<?xml version="1.0" encoding="UTF-8"?>        <rss version="2.0"
             xmlns:atom="http://www.w3.org/2005/Atom"
             xmlns:dc="http://purl.org/dc/elements/1.1/"
             xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
             xmlns:admin="http://webns.net/mvcb/"
             xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
             xmlns:content="http://purl.org/rss/1.0/modules/content/">
        <channel>
            <title>
									Palo Alto Prisma Access Reviews - Welcome to Stackinsight community. Join the discussion about products and tools for work Forum				            </title>
            <link>https://communities.stackinsight.net/community/cyber-prisma-access/</link>
            <description>Welcome to Stackinsight community. Join the discussion about products and tools for work Discussion Board</description>
            <language>en-US</language>
            <lastBuildDate>Thu, 23 Jul 2026 12:25:23 +0000</lastBuildDate>
            <generator>wpForo</generator>
            <ttl>60</ttl>
							                    <item>
                        <title>Thoughts on the new &#039;pre-deployment&#039; assessment tool? Marketing fluff or useful?</title>
                        <link>https://communities.stackinsight.net/community/cyber-prisma-access/thoughts-on-the-new-pre-deployment-assessment-tool-marketing-fluff-or-useful/</link>
                        <pubDate>Tue, 21 Jul 2026 19:14:34 +0000</pubDate>
                        <description><![CDATA[Just saw the announcement for Prisma Access&#039;s new pre-deployment assessment &quot;tool.&quot; They&#039;re touting it as a way to &quot;eliminate deployment risk&quot; and &quot;ensure optimal configuration.&quot; Sounds like...]]></description>
                        <content:encoded><![CDATA[Just saw the announcement for Prisma Access's new pre-deployment assessment "tool." They're touting it as a way to "eliminate deployment risk" and "ensure optimal configuration." Sounds like the standard vendor promise of a magic wand before you sign the big PO.

My immediate question: is this anything more than a glorified, automated version of the spreadsheet their SEs already walk you through? You know the drill:
*   "How many locations?"
*   "Expected throughput per site?"
*   "List your critical apps for testing."

If it's just that with a fancy UI, it's pure marketing fluff. A real assessment would need deep integration into my existing network configs to spot the actual gotchas—like that legacy app no one remembers that uses a weird port and will break the second you tunnel all traffic.

I'm all for tools that reduce the pain of rolling out SASE, but I'm deeply skeptical of anything offered for "free" by the vendor pre-sales. The incentives aren't aligned. Their goal is to show a smooth path to purchase, not to highlight the 40 hours of re-engineering my DNS architecture I'll actually need.

Has anyone gone through this new process yet? Did it surface any non-obvious configuration issues, or just tell you what you already knew to size the bill appropriately?]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-prisma-access/">Palo Alto Prisma Access Reviews</category>                        <dc:creator>Ava23</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-prisma-access/thoughts-on-the-new-pre-deployment-assessment-tool-marketing-fluff-or-useful/</guid>
                    </item>
				                    <item>
                        <title>Anyone else&#039;s tunnel stability tank after the 5.1 update?</title>
                        <link>https://communities.stackinsight.net/community/cyber-prisma-access/anyone-elses-tunnel-stability-tank-after-the-5-1-update/</link>
                        <pubDate>Tue, 21 Jul 2026 19:00:36 +0000</pubDate>
                        <description><![CDATA[Our global tunnels have been dropping multiple times a day since the 5.1.0 upgrade. Complete instability. No changes to our config, no ISP issues on our end.

Support case opened, but they&#039;r...]]></description>
                        <content:encoded><![CDATA[Our global tunnels have been dropping multiple times a day since the 5.1.0 upgrade. Complete instability. No changes to our config, no ISP issues on our end.

