Palo Alto NetworksSecure Access Service Edge (SASE)

    Prisma Access

    The cloud-delivered security service edge (SSE) of the Prisma SASE platform.

    Palo Alto Networks Prisma Access is the security service edge (SSE) component of the Prisma SASE platform, delivering best-in-class protection to secure the way your organization works — for users anywhere accessing SaaS, private apps, and the internet. It brings ZTNA, Secure Web Gateway, CASB, Firewall-as-a-Service, and the full Cloud-Delivered Security Services from the cloud. Faltrox designs, deploys, and operates it.

    Overview

    What Prisma Access is

    Prisma Access is the cloud-delivered SSE that secures users wherever they work. Rather than backhauling remote and branch traffic to a data centre for inspection, it applies best-in-class protection in the cloud, close to the user — delivering the same threat prevention as the NGFW, without the on-site appliance.

    It provides all the core SSE functions — Zero Trust Network Access to private apps, Secure Web Gateway, Cloud Access Security Broker, Firewall-as-a-Service — plus the full Cloud-Delivered Security Services (Advanced Threat Prevention, URL Filtering, WildFire, DNS Security) and DLP. As the SSE part of Prisma SASE, it pairs with Prisma SD-WAN and ADEM for a complete SASE architecture. Faltrox designs the zero-trust policy, migrates users from legacy VPN, and operates Prisma Access as a managed service.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Users Anywhere

    Secures remote and hybrid users from the cloud, close to where they work.

    02

    Private Applications

    Zero Trust Network Access grants least-privilege access to private apps.

    03

    SaaS & Internet

    Secure Web Gateway and CASB protect access to SaaS and the internet.

    04

    Full Threat Prevention

    Delivers the full Cloud-Delivered Security Services from the cloud.

    05

    Sensitive Data

    Integrated DLP protects sensitive data across the SSE fabric.

    06

    Branches

    Secures branch traffic without backhauling to a data centre.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Connect

      Users and branches connect to the nearest Prisma Access cloud location rather than backhauling to a data centre.

    2. 02

      Verify

      Zero-trust policy validates identity and device posture before granting access to applications.

    3. 03

      Inspect

      SWG, CASB, FWaaS, the Cloud-Delivered Security Services, and DLP inspect and control traffic in the cloud.

    4. 04

      Grant

      ZTNA provides least-privilege access to private apps for users wherever they work.

    5. 05

      Operate

      Faltrox designs the policy, migrates users off legacy VPN, and monitors it as managed SSE.

    Capabilities

    Key capabilities

    Zero Trust Network Access

    Least-privilege access to private apps by identity and device posture, replacing broad VPN.

    Secure Web Gateway

    Inspects and controls web and internet traffic in the cloud for users anywhere.

    Cloud Access Security Broker

    Discovers and controls SaaS usage, including shadow IT and risky behaviour.

    Firewall-as-a-Service

    Cloud-delivered firewalling with threat prevention for all traffic.

    Cloud-Delivered Security Services

    The full Advanced Threat Prevention, URL Filtering, WildFire, and DNS Security stack.

    Integrated DLP

    Protects sensitive data across the SSE fabric with unified data-loss prevention.

    Best-in-Class Protection

    Delivers the same threat prevention as the NGFW, from the cloud.

    Part of Prisma SASE

    Pairs with Prisma SD-WAN and ADEM for a complete SASE architecture.

    Works with

    Part of the platform

    Palo Alto Networks products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Palo Alto Networks Prisma Access for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01What is the difference between Prisma SASE and Prisma Access?

    Prisma SASE is the full platform; Prisma Access is its security service edge (SSE) component — the cloud-delivered security (ZTNA, SWG, CASB, FWaaS). Prisma SD-WAN provides the networking side and ADEM the experience management. Prisma Access is the security half of the SASE architecture.

    02How is it different from a VPN?

    It applies full security in the cloud close to the user rather than backhauling traffic to a data centre, and Zero Trust Network Access replaces broad VPN access with least-privilege access to specific applications by identity and posture. Faltrox manages the migration from legacy VPN.

    03Does it deliver the same protection as the firewalls?

    Yes — it delivers the full Cloud-Delivered Security Services (Advanced Threat Prevention, URL Filtering, WildFire, DNS Security) and the same threat prevention as the NGFW, from the cloud, so remote users get best-in-class protection without an on-site appliance.

    04Can it secure branches as well as remote users?

    Yes — branches connect to Prisma Access for cloud-delivered security instead of backhauling to a data centre, and with Prisma SD-WAN they form a complete SASE architecture. Faltrox designs both together.

    05How does Faltrox operate it?

    We design the zero-trust access policy, integrate it with your identity providers, migrate users off legacy VPN, and monitor threats and access — delivering the security service edge as a managed service.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us