<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does Prisma Browser support device-based Conditional Access (device ID / compliance)? in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/does-prisma-browser-support-device-based-conditional-access/m-p/1254733#M1293</link>
    <description>&lt;P&gt;Prisma Access has it's own Device ID as shown in&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/prisma-access-browser/administration/manage-prisma-access-browser-devices" target="_blank" rel="noopener"&gt;Manage Prisma Browser Devices&lt;/A&gt;&amp;nbsp;that can be grouped in Device Groups.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;About integrating with Microsoft Conditional Access Device ID after I checked with AI (I used Copilot but chatgpt should also help) I see that it may need&amp;nbsp;Windows Accounts Extension and maybe you have not allowed this extension that collects this data from the machine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also see&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/prisma-access-browser/integrations/windows-account-based-sso-authentication" target="_blank" rel="noopener"&gt;Windows Account Based SSO Authentication&lt;/A&gt;&amp;nbsp;and maybe enable&amp;nbsp;&lt;STRONG class="ph b"&gt;Microsoft Auto-SSO.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As Prisma Browser is heavily restricted on extensions that could be the issue but if not better open a support case.&lt;/P&gt;</description>
    <pubDate>Tue, 26 May 2026 06:05:12 GMT</pubDate>
    <dc:creator>nikoolayy1</dc:creator>
    <dc:date>2026-05-26T06:05:12Z</dc:date>
    <item>
      <title>Does Prisma Browser support device-based Conditional Access (device ID / compliance)?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/does-prisma-browser-support-device-based-conditional-access/m-p/1254142#M1292</link>
      <description>&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;Hi all,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;I’m currently investigating an issue with Prisma Access Browser (Android) in combination with Microsoft Entra Conditional Access and wanted to check if anyone has faced something similar.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;Setup:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;- Prisma Browser deployed via Intune (Android Enterprise, fully managed/BYOD)&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;- Company Portal installed and device properly enrolled&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;- Microsoft Authenticator used for MFA&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;- Authentication is routed via Palo Alto Cloud Identity Engine (Cloud Authentication Service)&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;- Conditional Access policy requires device-based conditions (device trust / compliance)&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;Issue:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;When users access an application (e.g. SaaS app protected by Entra Conditional Access) through Prisma Browser, the sign-in logs in Entra show:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;- Device ID: not present&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;- Join Type: not set&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;- Managed: No&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;- Compliant: No&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;Even in the Cloud Identity Engine (CAS) logs, device attributes are missing.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;Assumption:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;It seems that Prisma Browser does not pass through device identity / device claims to Entra (possibly due to its authentication flow and/or CAS integration).&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;Questions:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;- Is Prisma Browser on Android expected to support device-based Conditional Access (device ID, compliance, join type)?&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;- Does Prisma Browser integrate with Microsoft broker (Authenticator / Company Portal) for device identity?&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;- Is there any configuration required to enable device claims passthrough?&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;- Or is this a known limitation by design?&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;Currently, the only workaround is to use network-based exclusions, which weakens the Conditional Access model.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;Would appreciate any insights or experiences.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;Thanks!&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 17 May 2026 20:08:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/does-prisma-browser-support-device-based-conditional-access/m-p/1254142#M1292</guid>
      <dc:creator>SeriThal</dc:creator>
      <dc:date>2026-05-17T20:08:41Z</dc:date>
    </item>
    <item>
      <title>Re: Does Prisma Browser support device-based Conditional Access (device ID / compliance)?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/does-prisma-browser-support-device-based-conditional-access/m-p/1254733#M1293</link>
      <description>&lt;P&gt;Prisma Access has it's own Device ID as shown in&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/prisma-access-browser/administration/manage-prisma-access-browser-devices" target="_blank" rel="noopener"&gt;Manage Prisma Browser Devices&lt;/A&gt;&amp;nbsp;that can be grouped in Device Groups.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;About integrating with Microsoft Conditional Access Device ID after I checked with AI (I used Copilot but chatgpt should also help) I see that it may need&amp;nbsp;Windows Accounts Extension and maybe you have not allowed this extension that collects this data from the machine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also see&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/prisma-access-browser/integrations/windows-account-based-sso-authentication" target="_blank" rel="noopener"&gt;Windows Account Based SSO Authentication&lt;/A&gt;&amp;nbsp;and maybe enable&amp;nbsp;&lt;STRONG class="ph b"&gt;Microsoft Auto-SSO.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As Prisma Browser is heavily restricted on extensions that could be the issue but if not better open a support case.&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2026 06:05:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/does-prisma-browser-support-device-based-conditional-access/m-p/1254733#M1293</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2026-05-26T06:05:12Z</dc:date>
    </item>
  </channel>
</rss>