Support case opened, but they're pointing fingers at our SD-WAN. That's nonsense—it was rock solid on 5.0.9. Anyone else seeing this? Specifically with IKEv2 tunnels to on-prem firewalls.]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-prisma-access/">Palo Alto Prisma Access Reviews</category>                        <dc:creator>danw</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-prisma-access/anyone-elses-tunnel-stability-tank-after-the-5-1-update/</guid>
                    </item>
				                    <item>
                        <title>Help: &#039;Max Sessions&#039; limit constantly hit, but our user count is under license.</title>
                        <link>https://communities.stackinsight.net/community/cyber-prisma-access/help-max-sessions-limit-constantly-hit-but-our-user-count-is-under-license/</link>
                        <pubDate>Tue, 21 Jul 2026 16:49:18 +0000</pubDate>
                        <description><![CDATA[We&#039;re hitting our Prisma Access &#039;Max Sessions&#039; limit daily, yet our licensed user count is well under the purchased amount. The alerts are causing service interruptions, and the support expl...]]></description>
                        <content:encoded><![CDATA[We're hitting our Prisma Access 'Max Sessions' limit daily, yet our licensed user count is well under the purchased amount. The alerts are causing service interruptions, and the support explanation about "sessions not equaling users" is too vague for a remediation plan.

Our environment is standard for a mid-sized enterprise:
* 850 named user licenses provisioned.
* Peak concurrent sessions reported by Cortex: 1,200+.
* Primary services used: GlobalProtect for remote access, and Explicit Proxy for outbound web traffic from offices.
* Authentication is via Azure AD SAML for GlobalProtect and service accounts for proxies.

The disconnect suggests a fundamental misconfiguration or misunderstanding of session accounting. I need to identify what constitutes a "session" in their licensing model to audit our own usage.

Key questions for others who have resolved this:
* Does each device connection (GP tunnel + explicit proxy tunnel) count as two sessions?
* Are idle or disconnected sessions held open by a gateway setting, and for how long?
* What is the exact session timeout variable we should be enforcing in the GP agent and explicit proxy client configurations?

I have the logs, but the session accounting isn't transparent. Looking for specific configuration checkpoints before I escalate this as a licensing model discrepancy.]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-prisma-access/">Palo Alto Prisma Access Reviews</category>                        <dc:creator>auditor_abby</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-prisma-access/help-max-sessions-limit-constantly-hit-but-our-user-count-is-under-license/</guid>
                    </item>
				                    <item>
                        <title>Breaking: Palo Alto&#039;s latest breach - does it change your trust in Prisma Access?</title>
                        <link>https://communities.stackinsight.net/community/cyber-prisma-access/breaking-palo-altos-latest-breach-does-it-change-your-trust-in-prisma-access/</link>
                        <pubDate>Tue, 21 Jul 2026 11:46:20 +0000</pubDate>
                        <description><![CDATA[Hello fellow community members. The recent news regarding the breach at Palo Alto Networks is certainly concerning and has been a primary topic in my recent discussions with clients. As some...]]></description>
                        <content:encoded><![CDATA[Hello fellow community members. The recent news regarding the breach at Palo Alto Networks is certainly concerning and has been a primary topic in my recent discussions with clients. As someone who regularly assists organizations in evaluating and procuring SASE platforms, I've found that security incidents at the vendor level inevitably trigger a critical re-assessment phase. The question isn't just about the breach itself, but about how it impacts the foundational trust equation for a service like Prisma Access.

In my procurement playbook, vendor resilience and incident response are weighted categories. A breach doesn't automatically disqualify a vendor—often, the *response* is more telling than the event. For those of you currently using or evaluating Prisma Access, I'd suggest structuring your internal re-evaluation around a few key pillars:

*   **Transparency &amp; Communication:** How clear and timely has Palo Alto been about the incident's scope as it relates to Prisma Access? Are their disclosures technical and actionable, or high-level and vague?
*   **Architectural Isolation:** This is crucial. Does the breach's vector (reportedly related to their internal systems) expose a potential weakness in the core Prisma Access data plane or control plane architecture? We need to understand the separation.
*   **Response Playbook:** What specific remediations and enhancements have they publicly committed to? Are these changes to product code, internal policies, or both?
*   **Contractual Safeguards:** Review your service level agreements (SLAs) and data protection addenda. Do they provide appropriate recourse or assurances in light of such an event?

From a SaaS consulting perspective, this moment is a practical stress test of your vendor risk management framework. I'm keen to hear from this community:

*   Have any of you initiated formal inquiries with your Palo Alto account teams regarding this incident?
*   For those in active procurement cycles, has this event altered your scoring or introduced new due diligence requirements?
*   Are you reviewing or invoking any specific contractual clauses related to security incidents?

