NetSec Platform: Strata Cloud Manager (SCM)

Strata Cloud Manager (SCM) is a cloud-based network security control plane. It brings together access patterns, modular security services, and enforcement across an entire enterprise, providing unified SASE and NGFW management.

SCM combines capabilities and tools that have traditionally operated in silos across multiple domains, such as remote access, data centre, cloud, SaaS, internet, edge, and endpoint.

Common use cases for SCM include:

  • Unified policy management
  • Centralised security insights and analytics
  • Autonomous Digital Experience Management (ADEM)
  • AI-assisted troubleshooting and issue resolution
  • Security posture optimisation
  • Security audit and compliance
  • Operational workflows and integrations

SCM leverages Machine Learning, Deep Learning, and Generative AI to provide proactive analytics, contextual insights, policy recommendations, and operational guidance.

Platform Tenancy

SCM is delivered as a tenant-based control plane tied to a specific region. A tenant is referred to as a Tenant Services Group (TSG), a common services layer that includes:

  • Strata Cloud Manager (SCM): network security control plane and UI
  • Strata Logging Service (SLS): retains logs and normalises telemetry into a common data model
  • Cloud Identity Engine (CIE): Identity Provider (IdP) integration and directory sync
  • Licensing and subscriptions

Larger organisations or service providers can nest multiple TSGs into a hierarchy of child tenants, each with their own instances of the services mentioned above.

Platform Policy and Operations

Within SCM, security policy is created centrally and enforced consistently across Prisma Access and NGFWs:

  • Global scope cascades policy across the entire estate
  • Folders group Prisma Access deployments and NGFWs separately by product
  • Snippets bridge across folder boundaries, enabling a policy to span deployments without duplication

Policies extend to the Cloud-Delivered Security Services (CDSS) that inspect traffic within the enforcement fabric. Threat prevention, malware analysis, URL filtering, and DNS security policies are authored and managed directly in SCM.

As well as unified policy, another benefit of centralised management is the common data model which enables the following features:

Insights: provide dashboards and deep analytics across network activity, security posture, and operational health.

Screenshot: Threat Insights in Strata Cloud Manager (SCM)

Compliance Centre: benchmarks configuration against best practices and named frameworks, with playbooks to directly remediate failing configuration.

Zero Trust Posture Centre: a risk and prioritisation hub that integrates best practice checks, policy optimisation, and config cleanup, organised around Zero Trust pillars.

Screenshot: Zero Trust Posture Centre in Strata Cloud Manager (SCM)

Incidents: centralise degradations in availability, performance, or security into a single view, whilst also integrating with third-party IT Service Management (ITSM) and Security Incident Response (SIR) tools.

Copilot: a natural-language assistant, allowing administrators to query configuration, get remediation guidance, and receive recommendations conversationally.

Screenshot: Incidents and Copilot in Strata Cloud Manager (SCM)

Example: ADEM

Autonomous Digital Experience Management (ADEM) is an observability and experience management capability surfaced through SCM.

ADEM would not be possible with fragmented tooling. It relies on policy context, enforcement telemetry, and endpoint signals existing within the same data model.

ADEM uses Machine Learning to calculate health scores, identify issues, and determine root cause within a single interface, covering multiple domains:

  • End-to-end segment monitoring (RUM, synthetic testing)
  • Endpoint telemetry (CPU, memory, WiFi)
  • First and last mile metrics (LAN, ISP)
  • Security service telemetry (Prisma Access, NGFW)
  • Application performance metrics (latency, connection time)

For example, if a user reports performance issues with Teams, without SCM the process looks something like this:

  • Check the endpoint
  • Check the remote access solution
  • Check the firewall logs
  • Check the ISP metrics
  • Check the SaaS application portal

With SCM the workflow is simplified:

  • Complete user experience view
  • Enforcement, endpoint, and network telemetry in one place
  • Health score with domain breakdown for troubleshooting
  • Suggested root cause is provided

User coaching can be delivered using the endpoint agent, useful when performance issues are detected due to a local device or home WiFi issue.

Screenshots: ADEM in Strata Cloud Manager (SCM)

ADEM is one form of SCM's broader AI-assisted operational foundation. The common data model that powers health scoring and root cause analysis here also drives troubleshooting, security posture optimisation, and compliance reporting elsewhere in the platform.

Read more