration.
  5. Select the App tab.
  6. In the App Configurations area, select a choice in Allow User to Upgrade GlobalProtect App to specify whether mobile users can upgrade their GlobalProtect app version to the active version that is hosted on Prisma Access and, if they can, whether they can choose when to upgrade:
    • Allow with Prompt (default)—Prompt users when a new version is activated and allow users to upgrade their software when it is convenient.
    • Disallow—Prevent users from upgrading the app software.
    • Allow Manually—Allow users to manually check for and initiate upgrades by selecting Check Version in the GlobalProtect app.
    • Allow Transparently—Automatically upgrade the app software whenever a new version becomes available on the portal.
    • Internal—Automatically upgrade the app software whenever a new version becomes available on the portal, but wait until the endpoint is connected internally to the corporate network. This prevents delays caused by upgrades over low-bandwidth connections.