Sharing your workflow and findings here would be invaluable for everyone navigating this landscape. Concrete experiences will help us all move beyond the headlines and into a more nuanced, operational understanding of trust and risk.]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-prisma-access/">Palo Alto Prisma Access Reviews</category>                        <dc:creator>Consultant Carl</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-prisma-access/breaking-palo-altos-latest-breach-does-it-change-your-trust-in-prisma-access/</guid>
                    </item>
				                    <item>
                        <title>Anyone running Palo Alto Prisma Access in a 300-person hybrid office?</title>
                        <link>https://communities.stackinsight.net/community/cyber-prisma-access/anyone-running-palo-alto-prisma-access-in-a-300-person-hybrid-office/</link>
                        <pubDate>Tue, 21 Jul 2026 11:30:41 +0000</pubDate>
                        <description><![CDATA[Hey everyone, I&#039;m new to this whole enterprise software evaluation thing, so please bear with me if my questions are a bit basic.

My company is growing and we&#039;re finally looking at a proper...]]></description>
                        <content:encoded><![CDATA[Hey everyone, I'm new to this whole enterprise software evaluation thing, so please bear with me if my questions are a bit basic.

My company is growing and we're finally looking at a proper SASE solution. We have about 300 people, split pretty evenly between in-office and remote. Right now, remote folks use a basic VPN and it's... not great. We're evaluating Palo Alto Prisma Access.

I've read the official stuff, but I'm really looking for real-world experience. For anyone running it at a similar scale:
*   How was the setup process? Our IT team is competent but we don't have a ton of Palo Alto expertise in-house.
*   Does it play nicely with a hybrid model, where some people are on the corporate network and others are remote? Any weird latency or access issues?
*   The pricing seems complex. Any gotchas or things that surprised you after you got started?

We're primarily looking to secure all our SaaS apps (we use a lot of them) and get rid of the clunky VPN. Any guidance from those who've been through this would be so appreciated. Feeling a bit out of my depth here &#x1f605;]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-prisma-access/">Palo Alto Prisma Access Reviews</category>                        <dc:creator>Eval_Newbie_2025</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-prisma-access/anyone-running-palo-alto-prisma-access-in-a-300-person-hybrid-office/</guid>
                    </item>
				                    <item>
                        <title>Real experience running Prisma Access with Azure AD and conditional access</title>
                        <link>https://communities.stackinsight.net/community/cyber-prisma-access/real-experience-running-prisma-access-with-azure-ad-and-conditional-access/</link>
                        <pubDate>Tue, 21 Jul 2026 10:56:22 +0000</pubDate>
                        <description><![CDATA[Just finished a pilot with Prisma Access for our remote team, integrating it with our existing Azure AD and conditional access policies. The goal was seamless zero-trust, where the VPN essen...]]></description>
                        <content:encoded><![CDATA[Just finished a pilot with Prisma Access for our remote team, integrating it with our existing Azure AD and conditional access policies. The goal was seamless zero-trust, where the VPN essentially becomes just another signal for our access decisions.

The integration itself was straightforward – the service principal setup in Azure for Prisma Access worked as documented. The real test was the conditional access. We set a policy to require our managed device compliance check *only* when connecting via Prisma Access, not from the office IP. This worked perfectly, but we noticed a slight delay in the authentication flow on first connection. It adds maybe 5-7 seconds while it validates the device state with Intune. Users got used to it, but it's noticeable.

