Prisma Access
The cloud-delivered security service edge (SSE) of the Prisma SASE platform.
Palo Alto Networks Prisma Access is the security service edge (SSE) component of the Prisma SASE platform, delivering best-in-class protection to secure the way your organization works — for users anywhere accessing SaaS, private apps, and the internet. It brings ZTNA, Secure Web Gateway, CASB, Firewall-as-a-Service, and the full Cloud-Delivered Security Services from the cloud. Faltrox designs, deploys, and operates it.
Overview
What Prisma Access is
Prisma Access is the cloud-delivered SSE that secures users wherever they work. Rather than backhauling remote and branch traffic to a data centre for inspection, it applies best-in-class protection in the cloud, close to the user — delivering the same threat prevention as the NGFW, without the on-site appliance.
It provides all the core SSE functions — Zero Trust Network Access to private apps, Secure Web Gateway, Cloud Access Security Broker, Firewall-as-a-Service — plus the full Cloud-Delivered Security Services (Advanced Threat Prevention, URL Filtering, WildFire, DNS Security) and DLP. As the SSE part of Prisma SASE, it pairs with Prisma SD-WAN and ADEM for a complete SASE architecture. Faltrox designs the zero-trust policy, migrates users from legacy VPN, and operates Prisma Access as a managed service.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Users Anywhere
Secures remote and hybrid users from the cloud, close to where they work.
Private Applications
Zero Trust Network Access grants least-privilege access to private apps.
SaaS & Internet
Secure Web Gateway and CASB protect access to SaaS and the internet.
Full Threat Prevention
Delivers the full Cloud-Delivered Security Services from the cloud.
Sensitive Data
Integrated DLP protects sensitive data across the SSE fabric.
Branches
Secures branch traffic without backhauling to a data centre.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Connect
Users and branches connect to the nearest Prisma Access cloud location rather than backhauling to a data centre.
- 02
Verify
Zero-trust policy validates identity and device posture before granting access to applications.
- 03
Inspect
SWG, CASB, FWaaS, the Cloud-Delivered Security Services, and DLP inspect and control traffic in the cloud.
- 04
Grant
ZTNA provides least-privilege access to private apps for users wherever they work.
- 05
Operate
Faltrox designs the policy, migrates users off legacy VPN, and monitors it as managed SSE.
Capabilities
Key capabilities
Zero Trust Network Access
Least-privilege access to private apps by identity and device posture, replacing broad VPN.
Secure Web Gateway
Inspects and controls web and internet traffic in the cloud for users anywhere.
Cloud Access Security Broker
Discovers and controls SaaS usage, including shadow IT and risky behaviour.
Firewall-as-a-Service
Cloud-delivered firewalling with threat prevention for all traffic.
Cloud-Delivered Security Services
The full Advanced Threat Prevention, URL Filtering, WildFire, and DNS Security stack.
Integrated DLP
Protects sensitive data across the SSE fabric with unified data-loss prevention.
Best-in-Class Protection
Delivers the same threat prevention as the NGFW, from the cloud.
Part of Prisma SASE
Pairs with Prisma SD-WAN and ADEM for a complete SASE architecture.
Works with
Part of the platform
Palo Alto Networks products this pairs with, and the Faltrox services that operate it.
Palo Alto Networks products
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Palo Alto Networks Prisma Access for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01What is the difference between Prisma SASE and Prisma Access?
Prisma SASE is the full platform; Prisma Access is its security service edge (SSE) component — the cloud-delivered security (ZTNA, SWG, CASB, FWaaS). Prisma SD-WAN provides the networking side and ADEM the experience management. Prisma Access is the security half of the SASE architecture.
02How is it different from a VPN?
It applies full security in the cloud close to the user rather than backhauling traffic to a data centre, and Zero Trust Network Access replaces broad VPN access with least-privilege access to specific applications by identity and posture. Faltrox manages the migration from legacy VPN.
03Does it deliver the same protection as the firewalls?
Yes — it delivers the full Cloud-Delivered Security Services (Advanced Threat Prevention, URL Filtering, WildFire, DNS Security) and the same threat prevention as the NGFW, from the cloud, so remote users get best-in-class protection without an on-site appliance.
04Can it secure branches as well as remote users?
Yes — branches connect to Prisma Access for cloud-delivered security instead of backhauling to a data centre, and with Prisma SD-WAN they form a complete SASE architecture. Faltrox designs both together.
05How does Faltrox operate it?
We design the zero-trust access policy, integrate it with your identity providers, migrate users off legacy VPN, and monitor threats and access — delivering the security service edge as a managed service.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us