TrustRadius: an HG Insights company

Palo Alto Networks Prisma Access

Score8.9 out of 10

47 Reviews and Ratings

What is Palo Alto Networks Prisma Access?

GlobalProtectâ„¢ delivers the protection of next-generation security platform to the mobile workforce in order to stop targeted cyberattacks, evasive application traffic, phishing, malicious websites, command-and-control traffic, and known and unknown threats.

Palo Alto Networks Prisma Access is the Gorilla in the Room

Use Cases and Deployment Scope

We use Palo Alto Networks Prisma Access for Remote Networks (SDWAN) and Mobile Users (GlobalProtect VPN). This allowed us to decommission on-prem firewalls and allow secure remote access from any office and any sanctioned device around the world.

Pros

  • GlobalProtect VPN works amazing. I can set a single policy set in my MU policies that apply to all of my end-users no matter where their home office or location is. I have offices in America, UK and Asia.
  • The Remote Networks policies were amazing to have a single policy set for all of my 11 offices instead of having to manage an on-oprem firewall in each office and having to make sure all changes are the same across all 11 firewalls (minus the passive HA devices).
  • ADEM allowed us to get proactive information about a GP client's networking/internet position to see if there was going to be a problem with them working based on the last mile and local internet routing information.

Cons

  • We were an early adopter (Q4 2019) so there was some growing pains with the CloudGenix acquisition and Palo rebranding it and shoe-horning it into the Palo Alto Networks Prisma Access ecosystem
  • Support was a huge problem recently. If you had an SDWAN (remote networks) you had to get transitioned to a different team. If you had aPalo Alto Networks Prisma Access problem with ADEM or Mobile Users, you got transitioned to a different team. If you had no idea if the problem was SDWAN related or GP related, then it got bounced around

Return on Investment

  • Palo has increased their pricing and subscriptions lately and is causing us to revisit out position. We have been on Palo for 10 years with on-prem and 5 with Palo Alto Networks Prisma Access so we have a lot of in-house knowledge on how to use and administer Palo Alto Networks Prisma Access but the costs are making use do a cost benefit analysis against some of the other players in the magic quadrant. Especially if we can save costs.
  • Positive note is that when I do client audits (about 70 a year), once I tell them we are on Palo Alto Networks Prisma Access, they immediately check the box for meeting compliance with their requirements.
  • Another negative though is the many recent issues having to update certificates or zero-day vulnerability security updates. When you do this, it causes downtime. We're on 3 continents and run 24x7 so any downtime is difficult to navigate.

Usability

Alternatives Considered

Zscaler Internet Access, Zscaler Digital Experience, Zscaler Private Access, Cato Networks, Cisco Umbrella and Cisco AnyConnect

Other Software Used

Authentic8 Silo, Sumo Logic, Recorded Future Intelligence Cloud, Splunk Cloud

Extra security for apps with prisma.

Use Cases and Deployment Scope

We are making a leap to the organization with the apps and improving them through a good security infrastructure, we reinforce the connection since we have much monitoring in the company, and Palo Alto has given us a good network reinforcement experience, in addition, to providing us with continuous updates so that we are not left with an antiquated protected network.

Pros

  • A secure end-to-end network with virtualization to be able to choose the port of our interest and an opening of the same.
  • Monthly updates that are sufficient, automatic updates that allow us not to have to do the manual implementation.
  • Prisma allows automatically opens an IPsec/SSL VPN connection to Prisma Access.
  • Is flexible and scalable

Cons

  • It has a stable connection, it is secure and it has very good help support, I think it is time to say that I have no negative things to say related to prism so far. Has fully met the demarcated objective.

Most Important Features

  • I agree that the first is the security of stability that it gives us.
  • The expeditious support in which they have no drama in providing us with driving information in the wee hours of the evening.
  • Opening ports at ease.

Return on Investment

  • An estimated return on investment will be obtained in approximately 1 year.
  • The delay in entering applications with extra security has been saved by 5% vs. the old application, similar to the prism that we had.
  • We have reduced many more intrusions.
  • We have been able to save money on hiring helpers on tumultuous meddling repairs in the past.

East to use and well thought out mobile security management

Use Cases and Deployment Scope

Our company uses [Palo Alto Networks] GlobalProtect Mobile Security [Manager] to manage the large number of mobile phones and devices we have around the globe in one place with one common piece of software. This is needed especially now more than ever with almost all of our 5k+ employees located in remote work from home scenarios.

Pros

  • Complete control and configuration of iOS devices across our network.
  • Great username options in the latest version to help keep our devices organized and easy to manage.
  • Easy to enroll devices to connect to the VPN.

Cons

  • With all of it's unique features it does take some time to get folks up to speed in regards to supporting/managing the software.
  • Doesn't always play nice with non Palo Alto software.

Most Important Features

  • All devices managed in one place
  • Ability to create different security levels/groups
  • Wide range of configuration options

Return on Investment

  • This solved our problem of having more than one piece of software to manage access for different types of mobile devices.
  • Reduced our cost of needing multiple licenses to manage our VPN connectivity outside of the office.

Alternatives Considered

Trend Micro Mobile Security for Enterprises and Cisco AnyConnect

Other Software Used

DBeaver, Smartsheet

Great tool for remote access.

Pros

  • The ease of use through the panorama console is a big plus.
  • Users have reported back to us that they have had less issues getting connected.
  • Less latency in the connections in general.

Cons

  • It has created another area for us to manage some of the internet traffic for our users. Sites being open on-site and not on remote access or vice versa.
  • In general, the certificates are easier to handle than while on Cisco solution, it is still a pain to get the remote device a cert in place if it has "broken."
  • We would like to lock in the ability of which gateway we use to connect to the network. While it's not been an issue for us we have seen some oddness when using a different gateway than the preferred one.

Most Important Features

  • The rollout process was extremely simple and easy to lock down so that end-users could not make changes to the agents.
  • Ease of use for the end users.
  • Part of our already in place eco system of vendor technologies.

Return on Investment

  • It is extremely easy to manage who has remote access in our organization now.
  • It has allowed us to more fluidly get remote workers up and running.
  • Another tool to mange is never a good thing and the Panorama UI could use a little work.

Alternatives Considered

Cisco AnyConnect

Palo Alto Networks comes through

Pros

  • Easy to configure.
  • Authentication rules can be made as strict as required to satisfy stringent audits.
  • Easy for end users.

Cons

  • I thought it did all things required very well.

Return on Investment

  • It allowed us to pass very strict audits from the world's largest banks.
  • It was easy for our IT department to implement.

Alternatives Considered

SonicWall Email Security Software

Other Software Used

Microsoft Dynamics CRM, Microsoft Visual Studio Team System, JIRA Software