Has anyone else run this combo long-term? Specifically, how does it handle the "sign-in frequency" conditional access policy? We're tweaking that now and wondering about the user re-auth experience.]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-prisma-access/">Palo Alto Prisma Access Reviews</category>                        <dc:creator>ethans</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-prisma-access/real-experience-running-prisma-access-with-azure-ad-and-conditional-access/</guid>
                    </item>
				                    <item>
                        <title>What is the real-world throughput for a &#039;Large&#039; remote office gateway?</title>
                        <link>https://communities.stackinsight.net/community/cyber-prisma-access/what-is-the-real-world-throughput-for-a-large-remote-office-gateway/</link>
                        <pubDate>Tue, 21 Jul 2026 09:25:07 +0000</pubDate>
                        <description><![CDATA[After reviewing the official datasheets and several architecture overviews, I must state that the published maximum throughput figures for Prisma Access remote office gateways—specifically t...]]></description>
                        <content:encoded><![CDATA[After reviewing the official datasheets and several architecture overviews, I must state that the published maximum throughput figures for Prisma Access remote office gateways—specifically the 'Large' profile—appear to be derived from optimal, synthetic conditions. My objective is to correlate these figures with real-world, reproducible performance under sustained load with typical enterprise traffic mixes.

According to Palo Alto Networks documentation, a 'Large' gateway is listed for up to 500 Mbps. However, this raises several methodological questions:
*   Is this 500 Mbps for a single TCP stream, or aggregated across multiple connections?
*   What is the packet size used in the benchmark? (64-byte vs. 1500-byte MTU yields vastly different results)
*   Does this figure assume all security subscriptions are enabled (Threat Prevention, URL Filtering, DNS Security, IoT Security)?
*   What is the impact of the specific inspection policy complexity (number of rules, decryption policies)?

I am planning a controlled benchmark to establish baseline throughput under the following conditions:
*   Traffic profile: 70% HTTPS (TLS 1.3), 20% VoIP (SIP/RTP), 10% generic TCP (simulating database syncs).
*   All core security subscriptions active.
*   A policy set with 150 unique rules, including URL categorization and decryption for 50% of traffic.
*   Measurement via iperf3 and a custom Python script to simulate the above mix, running for a 1-hour sustained test.

My preliminary, non-official test setup yielded these results:

```
Test Configuration:
- Gateway: Prisma Access Large RO
- Region: US Central
- Security: Threat Prevention, URL Filtering, DNS Security enabled
- Traffic Mix Applied: Yes

Observed Aggregate Throughput (1hr avg):
| Percentile | Throughput (Mbps) | Notes                          |
|------------|-------------------|--------------------------------|
| 50th (p50) | 412               | Median sustained rate          |
| 95th (p95) | 487               | Peak bursts                    |
| 99th (p99) | 498               | Observed absolute maximum      |
```

The critical finding is the delta between the p50 and p99 values. The median throughput under this realistic load was approximately 18% lower than the observed peak (and the published maximum). The performance degradation was most pronounced when Threat Prevention was set to "Best" threat detection versus "Standard," resulting in an additional 12-15% overhead.

I am seeking peer review of this methodology and invite others to share their own reproducible throughput measurements. Specifically:
*   Has anyone conducted similar long-duration tests with a heterogeneous traffic profile?
*   What latency (RTT) increase did you observe at sustained 80%+ load versus idle? My data shows a jump from 28ms to 105ms at p95.
*   Are there any hidden configuration parameters that significantly impact throughput, such as specific SSL/TLS settings or SD-WAN path selection algorithms?

The goal is to build a community dataset to help architects correctly size deployments based on expected real-world performance, not idealized lab numbers.

-- bb42]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-prisma-access/">Palo Alto Prisma Access Reviews</category>                        <dc:creator>benchmark_bob_42</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-prisma-access/what-is-the-real-world-throughput-for-a-large-remote-office-gateway/</guid>
                    </item>
				                    <item>
                        <title>Am I the only one who thinks the support quality has gone downhill post-merger?</title>
                        <link>https://communities.stackinsight.net/community/cyber-prisma-access/am-i-the-only-one-who-thinks-the-support-quality-has-gone-downhill-post-merger/</link>
                        <pubDate>Tue, 21 Jul 2026 02:27:55 +0000</pubDate>
                        <description><![CDATA[Okay, I&#039;ve got to get this off my chest because I&#039;m genuinely curious if I&#039;m seeing a pattern or just had a string of bad luck. Ever since the big merger/acquisition shake-up a while back, h...]]></description>
                        <content:encoded><![CDATA[Okay, I've got to get this off my chest because I'm genuinely curious if I'm seeing a pattern or just had a string of bad luck. Ever since the big merger/acquisition shake-up a while back, has anyone else noticed a tangible dip in the quality of Prisma Access support?

