<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does Prisma Browser support device-based Conditional Access (device ID / compliance)? in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/does-prisma-browser-support-device-based-conditional-access/m-p/1255878#M1300</link>
    <description>&lt;P&gt;Nice that you are sharing this info with the community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe see&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-browser-for-mobile/td-p/1255306" target="_blank" rel="noopener"&gt;LIVEcommunity - Prisma Browser for Mobile - LIVEcommunity - 1255306&lt;/A&gt;&amp;nbsp;as I mentioned &lt;SPAN&gt;SAA&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma-access/administration/secure-agentless-access" target="_blank" rel="nofollow noopener noreferrer"&gt;Secure Agentless Access&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp; that could be an option as well.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Other than that if it is corporate device Globalprotect or Prisma Agent could be an option or to use something like MAM isolation for BYOD devices&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/intune/app-management/protection/mam-without-enrollment" target="_blank" rel="noopener"&gt;Mobile Application Management (MAM) for unenrolled devices in Microsoft Intune - Microsoft Intune | Microsoft Learn&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jun 2026 15:13:30 GMT</pubDate>
    <dc:creator>nikoolayy1</dc:creator>
    <dc:date>2026-06-10T15:13:30Z</dc:date>
    <item>
      <title>Does Prisma Browser support device-based Conditional Access (device ID / compliance)?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/does-prisma-browser-support-device-based-conditional-access/m-p/1254142#M1292</link>
      <description>&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;Hi all,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;I’m currently investigating an issue with Prisma Access Browser (Android) in combination with Microsoft Entra Conditional Access and wanted to check if anyone has faced something similar.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;Setup:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;- Prisma Browser deployed via Intune (Android Enterprise, fully managed/BYOD)&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;- Company Portal installed and device properly enrolled&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;- Microsoft Authenticator used for MFA&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;- Authentication is routed via Palo Alto Cloud Identity Engine (Cloud Authentication Service)&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;- Conditional Access policy requires device-based conditions (device trust / compliance)&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;Issue:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;When users access an application (e.g. SaaS app protected by Entra Conditional Access) through Prisma Browser, the sign-in logs in Entra show:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;- Device ID: not present&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;- Join Type: not set&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;- Managed: No&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;- Compliant: No&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;Even in the Cloud Identity Engine (CAS) logs, device attributes are missing.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;Assumption:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;It seems that Prisma Browser does not pass through device identity / device claims to Entra (possibly due to its authentication flow and/or CAS integration).&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;Questions:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;- Is Prisma Browser on Android expected to support device-based Conditional Access (device ID, compliance, join type)?&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;- Does Prisma Browser integrate with Microsoft broker (Authenticator / Company Portal) for device identity?&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;- Is there any configuration required to enable device claims passthrough?&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;- Or is this a known limitation by design?&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;Currently, the only workaround is to use network-based exclusions, which weakens the Conditional Access model.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;Would appreciate any insights or experiences.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="scriptor-paragraph"&gt;&lt;SPAN&gt;Thanks!&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 17 May 2026 20:08:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/does-prisma-browser-support-device-based-conditional-access/m-p/1254142#M1292</guid>
      <dc:creator>SeriThal</dc:creator>
      <dc:date>2026-05-17T20:08:41Z</dc:date>
    </item>
    <item>
      <title>Re: Does Prisma Browser support device-based Conditional Access (device ID / compliance)?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/does-prisma-browser-support-device-based-conditional-access/m-p/1254733#M1293</link>
