Integration · Palo Alto Prisma Access

Automatic Zero Trust enforcement on your Prisma Access tenant.

When a user's posture changes, 4Remote updates their Prisma Access local-user group memberships and pushes the candidate configuration automatically. Access flexes with security state, with no manual policy edits.

4R4Remote
PAPrisma
# sync jane@acme posture changed: Compliant → Quarantine → local group "Compliant": user removed → local group "Quarantine": user added → candidate config: pushing… → running config: live
Background

What Prisma Access does, and where it stops.

Palo Alto Networks Prisma Access is a cloud-delivered Security Service Edge (SSE) platform. It provides secure network access for remote users and branch offices, with policies that decide which resources each user group can reach. Powerful, but the group membership is normally a manual job, and every change has to be staged then pushed.

Cloud-delivered SSE

Security Service Edge that sits in front of your users wherever they are, with no on-prem appliance to scale.

Remote and branch ready

Built for distributed workforces and branch offices, secured by a single cloud control plane.

Group-based access

Local user groups gate which resources each user can reach. Move a user between groups, and access changes.

Local Group

Prisma Access local user groups are the lever for differentiated access: put a user in a group and the policies tied to it become the access they get. The catch: keeping group membership in sync with real-world device posture is normally a manual job, and every edit has to be staged in candidate then pushed to running.

Why Integrate

From manual edits and pushes to automatic posture enforcement.

4Remote watches device posture continuously. The moment it changes, the matching Prisma Access local groups are updated for that user and the candidate configuration is pushed automatically. No tickets. No console clicks. No window where a compromised user still has standard access.

Automatic updates

Group memberships change instantly when a user's security posture changes.

Zero Trust enforcement

Only compliant users retain access to protected Prisma Access resources.

Reduced manual work

No need to manually edit local user groups or commit configuration pushes. The integration handles it.

Real-time protection

Non-compliant users are removed from privileged groups immediately, not at the next audit cycle.

Important · Scope

This integration only manages local Prisma Access users. Users authenticated via external identity providers (LDAP, SAML, or other SSO systems) are not managed by this integration and must be handled through those systems.

Important · Config push

Changes in Prisma Access are staged in a candidate configuration and don't take effect until pushed. The integration handles this automatically after each sync.

How it works

Four steps, fully automatic.

The integration runs continuously. Posture changes flow into your Prisma Access tenant within seconds of the next push.

01

Device security is evaluated

The platform monitors device security continuously.

  • Vulnerability scans detect issues
  • Compliance rules check configuration
  • Risk scores reflect findings
02

Zero Trust statuses are assigned

Each user gets the statuses that match their evaluation:

High Security Compliant Quarantine Update Required
03

Local groups are synchronised

The integration updates Prisma Access automatically:

  • Creates matching local user groups if missing
  • Adds users to the groups for their current statuses
  • Removes users from groups they no longer qualify for
04

Configuration is pushed

The candidate configuration is committed to running:

  • Push happens after every successful sync
  • Policies enforce access against the new groups
  • If a push fails, changes wait for the next cycle
Note: Group membership and the configuration push are reconciled together on every sync. There is no drift between what 4Remote sees and what your Prisma Access tenant enforces.
Prisma-only

Candidate, then running. The push is automatic.

Prisma Access uses a candidate/running configuration model. Changes stage in candidate first, then become live after the configuration is pushed. The integration handles the entire lifecycle so you never have to log into the console to commit.

Auto-handled after every sync
Stage 1 · Staged

Candidate

Group changes queued in the candidate configuration. Not yet enforced.

Stage 2 · Pushing

Pushing

Integration commits candidate to running. No console clicks required.

Stage 3 · Live

Running

Policies enforce against the new groups. Access updates take effect immediately.

Failed push? Staged changes are preserved and committed on the next successful sync. No silent drift.

How users are matched

Users are matched by their email address against Prisma Access's local user directory. The user must already exist as a local Prisma Access account for the integration to manage them.

Federated and SSO users (LDAP, SAML, or external IdP) are out of scope. They continue to be governed by your identity provider's groups, not by 4Remote.

  • Local Prisma Access users. Matched by email and synced automatically.
  • LDAP-backed users. Out of scope; manage via your LDAP source.
  • SAML / SSO users. Out of scope; manage via your identity provider.
  • Users without a matching email. Skipped; no action taken until the local account exists.
Real-world example

What happens when a critical CVE drops.

An employee's laptop picks up a critical vulnerability. Here is what 4Remote and Prisma Access do, in seconds, including the configuration push, with no human in the loop.

Scenario

An employee's laptop has a critical vulnerability discovered during a routine scan.

  1. T+0s

    Vulnerability detected

    Scheduled scan flags CVE-2024-1234 at Critical severity on the user's laptop.

  2. T+1s

    Status reassigned

    4Remote moves the user's status from Compliant to Quarantine.

  3. T+2s

    Removed from Compliant (candidate)

    Integration stages the change in candidate config: user removed from Compliant.

  4. T+2s

    Added to Quarantine (candidate)

    Same stage cycle: user added to Quarantine in candidate config.

  5. T+3s

    Configuration pushed Auto

    Candidate is committed to running. Prisma Access policies now enforce against the updated groups.

  6. T+4s

    Access restricted, user notified

    Sensitive resources blocked for the Quarantine group. Employee receives remediation steps with the affected device and the patch needed.

  7. Later

    Access restored

    Patch applied, next scan clears the CVE. Status flips back to Compliant, the candidate is pushed automatically, and access is restored.

Timeline: the full detection, group update, and configuration push completes in seconds, with zero human in the loop.

Get started

Plug it in. Watch your Prisma Access policies flex with posture.

If you run Prisma Access with local users, this integration turns your existing groups into a real-time enforcement layer for Zero Trust, with the configuration push handled automatically. Talk to us about a partner integration or a customer rollout.

Work with Us

Talk to our team

Whether you want to see 4Remote in your own environment, talk through pricing, explore a partnership, or ask us something else entirely, we're ready to respond. Tell us what you need and the right person will come back to you directly.

  • Request a demo. Deployed into your real environment with results visible in the first scan
  • Talk to sales. Straight answers on pricing, editions, and what fits your organisation
  • Partner enquiry. Routed to our channel team to discuss reseller, MSP, MSSP, or white-label options
  • Contact us. Any other question, answered by someone who knows the product
  • UK and US coverage. Real people responding across both time zones