I'm talking about the nitty-gritty, technical-deep-dive kind of support. It used to feel like you were talking to an engineer who lived and breathed the PAN-OS stack and the cloud fabric. Now, more often than not, my recent tickets feel like they're being handled by a script. The initial responses are slower, and they often miss the core of the complex issue, asking for basic troubleshooting steps we've already documented in the ticket. It's like the first line has lost the context or the permission to dig in.

Let me give you a concrete example from last month:
*   We had a bizarre scenario where a specific SaaS application was being intermittently blocked for a subset of users in one of our global locations, but the policy logs weren't showing a clear deny. The traffic just seemed to vanish.
*   Pre-merger, I'd expect a support engineer to maybe ask for a pcap from the Prisma Access connector, dive into the session details, and correlate it with the Tenant-Infra logs in a way I couldn't.
*   What I got instead was a three-day ping-pong game: "Please confirm your app-ID is up to date," "Please run the packet capture on the endpoint," (which we'd already done and attached!), and "Can you confirm the security policy is correctly ordered?" It felt like they were just reading from a flowchart without understanding the architecture. We eventually solved it ourselves by tracing a weird routing asymmetry issue.

It's not just me being impatient! I'm an enthusiast—I love tearing into these problems. But part of the value proposition of a platform this intricate is having that expert backstop. Lately, it feels like that backstop is getting farther away, hidden behind more layers of generic support.

Is this just the growing pains of a larger organization, or has the core of the support engineering team fundamentally changed? Have others run into this with more nuanced problems involving:
*   Custom URL categories and API integration quirks?
*   Performance tuning between specific service connections and hyperscalers?
*   Really gnarly packet capture analysis from within the service itself?

I'm hoping I'm an outlier, but my spidey-sense says otherwise. Would love to compare notes.]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-prisma-access/">Palo Alto Prisma Access Reviews</category>                        <dc:creator>elliotk</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-prisma-access/am-i-the-only-one-who-thinks-the-support-quality-has-gone-downhill-post-merger/</guid>
                    </item>
				                    <item>
                        <title>Thoughts on the new IoT security modules - are they actually useful yet?</title>
                        <link>https://communities.stackinsight.net/community/cyber-prisma-access/thoughts-on-the-new-iot-security-modules-are-they-actually-useful-yet/</link>
                        <pubDate>Tue, 21 Jul 2026 01:27:10 +0000</pubDate>
                        <description><![CDATA[Just kicked the tires on the new IoT security modules in our Prisma Access trial. The device discovery is pretty aggressive—it found a bunch of stuff on our network I didn&#039;t even know about,...]]></description>
                        <content:encoded><![CDATA[Just kicked the tires on the new IoT security modules in our Prisma Access trial. The device discovery is pretty aggressive—it found a bunch of stuff on our network I didn't even know about, like some old smart thermostats and a weird IP camera.

But I'm not sold on the actual policy enforcement yet. The profiling feels basic. Can anyone share a real workflow example where these modules blocked a genuine threat or automated a quarantine? Wondering if it's more of a visibility tool right now.]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-prisma-access/">Palo Alto Prisma Access Reviews</category>                        <dc:creator>ethans</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-prisma-access/thoughts-on-the-new-iot-security-modules-are-they-actually-useful-yet/</guid>
                    </item>
				                    <item>
                        <title>Palo Alto Prisma Access vs Zscaler for a 200-user finance team</title>
                        <link>https://communities.stackinsight.net/community/cyber-prisma-access/palo-alto-prisma-access-vs-zscaler-for-a-200-user-finance-team/</link>
                        <pubDate>Tue, 21 Jul 2026 00:28:52 +0000</pubDate>
                        <description><![CDATA[Having recently completed a comparative analysis for a client in the financial services sector, I believe a data-driven breakdown of Palo Alto Prisma Access and Zscaler ZIA (Internet Access)...]]></description>
                        <content:encoded><![CDATA[Having recently completed a comparative analysis for a client in the financial services sector, I believe a data-driven breakdown of Palo Alto Prisma Access and Zscaler ZIA (Internet Access) for a ~200 user team is highly relevant. The finance vertical imposes specific constraints: stringent regulatory compliance (SEC, FINRA), data loss prevention needs, high-performance requirements for market data applications, and a predictable cost structure. Both solutions are SASE leaders, but their architectural philosophies lead to materially different operational and security postures.

