after you upgrade Panorama to 10.1, you will be able to manage all Firewalls running older version of PAN-OS. As long as Panorama is running the same or higher version than managed Firewall, it is going to be compatible.
I can agree with what @PavelK said with one clarification. Although there is no official support matrix for Panorama, it seems Panorama cannot support "difference bigger than a major release" (exact words from PAN support engineer). So Panorama cannot support all earlier version, there is a limit. I wish only Palo Alto to public official guide for that limitation.
Couple of months ago we tried to onboard FW running 9.0 on Panorama running 10.1, but it was failing to commit on the FW. PAN support engineer explained that Panorama was pushing config for 9.1, which firewall obviously was failing to commit. The only solution was to upgrade FW to 9.1, as it was the lowest supported version by Panorama running 10.1.
So I can confirm that Panorama 10.1 can manage without issues FWs running 9.1 and above
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!