When a user's posture changes, 4Remote updates their Prisma Access local-user group memberships and pushes the candidate configuration automatically. Access flexes with security state, with no manual policy edits.
Palo Alto Networks Prisma Access is a cloud-delivered Security Service Edge (SSE) platform. It provides secure network access for remote users and branch offices, with policies that decide which resources each user group can reach. Powerful, but the group membership is normally a manual job, and every change has to be staged then pushed.
Security Service Edge that sits in front of your users wherever they are, with no on-prem appliance to scale.
Built for distributed workforces and branch offices, secured by a single cloud control plane.
Local user groups gate which resources each user can reach. Move a user between groups, and access changes.
Prisma Access local user groups are the lever for differentiated access: put a user in a group and the policies tied to it become the access they get. The catch: keeping group membership in sync with real-world device posture is normally a manual job, and every edit has to be staged in candidate then pushed to running.
4Remote watches device posture continuously. The moment it changes, the matching Prisma Access local groups are updated for that user and the candidate configuration is pushed automatically. No tickets. No console clicks. No window where a compromised user still has standard access.
Group memberships change instantly when a user's security posture changes.
Only compliant users retain access to protected Prisma Access resources.
No need to manually edit local user groups or commit configuration pushes. The integration handles it.
Non-compliant users are removed from privileged groups immediately, not at the next audit cycle.
This integration only manages local Prisma Access users. Users authenticated via external identity providers (LDAP, SAML, or other SSO systems) are not managed by this integration and must be handled through those systems.
Changes in Prisma Access are staged in a candidate configuration and don't take effect until pushed. The integration handles this automatically after each sync.
The integration runs continuously. Posture changes flow into your Prisma Access tenant within seconds of the next push.
The platform monitors device security continuously.
Each user gets the statuses that match their evaluation:
The integration updates Prisma Access automatically:
The candidate configuration is committed to running:
Prisma Access uses a candidate/running configuration model. Changes stage in candidate first, then become live after the configuration is pushed. The integration handles the entire lifecycle so you never have to log into the console to commit.
Group changes queued in the candidate configuration. Not yet enforced.
Integration commits candidate to running. No console clicks required.
Policies enforce against the new groups. Access updates take effect immediately.
Failed push? Staged changes are preserved and committed on the next successful sync. No silent drift.
Users are matched by their email address against Prisma Access's local user directory. The user must already exist as a local Prisma Access account for the integration to manage them.
Federated and SSO users (LDAP, SAML, or external IdP) are out of scope. They continue to be governed by your identity provider's groups, not by 4Remote.
An employee's laptop picks up a critical vulnerability. Here is what 4Remote and Prisma Access do, in seconds, including the configuration push, with no human in the loop.
An employee's laptop has a critical vulnerability discovered during a routine scan.
Scheduled scan flags CVE-2024-1234 at Critical severity on the user's laptop.
4Remote moves the user's status from Compliant to Quarantine.
Integration stages the change in candidate config: user removed from Compliant.
Same stage cycle: user added to Quarantine in candidate config.
Candidate is committed to running. Prisma Access policies now enforce against the updated groups.
Sensitive resources blocked for the Quarantine group. Employee receives remediation steps with the affected device and the patch needed.
Patch applied, next scan clears the CVE. Status flips back to Compliant, the candidate is pushed automatically, and access is restored.
Timeline: the full detection, group update, and configuration push completes in seconds, with zero human in the loop.
If you run Prisma Access with local users, this integration turns your existing groups into a real-time enforcement layer for Zero Trust, with the configuration push handled automatically. Talk to us about a partner integration or a customer rollout.
Work with Us
Whether you want to see 4Remote in your own environment, talk through pricing, explore a partnership, or ask us something else entirely, we're ready to respond. Tell us what you need and the right person will come back to you directly.