# palo-alto

Source: https://startwithidentity.com/vendors/zero-trust/palo-alto/
Last updated: 2026-01-15
License: content by Start with Identity. Cite the source URL.

---

## Overview

Prisma Access is Palo Alto Networks' Security Service Edge (SSE) and SASE platform, extending its next-generation firewall heritage into the cloud. Its natural buyer is the large enterprise already standardized on Palo Alto firewalls that wants the same threat-prevention and policy model applied to remote users and branches. Palo Alto's pending acquisition of [CyberArk](https://startwithidentity.com/vendors/pam/cyberark/) signals a deeper move into identity security.

## What it is good at

Consistent, leading network security. Prisma Access brings PAN-OS threat prevention, URL filtering, and DLP to a cloud-delivered edge, so security teams keep one policy and threat model from data center to remote worker. ZTNA provides identity-aware per-application access, and integration with the broader Palo Alto platform (Cortex, firewalls) is a major draw for existing customers. Support and enterprise credibility are strong.

## Where it falls short

The value is highest if you are already a Palo Alto shop; for greenfield teams without that investment, the platform is heavy and the pricing is enterprise-tier and quote-based. It consumes identity from your IdP rather than providing it, and developer-centric, self-serve access is better served by [Cloudflare](https://startwithidentity.com/vendors/zero-trust/cloudflare/) or [Tailscale](https://startwithidentity.com/vendors/zero-trust/tailscale/). It competes head-on with [Zscaler](https://startwithidentity.com/vendors/zero-trust/zscaler/) and [Netskope](https://startwithidentity.com/vendors/zero-trust/netskope/) at the top of the market.

## Pricing

Quote-based and enterprise-tier, typically by user and module, often bundled with broader Palo Alto commitments.

## Best for, and who should look elsewhere

Choose Prisma Access when you run Palo Alto firewalls and want unified policy and threat prevention across a cloud edge. Choose Zscaler for the largest pure-SSE consolidations, Netskope for data-centric needs, or Cloudflare and Tailscale for value and simplicity.

## Bottom line

A strong SASE choice for Palo Alto enterprises that value one consistent security platform, less compelling for greenfield or lightweight needs.