      <description>&lt;P&gt;Prisma Access has it's own Device ID as shown in&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/prisma-access-browser/administration/manage-prisma-access-browser-devices" target="_blank" rel="noopener"&gt;Manage Prisma Browser Devices&lt;/A&gt;&amp;nbsp;that can be grouped in Device Groups.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;About integrating with Microsoft Conditional Access Device ID after I checked with AI (I used Copilot but chatgpt should also help) I see that it may need&amp;nbsp;Windows Accounts Extension and maybe you have not allowed this extension that collects this data from the machine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also see&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/prisma-access-browser/integrations/windows-account-based-sso-authentication" target="_blank" rel="noopener"&gt;Windows Account Based SSO Authentication&lt;/A&gt;&amp;nbsp;and maybe enable&amp;nbsp;&lt;STRONG class="ph b"&gt;Microsoft Auto-SSO.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As Prisma Browser is heavily restricted on extensions that could be the issue but if not better open a support case.&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2026 06:05:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/does-prisma-browser-support-device-based-conditional-access/m-p/1254733#M1293</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2026-05-26T06:05:12Z</dc:date>
    </item>
    <item>
      <title>Re: Does Prisma Browser support device-based Conditional Access (device ID / compliance)?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/does-prisma-browser-support-device-based-conditional-access/m-p/1255794#M1299</link>
      <description>&lt;P&gt;Feedback from Palo Alto Support to this question (PAN Copilot):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The issue you are encountering with Prisma Browser on Android and iOS devices, where device attributes such as Device ID, Join Type, Managed, and Compliant are not being passed to Microsoft Entra Conditional Access, stems from specific architectural and feature limitations.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Root Cause&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The primary root cause is that the "Microsoft Auto-SSO" feature, which includes the "Microsoft Single Sign On" Extension, is explicitly supported only on Microsoft Windows and macOS devices, and not on mobile operating systems like Android or iOS &lt;A href="https://docs.paloaltonetworks.com/prisma-access-browser/administration/manage-prisma-access-browser-policy-profiles/configure-prisma-access-browser-browser-customization/configure-customization" target="_blank"&gt;1&lt;/A&gt;. Therefore, enabling this extension for mobile Prisma Browser users will not yield the desired device identity passthrough.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Additionally, when configuring the Cloud Identity Engine (CIE) as a mapping source for user and group information, the documentation explicitly advises to "Leave the Device Attributes as None" &lt;A href="https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-user-based-policy/retrieve-user-id-information/retrieve-group-mapping-using-the-cloud-identity-engine" target="_blank"&gt;2&lt;/A&gt;. This indicates that the current design of CIE, in this context, does not facilitate the passthrough of detailed device attributes to downstream systems like Microsoft Entra ID for granular conditional access evaluation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;While Prisma Browser Mobile performs its own device posture assessment and can integrate with Mobile Device Management (MDM) solutions, this is primarily for enforcing Prisma Browser's internal access policies rather than forwarding those specific device claims directly to Microsoft Entra Conditional Access for its evaluation.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Known Limitations and Answers to Your Questions&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Is Prisma Browser on Android and iOS expected to support device-based Conditional Access (device ID, compliance, join type)?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prisma Browser Mobile &lt;EM&gt;does&lt;/EM&gt; perform its own device posture assessment. It can evaluate attributes such as root/jailbreak status, active screen lock, OS versions (iOS and Android), device type, and device manufacturer &lt;A href="https://docs.paloaltonetworks.com/prisma-access-browser/administration/manage-prisma-access-browser-devices/prisma-access-browser-mobile-device-posture-attributes" target="_blank"&gt;3&lt;/A&gt; &lt;A href="https://www.paloaltonetworks.com/resources/datasheets/prisma-access-browser" target="_blank"&gt;4&lt;/A&gt;. This assessment ensures the browser runs in a secure environment and can restrict access if the device posture is non-compliant &lt;A href="https://www.paloaltonetworks.com/resources/datasheets/prisma-access-browser" target="_blank"&gt;4&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Furthermore, Prisma Access Browser Mobile can integrate with MDM solutions (like Microsoft Intune) to enforce sign-in policies based on device management status and can reuse existing MDM compliance rules for its &lt;EM&gt;own&lt;/EM&gt; access control &lt;A href="https://docs.paloaltonetworks.com/prisma-access-browser/integrations/third-party-integrations/enforcing-prisma-access-browser-mobile-access-on-managed-devices-using-mdm-app-configuration" target="_blank"&gt;5&lt;/A&gt;. This allows for secure access by ensuring only MDM-enrolled, compliant devices can sign in to PAB Mobile &lt;A href="https://docs.paloaltonetworks.com/prisma-access-browser/integrations/third-party-integrations/enforcing-prisma-access-browser-mobile-access-on-managed-devices-using-mdm-app-configuration" target="_blank"&gt;5&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, the direct passthrough of comprehensive device identity/claims (Device ID, Join Type, Managed, Compliant) from Prisma Browser on Android and iOS to Microsoft Entra Conditional Access for Entra's native evaluation is not explicitly supported by the current Microsoft Auto-SSO feature on these mobile platforms &lt;A href="https://docs.paloaltonetworks.com/prisma-access-browser/administration/manage-prisma-access-browser-policy-profiles/configure-prisma-access-browser-browser-customization/configure-customization" target="_blank"&gt;1&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Does Prisma Browser integrate with Microsoft broker (Authenticator / Company Portal) for device identity?