Managed Enterprise Browser Security with Prisma Browser for MSPs

Sep 08, 2026
5 minutes

Many organizations today face a common challenge: they require enterprise-grade security but lack the time, specialized resources, or infrastructure to manage it effectively. As a result, they turn to Managed Service Providers (MSPs) to help them deploy, manage, and operate security services. MSPs offering such services to a large number of customers in turn face significant administrative overhead.

To address this challenge, Palo Alto Networks is introducing Prisma Browser for MSPs. Purpose-built for NextWave MSSP Partners, this new capability enables Managed Service Providers (MSPs) to deliver powerful, browser-based security to customers. By streamlining deployment, centralizing management, and offering flexible licensing, Prisma Browser for MSPs removes the operational friction of individually managing Prisma Browser deployments for hundreds of end customers.

Secure the Future of Work with Prisma Browser

The browser has become the primary workspace for today's employees, making it one of the most effective places to enforce security. As users access SaaS applications, private applications, corporate data, and GenAI tools through the browser, organizations need security that protects every web session. Leveraging Palo Alto Network’s AI-driven security, which blocks up to 9 million new and unique attacks every day, and enterprise DLP, Prisma Browser stops web-based threats, secures interactions with sensitive data, and prevents unauthorized data sharing across web applications and AI applications. 

Prisma Browser enables MSPs to deliver enterprise-grade web security, browser-native data protection, and secure access directly in the browser. Customers can confidently adopt GenAI while preventing sensitive data from being exposed to unsanctioned AI applications. It also  stops phishing, malware, malicious websites, and browser-based attacks before they impact users, and protect sensitive information with policies that prevent unauthorized downloads, uploads, copy-and-paste, and other data exfiltration techniques. The same browser also enables organizations to securely support BYOD and third-party contractors by extending consistent security controls to unmanaged devices without compromising user experience or requiring corporate-issued endpoints. 

Managed Browser Solution: Hierarchical Tenancy Model Built for Efficiency

At the core of Prisma Browser for MSPs is a streamlined management model, with Multi-Tenant Strata Cloud Manager, designed to optimize visibility, provisioning and license management across your entire customer ecosystem. The multi-tenant architecture has two distinct levels:

  • The Root Tenant: Serving as your primary administrative container, the root tenant is where the Prisma Browser license pool is activated. From this single vantage point, administrators can dynamically allocate license capacity, enforce baseline security policies, and monitor deployment health across all associated customers.
  • Child Tenants: Each child tenant represents an individual customer deployment. To uphold strict data separation and privacy controls, child tenants operate as dedicated environments with their own users and devices, and if needed the ability to customize security policies. MSPs can grant access to end customers to view or manage their own tenant. No customer can view or access another’s data, providing complete organizational boundaries.

Operational dashboard showing health of deployment across the multi-tenant hierarchy

Optimizing License Management and Identity Architecture

Managing separate software procurement contracts and Identity Platform integrations for each end customer is an operational overhead that can quickly stall an MSP's growth. This new platform addresses those exact operational bottlenecks through infrastructure flexibility.

Dynamic License Pooling

MSPs purchase a pool of Prisma Browser licenses (minimum of 200 users across all customers) and can dynamically allocate them to child tenants (as low as one user). If an end customer wants to reduce the number of users or not renew, those licenses can be reclaimed and returned to the central license pool. This allows MSPs to service customers of any size without the overhead of unused licenses.

Unified Identity Architecture

Integrating distinct Identity Providers (IdPs) for every end customer can quickly become a deployment bottleneck. The platform addresses this with MSP IdP architecture, allowing providers to host a single, centralized IdP at the root level, and create user groups to authenticate users across each child tenant. For end customers who have their own IdP platform, this solution also seamlessly supports Tenant-Specific IdPs linked to a tenant-level Cloud Identity Engine (CIE).

Streamlining Customer Onboarding and Security Reporting

To accelerate time-to-value, the platform features a self-service Add Tenant Wizard within the Strata Multi-tenant Cloud Manager UI. This guided, step-by-step workflow automates the provisioning process—including region selection, license allocation, and IdP configuration—allowing administrators to deploy new customer environments in minutes. For MSPs that want to automate the process, the same workflow can be invoked via APIs.

Once deployed, Prisma Browser for MSPs provides robust visibility needed to maintain a strong security posture and clearly demonstrate service value to your clients:

  • Aggregated Security Metrics: The root dashboard surfaces macro-level insights across all tenants, including the total number of websites analyzed and a detailed breakdown of blocked threats by category and method.
  • Demonstrable Customer Value: Administrators can generate and download tenant-specific reports for individual customers. These reports detail top malicious websites, malware families, and malicious extensions blocked, giving MSPs the data they need to prove the tangible impact of their security services.

Scaling Managed Security Services with Enterprise Browser

The introduction of Prisma Browser for MSPs fundamentally redefines how Managed Service Providers secure the modern enterprises, with The Most Secure Browser Built for the Agentic AI Era. By combining enterprise-grade threat protection with an operationally efficient, multi-tenant framework, Palo Alto Networks empowers MSPs to scale their business, protect their customers, and eliminate management complexity.

Deploy a Secure Browser for Your Customers

Ready to simplify your browser security deployments and eliminate administrative overhead? Review the Prisma Browser prerequisites in the NextWave Partner Community or contact your account representative to activate your multi-tenant licenses today.


Subscribe to Sase Blogs!

Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more.