: Activate a Product: PayGo
Focus
Focus

Activate a Product: PayGo

Table of Contents

Activate a Product: PayGo

Activate Pay-As-You-Go (PayGo) credit-based monthly postpaid licensing for Prisma SASE for MSPs.
Where Can I Use This?What Do I Need?
  • Strata Multitenant Cloud Manager
  • Strata Cloud Manager
  • Multitenant Superuser role on the root tenant
  • Active Palo Alto Networks Customer Support Portal (CSP) account
The Pay-As-You-Go (PayGo) billing model for Prisma® SASE is designed for Managed Service Providers (MSPs) that need a flexible way to onboard customers and manage licenses as their tenant base grows. PayGo uses a monthly postpaid model, where you are billed based on the packages activated, add-ons, and the capacity (mobile users and site count) within the package activated each day during the billing cycle.
With PayGo, you can:
  • Select and scale PayGo packages — MSPs can scale to meet different customer requirements by selecting the appropriate PayGo package: use Prisma Browser for browser-based security, SASE SWG for secure internet and SaaS access, or SASE ENT for comprehensive secure internet, SaaS, and private application access.
  • Onboard tenants quickly — Add new tenants, set initial capacity count (mobile users, sites, etc.), and deploy environments as needed.
  • Manage licenses flexibly — Increase or decrease the capacity count (mobile users, sites, etc.), enable or disable add-ons based on tenant requirements within a PayGo package.
  • Monitor PayGo packages from the root — Gain unified visibility from the root, where packages, add-ons, and capacity counts are tracked on a daily basis across all tenants.

How PayGo Works

When a PayGo SKU order is processed, it is activated on the absolute root tenant associated with the Customer Support Portal (CSP). The root tenant acts as a container for child tenants and provides a consolidated view of PayGo activity.
You can create child tenants under the absolute root tenant and activate SASE ENT, SASE SWG, and Prisma Browser Core packages on those tenants.
At the end of each billing cycle, you receive a monthly invoice based on the package chosen, add-ons selected, and capacity (MU and site count) tracked daily across your child tenants during the billing period.

Activate PayGo

When a PayGo SKU order is processed, the subscription is activated on the root tenant. The root tenant serves as the parent container for all child tenants and does not consume or activate packages.
After the root tenant is activated, you can create child tenants and activate SASE SWG, SASE ENT, and Prisma Browser Core packages on those tenants. Billing is calculated based on the packages active on each child tenant for a given day.
You can view consolidated package and billing information from the root tenant. However, you cannot activate packages directly on the root tenant.
  1. Click Activate in the activation email. This takes you to the subscription management page.
  2. Click Post-Paid > Launch on MSSP SASE PayGo product, and it will take you to the MSP portal.
    The Pre-Paid tab appears only if you have an active pre-paid subscription. Otherwise, you are directed to the Post-Paid page.
  3. In the MSP Portal, select ConfigurationWorkflowsTenant Onboarding. The Activate New Tenant with PayGo Postpaid Billing Model tile is now visible, confirming activation is complete. You can add the new child tenant and activate packages on those tenants. You can add a child tenant and activate the following packages on them:
After onboarding tenants, you can amend a PayGo tenant to adjust user quantities and add-ons, or deprovision a PayGo tenant to remove it from your hierarchy. You can monitor package activation and billing activity across all tenants from the Business dashboard.