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prisma Browser Mobile can leverage MDM integration (e.g., with Intune and Company Portal) for its own internal policy enforcement regarding device management status and compliance &lt;A href="https://docs.paloaltonetworks.com/prisma-access-browser/integrations/third-party-integrations/enforcing-prisma-access-browser-mobile-access-on-managed-devices-using-mdm-app-configuration" target="_blank"&gt;5&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For iOS/iPad devices, in cases where authentication issues arise due to a missing device ID, the Authenticator app, if installed on the same device as Prisma Browser, can communicate and pass the "Entra ID that is needed for authentication" &lt;A href="https://docs.paloaltonetworks.com/prisma-access-browser/deployment/troubleshoot-the-prisma-access-browser" target="_blank"&gt;6&lt;/A&gt;. This suggests a limited form of device identity passthrough for authentication purposes on iOS/iPad, but it does not encompass the full spectrum of device claims (Join Type, Managed, Compliant) required by Microsoft Entra Conditional Access policies for comprehensive device-based conditions.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Is there any configuration required to enable device claims passthrough?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Based on the available documentation, there is no specific configuration within Prisma Browser or Cloud Identity Engine that enables the comprehensive passthrough of device claims (Device ID, Join Type, Managed, Compliant) from Prisma Browser on Android and iOS directly to Microsoft Entra Conditional Access for its policy evaluation. The "Microsoft Auto-SSO" control is explicitly noted as having "No support" for mobile browsers &lt;A href="https://docs.paloaltonetworks.com/prisma-access-browser/administration/manage-prisma-access-browser-policy-profiles/configure-prisma-access-browser-browser-customization/configure-customization" target="_blank"&gt;1&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The configuration for Cloud Identity Engine as a mapping source for user and group information specifically requires leaving "Device Attributes as None" &lt;A href="https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-user-based-policy/retrieve-user-id-information/retrieve-group-mapping-using-the-cloud-identity-engine" target="_blank"&gt;2&lt;/A&gt;, indicating that this component is not intended for device attribute forwarding in this manner.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Or is this a known limitation by design?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Yes, based on the documentation, the inability to pass detailed device identity/claims (Device ID, Join Type, Managed, Compliant) from Prisma Browser on Android and iOS directly to Microsoft Entra Conditional Access for evaluation appears to be a known limitation by design, particularly concerning the "Microsoft Auto-SSO" feature &lt;A href="https://docs.paloaltonetworks.com/prisma-access-browser/administration/manage-prisma-access-browser-policy-profiles/configure-prisma-access-browser-browser-customization/configure-customization" target="_blank"&gt;1&lt;/A&gt; and the current configuration scope of the Cloud Identity Engine for device attributes &lt;A href="https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-user-based-policy/retrieve-user-id-information/retrieve-group-mapping-using-the-cloud-identity-engine" target="_blank"&gt;2&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Remediation&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Given these limitations, the recommended approach is to leverage the device posture assessment capabilities of Prisma Browser Mobile and its MDM integration for enforcing access policies, rather than relying on direct device claims passthrough to Microsoft Entra Conditional Access for mobile devices.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Utilize Prisma Browser Mobile's Device Posture Enforcement&lt;/STRONG&gt;:&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;Configure Prisma Browser Mobile device groups based on attributes such as root/jailbreak status, active screen lock, OS versions, device type, and manufacturer &lt;A href="https://docs.paloaltonetworks.com/prisma-access-browser/administration/manage-prisma-access-browser-devices/prisma-access-browser-mobile-device-posture-attributes" target="_blank"&gt;3&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;Enforce sign-in rules for Prisma Browser Mobile that utilize these device groups to control access based on the device's posture &lt;A href="https://docs.paloaltonetworks.com/prisma-access-browser/deployment/prisma-access-mobile-browser" target="_blank"&gt;7&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;Ensure your MDM solution (Intune) is configured to enforce necessary compliance checks, which Prisma Browser Mobile can then leverage for its own access policies &lt;A href="https://docs.paloaltonetworks.com/prisma-access-browser/integrations/third-party-integrations/enforcing-prisma-access-browser-mobile-access-on-managed-devices-using-mdm-app-configuration" target="_blank"&gt;5&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Review Conditional Access Policy for Mobile Devices&lt;/STRONG&gt;:&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;Since direct device claims passthrough for Entra Conditional Access is limited from Prisma Browser on mobile, consider if your Conditional Access policies can be adjusted to rely on other signals available from the authentication flow or user context, or if the device posture enforcement within Prisma Browser Mobile itself is sufficient for the target applications.&lt;/LI&gt;
