NetSec Platform: Prisma Access

At a high level, Prisma Access is a distributed security enforcement layer. The key concept is that security enforcement happens in a cloud-delivered security edge, close to users and applications, rather than a single physical location (like a data centre firewall).

Prisma Access consolidates several key security capabilities into a single platform:

  • Zero Trust Network Access 2.0 (ZTNA)
  • Cloud Access Security Broker (CASB)
  • Firewall-as-a-Service (FWaaS)
  • Secure Web Gateway (SWG)

This enables consistent controls for:

  • Remote users
  • Branch and site connectivity
  • Internet and SaaS access
  • Private application access
In industry language Prisma Access is a Security Service Edge (SSE). It can be combined with native SD-WAN to form a Secure Access Service Edge (SASE).

Prisma Access Use Cases

Most organisations implement Prisma Access for one or several of the following reasons:

Use case 1: Secure hybrid and remote work. The traditional VPN and data centre backhaul model is not suitable for the modern workforce. Users are distributed and mobile, performance expectations are high, and the majority of traffic is destined for internet and SaaS applications.

Platform outcome: Users get fast, direct-to-app connectivity while the organisation is able to standardise security, decryption, and threat-inspection policies globally.

Use Case 2: Zero Trust transition. Older access models often allow broad lateral visibility within the corporate network. Many organisations have legacy and overly permissive rules configured that pose security risks should an identity be breached.

Platform outcome: Access is granted using the concept of least privilege, with identity verification, device posture, and context considered for every application request. Access is dynamic and revoked if conditions change during the active session, preventing lateral threat movement and reducing the blast radius of a breach.

Use Case 3: Branch transformation. Maintaining hardware firewalls, routers, and dedicated MPLS circuits at every physical site is expensive and difficult to scale. Security policy, visibility, and tooling is often inconsistent.

Platform outcome: Organisations can reduce or eliminate local hardware footprints and standardise rapid onboarding of new sites and users. A platform approach enables end-to-end Digital Experience Management improving user experience and Mean Time To Resolve (MTTR).

Use Case 4: Safe adoption of Generative AI tools. Employees are increasingly relying on public AI tools to optimise their work, presenting a different type of data exposure risk. Blocking access is counter-productive, leads to users seeking workarounds, and misses AI features that appear in sanctioned applications.

Platform outcome: Native integration into AI Access Security and Data Loss Prevention engines allows organisations to discover and categorise AI applications and attributes, while applying real-time safeguards to remove sensitive data exposed in prompts or other methods before it reaches public LLMs.

Use Case 5: Secure third-party access. External contractors or employees using personal devices (Bring Your Own Device) will often need access to corporate systems. This use case often leads to mixed solutions since organisations have no control over the endpoints or networks.

Platform outcome: Access to corporate systems and sensitive information can be isolated entirely within a browser session using Prisma Browser. Access is secured from any device with granular controls to prevent data exfiltration even on compromised endpoints.

Access Patterns

Prisma Access is consumed as a service with a cloud-delivered operating model. The traditional overhead of sizing, deploying, and maintaining security gateways or other infrastructure components is removed.

Users and sites connect into Prisma Access where traffic is inspected and controlled according to policy. This architecture changes the traditional perimeter design in 2 important ways:

1) Enforcement moves closer to the natural traffic path (especially for internet and SaaS), reducing reliance on backhauling everything through a central data centre.
2) Security is delivered as a service edge, which provides standardisation and scale across remote users and sites, rather than being tied to a single physical location.

Prisma Access provides multiple on-ramp and off-ramp patterns that define how traffic enters and exits the enforcement fabric:

On-ramps:

  • Mobile Users: supports multiple methods including agent-based, explicit proxy, portal, or secure browser
  • Remote Networks: connect branch offices via standard IPSec or SD-WAN
    Remote Networks can also act as an off-ramp for users needing to access services hosted locally within a branch

Off-ramps:

  • Internet: direct, secure egress through the Prisma Access backbone
  • Private Applications:
    • Service Connection: a network-centric off-ramp for private application access, which also functions as an on-ramp for infrastructure traffic
    • Zero Trust Network Access (ZTNA) Connector: an application-centric off-ramp for private application access

Private Interconnects:

These options provide private, high-bandwidth, low-latency connectivity into the Prisma Access fabric, avoiding public internet transit. They are typically used in large-scale or service provider environments.

  • Service Provider Interconnect: direct backbone interconnect allowing an Internet Service Provider (ISP) to natively connect into the Prisma Access fabric with VLAN-based hand-off
    This enables ISPs to deliver Clean Pipe services, where traffic is inspected and scrubbed before reaching downstream networks
  • Private Connect: Cloud Interconnect: privately connects public cloud Virtual Private Clouds (VPCs) or Virtual Networks (VNETs) directly into the Prisma Access fabric
  • Private Connect: Colo Connect: privately connects infrastructure hosted in third-party colocation facilities into the Prisma Access fabric

The commonality across all access types is that verification, inspection, and enforcement are applied consistently throughout the session.

Platform Approach

Prisma Access uses the advanced capabilities of Cloud-Delivered Security Services (CDSS) as the inspection layer for real time detection and prevention. As traffic transits the Prisma Access data plane, it undergoes single-pass inspection across modular services including threat prevention, malware analysis, URL filtering, and DNS security.

Strata Cloud Manager (SCM) centralises policy, visibility, and management across Cloud-Delivered Security Services and the Prisma Access enforcement fabric.

In platform language Prisma Access forms the data plane, with central policy management from Strata Cloud Manager (SCM) providing the control plane.
Diagram: Prisma Access in the network security platform

There isn't a one size fits all deployment for Prisma Access. The core idea stays consistent (traffic is steered into a cloud-delivered enforcement layer) but the design choices and operational outcomes change depending on the use cases.

As with any distributed enforcement model, resilience and degraded-mode behaviour should be intentionally designed rather than assumed.

Across all use cases, successful deployments share the same mindset:

  • Prisma Access is an enforcement layer
  • Identity and policy structure are designed intentionally
  • Connectivity and routing are treated as security architecture
  • Visibility and operations are planned from day 1

Platform outcomes are not defined by where enforcement happens. A platform is built with a common policy model, common visibility, and common security controls that scale consistently.

In the next post, we'll go into the distributed enforcement architecture of Prisma Access in more detail.

Read more