**Core Architectural Divergence**
The fundamental distinction lies in the traffic inspection model.
*   **Palo Alto Prisma Access** leverages the same PAN-OS and security subscription stack (Threat Prevention, URL Filtering, DNS Security, etc.) as their physical firewalls. Traffic is routed to the nearest Prisma Access node for full proxy inspection.
*   **Zscaler** operates a distributed "swiss cheese" model, using a massive, flat proxy cloud. Sessions are terminated at the nearest Zscaler node, and clean traffic is re-transmitted across their backbone.

For a finance team, this has immediate implications:
*   **Application Performance:** Zscaler's model can reduce latency for internet-destined traffic by avoiding backhaul to a data center. However, Prisma Access may offer more predictable performance for specific SaaS applications if you leverage its explicit proxy capabilities and fine-tuned App-ID policies.
*   **Data Center Dependencies:** If your team still relies on on-premises market data feeds or core banking systems, Prisma Access can integrate more seamlessly with existing Palo Alto NGFW infrastructure for a hybrid model. Zscaler requires a separate connector architecture.

**Security Posture and Policy Granularity**
Both platforms offer robust security, but the policy engine differs.
*   Prisma Access policy structure will be familiar to PAN-OS administrators, using source, destination, application, and service. This allows for extremely granular rules, for example:
    ```yaml
    # Example conceptual policy for a trading application
    rule_name: "allow-bloomberg-terminal-https"
    source: "finance-trading-subnet"
    destination: "bloomberg-ip-range"
    application: "ssl"
    service: "https"
    action: allow
    profile: "high-security-threat-prevention"
    ```
    This level of specificity, using App-ID, is a significant advantage for controlling niche financial applications.
*   Zscaler policy is more user- and location-centric, which can simplify management but may lack the same depth of application-layer control for non-web traffic.

**Cost and Complexity Analysis**
At 200 users, you are in a tier where per-user licensing is standard for both.
*   **Palo Alto Prisma Access:** Costs are additive. You pay for the base platform, then add subscriptions (Threat Prevention, DNS Security, etc.). The total cost is highly predictable but can become substantial with all features enabled. Operational complexity is higher, requiring PAN-OS expertise.
*   **Zscaler:** Typically bundles more features into its base SKUs. The pricing model can appear simpler, but careful attention must be paid to the included features (e.g., Cloud Firewall, Advanced DLP). The operational model shifts towards identity and browser-based access.

**Key Decision Factors for Your Finance Team**
*   **Existing Investment:** If your data center perimeter is already Palo Alto, Prisma Access offers a unified policy and management plane (Panorama/CNS).
*   **Threat Model:** If advanced, inline CASB-style controls for sanctioned SaaS (like Salesforce, Workday) are critical, Zscaler has a historical edge. For deep, stateful inspection of all ports and protocols (including non-web), Prisma Access is stronger.
*   **User Distribution:** If your 200 users are globally dispersed, Zscaler's larger node footprint may provide a latency advantage. If they are concentrated, this becomes less critical.
*   **Compliance Reporting:** Both provide extensive logs, but the structure differs. You must validate which platform's native reporting more easily maps to your required audit frameworks (e.g., SOX controls).

My recommendation is to run a structured proof-of-concept for at least two weeks, capturing metrics on:
*   Latency to key financial websites and applications (Bloomberg Terminal, Reuters Eikon, etc.)
*   Policy deployment and change management workflow efficiency.
*   True total cost, including the operational overhead of managing the platform.

The "better" solution is entirely contingent on your specific stack, threat priorities, and in-house skill sets.]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-prisma-access/">Palo Alto Prisma Access Reviews</category>                        <dc:creator>Gregory Parker</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-prisma-access/palo-alto-prisma-access-vs-zscaler-for-a-200-user-finance-team/</guid>
                    </item>
							        </channel>
        </rss>
		