&lt;LI&gt;The current workaround of using network-based exclusions, as you noted, weakens the Conditional Access model. By enforcing device posture directly within Prisma Browser Mobile, you can achieve a similar level of security for access &lt;EM&gt;through&lt;/EM&gt; the browser.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;Verification&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;To verify the configuration and behavior:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Monitor Prisma Browser Mobile Logs&lt;/STRONG&gt;: Check Prisma Browser Mobile logs for device posture assessment results and policy enforcement actions &lt;A href="https://www.paloaltonetworks.com/resources/datasheets/prisma-access-browser" target="_blank"&gt;4&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Verify MDM Integration&lt;/STRONG&gt;: Confirm that Prisma Browser Mobile is successfully deployed and managed by Intune, and that MDM compliance rules are being applied to the devices &lt;A href="https://docs.paloaltonetworks.com/prisma-access-browser/integrations/third-party-integrations/enforcing-prisma-access-browser-mobile-access-on-managed-devices-using-mdm-app-configuration" target="_blank"&gt;5&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Test Access with Compliant and Non-Compliant Devices&lt;/STRONG&gt;: Test access to the SaaS application protected by Entra Conditional Access using devices that meet and do not meet your defined Prisma Browser Mobile posture requirements. Observe if Prisma Browser Mobile correctly restricts access based on its internal policies.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Product Documentation&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;1 &lt;A href="https://docs.paloaltonetworks.com/prisma-access-browser/administration/manage-prisma-access-browser-policy-profiles/configure-prisma-access-browser-browser-customization/configure-customization" target="_blank"&gt;Configure Customization&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;2 &lt;A href="https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-user-based-policy/retrieve-user-id-information/retrieve-group-mapping-using-the-cloud-identity-engine" target="_blank"&gt;Prisma Access User-Based Policy: Retrieving Group Mapping Using the Cloud Identity Engine&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;3 &lt;A href="https://docs.paloaltonetworks.com/prisma-access-browser/administration/manage-prisma-access-browser-devices/prisma-access-browser-mobile-device-posture-attributes" target="_blank"&gt;Configure Prisma Browser Mobile Device Posture Attributes&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;4 &lt;A href="https://www.paloaltonetworks.com/resources/datasheets/prisma-access-browser" target="_blank"&gt;prisma-access-browser&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;5 &lt;A href="https://docs.paloaltonetworks.com/prisma-access-browser/integrations/third-party-integrations/enforcing-prisma-access-browser-mobile-access-on-managed-devices-using-mdm-app-configuration" target="_blank"&gt;Enforcing Prisma Access Browser Mobile Access on Managed Devices Using MDM App Configuration&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;6 &lt;A href="https://docs.paloaltonetworks.com/prisma-access-browser/deployment/troubleshoot-the-prisma-access-browser" target="_blank"&gt;Troubleshoot the Prisma Browser&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;7 &lt;A href="https://docs.paloaltonetworks.com/prisma-access-browser/deployment/prisma-access-mobile-browser" target="_blank"&gt;Prisma Browser for Mobile&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2026 06:40:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/does-prisma-browser-support-device-based-conditional-access/m-p/1255794#M1299</guid>
      <dc:creator>Stefan_Somogyi</dc:creator>
      <dc:date>2026-06-10T06:40:42Z</dc:date>
    </item>
    <item>
      <title>Re: Does Prisma Browser support device-based Conditional Access (device ID / compliance)?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/does-prisma-browser-support-device-based-conditional-access/m-p/1255878#M1300</link>
      <description>&lt;P&gt;Nice that you are sharing this info with the community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe see&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-browser-for-mobile/td-p/1255306" target="_blank" rel="noopener"&gt;LIVEcommunity - Prisma Browser for Mobile - LIVEcommunity - 1255306&lt;/A&gt;&amp;nbsp;as I mentioned &lt;SPAN&gt;SAA&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma-access/administration/secure-agentless-access" target="_blank" rel="nofollow noopener noreferrer"&gt;Secure Agentless Access&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp; that could be an option as well.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Other than that if it is corporate device Globalprotect or Prisma Agent could be an option or to use something like MAM isolation for BYOD devices&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/intune/app-management/protection/mam-without-enrollment" target="_blank" rel="noopener"&gt;Mobile Application Management (MAM) for unenrolled devices in Microsoft Intune - Microsoft Intune | Microsoft Learn&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2026 15:13:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/does-prisma-browser-support-device-based-conditional-access/m-p/1255878#M1300</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2026-06-10T15:13:30Z</dc:date>
    </item>
  </channel>
</rss>

