Skip to main content

Prisma Browser: Secure Web Browsing for End-users

General Overview

Guardz is partnering with Palo Alto Networks to bring web protection at the browser layer, built on Palo Alto Networks' Prisma Browser for Business, turned on per client from the Guardz console; Deployed as an extension or a standalone browser.

How does it Work?

Customers can either install a browser extension or install Prisma Browser as a standalone browser.

  • Installing the extension applies protection directly across supported browsers on the device (Chrome and Edge are supported via the extension).

  • Safari is not protected by the extension — users on Safari are not covered.

Default Configuration:

Prisma Access Browser provides built-in, preconfigured baseline protection powered by Palo Alto Networks’ integrated security engines. This protection is enforced directly at the browser layer and includes Advanced URL Filtering to detect and block phishing, malicious sites, and other web-based threats; Advanced WildFire to analyze files and prevent malicious downloads; and Advanced Extension Security to identify and block confirmed malicious browser extensions.

Together, these capabilities provide users with out-of-the-box protection against common web, malware, and browser-extension threats, without requiring customers to build these protections from scratch.

Browser vs. Extension:

Prisma Browser can be deployed in two forms: as a standalone browser or as a browser extension. Both apply the same core protections — web security, malware security, data controls, and extension security — through the same admin console, so the choice comes down to platform and coverage rather than security depth.

The standalone browser is a dedicated, secured browser installed on the device. Because protection is built into the browser itself, it isn't tied to whatever other browser the user has installed, and it's the only option that runs on Linux or supports Secure Workspace.

The extension adds protection into an existing browser rather than replacing it. It's supported on Windows and macOS, and works with Chrome and Edge — Safari is not covered. It doesn't support Secure Workspace.

In short: use the standalone browser when the device runs Linux, when Secure Workspace is needed, or when protection shouldn't depend on which browser the user opens. Use the extension when the goal is to protect an existing Chrome or Edge browser without installing a separate one. Both are managed from the same admin console, so there's no added overhead in choosing — or combining — the two.

Regional Availability:

At launch, Prisma Browser is only available to customers whose account sits in Guardz US data center. This is a regulatory and compliance restriction on Palo Alto's side. Hence, this feature is only available to US-based SMBs.

Packaging:

Prisma Browser is available either as part of the Elite plan or as a standalone add-on, regardless of the customer’s assigned plan.


Prisma Browser Deployment Aspects

Identity Provider Compatibility (for Extensions):

Identity Provider

Status

Microsoft (Entra / Microsoft 365)

Works smoothly

Google Workspace

Supported*

After installing the extension, an admin action called admin consent is required. This action allows the admin to complete the login process on behalf of the users, saving each individual user from having to log in manually.

This works smoothly with Microsoft. With Google, this remote login capability is not currently available, each user is required to log in manually themselves.

Platform-Specific Notes:

Platform

Script Deployment Method

Windows

RMM and MDM (similar to the SentinelOne deployment model)

macOS

MDM only

Step-by-Step Deployment Process:

  1. Select the relevant tenant (deployment is performed at the individual tenant level and must be completed separately for each tenant).

  2. Go to the Security Controls screen and open the Browser Security section.

  3. Click the 'Setup' button.

  4. Fill in / confirm your own MSP business details.

  5. Fill in / confirm the SMB business details.

  6. Click the 'Create Tenant' button

    1. At this point, the required details are sent to Palo Alto for review and approval. This process - "Compliance Screening" - may take some time, and activation will remain pending until final approval is received from their side.

    2. Once tenant is successfully created, 'Active' sign appears.

  7. For extensions which are deployed on Microsoft workspaces only:

    Enable the auto login on behalf of users (admin consent; this step removes the need for every individual user to log in manually).

    1. Click the 'Grant Consent' button.

    2. Click 'Grant Consent'.

    3. Proceed with the Microsoft consent approval process.

  8. Open the relevant deployment drawer (extension / full browser) and download the relevant installation script.

    1. For Browsers: select the desired script and download it.

    2. For Extensions:

      • Select the 'Block Private Browsing' checkbox if you want to block private browsing (Incognito mode). Selecting this option automatically adds the relevant configuration to the script before you download it.

      • Download the relevant script.

  9. Install the script on end-user devices:

    1. RMM instructions:

      1. Write & test locally first — never push untested scripts to production.

      1. Add logging + exit codes (0 = success, non-zero = fail) so the RMM can report status.

      2. Set execution context — SYSTEM for most config/registry changes, user context for HKCU/Office-level settings.

      3. Parameterize anything tenant-specific (IDs, names, secrets) instead of hardcoding — use the RMM's variables/credential vault.

      4. Upload to RMM script library, set type = PowerShell, define parameters + timeout.

      5. Pilot first — one device/client, then small batch, then full fleet.

      6. Verify results directly (registry, Graph API, service status) — don't just trust the exit code.

      7. Document what it does and which devices/tenants it applies to.

    2. MDM instructions:

      1. Package the app/config — MSI, PKG, or a Win32 app wrapper (.intunewin for Intune); confirm silent install switches work first.

      1. Upload to MDM console — e.g., Intune Admin Center → Apps → All apps → Add → choose app type (Line-of-business, Win32, etc.).

      2. Set install context — Device vs. User (Device = applies regardless of who logs in, needed for most system-level configs).

      3. Assign to groups — target a pilot Entra/AD group first, not "All Users/Devices."

      4. Configure detection rules (Intune-specific) — so it knows install succeeded (registry key, file version, MSI product code).

      5. Set assignment type — Required (auto-push) vs. Available (self-service via Company Portal).

      6. Deploy in waves — pilot group → small batch → full tenant.

      7. Monitor — check install status per device in the console; cross-verify (e.g., is the app/registry setting actually present).

      8. Document — what it does, which tenant/group it targets, rollback steps.

Important notes:

  • Silent login is supported only for Microsoft and only when using the browser extension.

  • If the Google extension option is selected, or if the browser itself is installed, the user will need to log in manually through the extension installed in the browser.


Visibility for Admins

Deployment Status:

Installation itself is managed at the tenant level: rather than having a distinct per-customer setting, the All Customers mode provides a single view showing which tenants have Prisma Browser installed.

Alerts (Events) Screen:

Admins can view protected activity as events on a dedicated Alerts page, providing visibility into detections and the underlying activity handled by the feature. Unlike other security events that may require investigation or remediation, these events are informational and do not require any action from the admin, as protection is applied automatically.

The page can be accessed from the main toolbar on the right side of the platform.


Palo Alto's Console Access

General Notes about the Console Access:

  • In general, the default configurations are designed to work well for most use cases, and changes should generally only be made when there is a specific need.

  • Console access is managed at the single-tenant level. Since Palo Alto does not offer global management (i.e., multi-tenant management capability), each tenant must be managed separately, with its own distinct console access.

  • Since each tenant is managed independently, activating any given tenant requires the admin to log in to the Palo Alto console using a different user account specific to that tenant.

How to Create a Console Access?

  1. Select the relevant tenant and go to the Browser Security section.

  2. Once feature is fully activated, open the 'Manage' drawer.

  3. Scroll down to the console access section.

  4. Select the admin you want to grant access to from the list and click 'Grant Access'. This grants the user console access automatically.

  5. Click Open Console to access the console directly. No additional login or authentication steps are required.


Post-activation Settings Management

Admins have the ability to control and restrict access to websites, either by blocking predefined categories based on an existing list or by manually blocking specific websites as needed. This provides admins with greater flexibility and control over which types of content and individual sites are accessible.

Did this answer your question?