- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-09-2026 01:23 AM
Hello community.
This is a confirmation regarding Prisma Access (existing contract) for a specific project.
As background,
we are currently conducting a Proof of Concept (PoC) to verify whether Prisma Access (via Global Protect) can reliably implement the display of the “Information Security Pledge Screen” for external users of our customer.
This functionality was previously handled by the authentication proxy.
The intended flow is as follows:
- When an unpledged external user attempts to access the web, the user is redirected to an Override page.
- From there, the user is redirected to the pledge page.
- The pledge page itself is configured as Allow.
After the pledge is completed, subsequent user traffic should be routed through a proxy using a PAC file.
However, the pledge page cannot be accessed through the proxy, so unpledged user traffic must not use the PAC file.
Question 1: PAC configuration remains in the Global Protect app
In Prisma Access (Mobile Users):
1. GP App Configuration #1 (PAC enabled)
→ After connecting, the Global Protect app correctly retrieves PAC information.
2. On the same endpoint, we then apply
GP App Configuration #2 (PAC disabled)
→ However, the PAC configuration obtained from Configuration #1 still remains on the device, even though the new configuration has PAC disabled.
Is this the expected behavior?
If so, is there any method to prevent this, such as automatically clearing / removing the previously applied PAC configuration?
Question 2: Priority behavior of Custom URL Categories in Prisma Access
We configured the following Custom URL Categories in Prisma Access:
- Category ①: * (Action: Override)
- Category ②: yahoo.co.jp (Action: Allow)
With this configuration, all traffic matches Category ①, and traffic never matches Category ②.
Is this the expected behavior?
If so, is there any recommended method to give precedence to a specific URL (such as yahoo.co.jp) over a wildcard category?
Thank you very much for your support and clarification.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

