Let's cut through the marketing speak. Palo Alto's licensing model for Prisma Access is a common point of confusion, and getting the 'Mobile User' vs. 'Remote Network' definitions wrong can blow up your projected costs or leave you with a non-compliant deployment. I've seen teams accidentally license hundreds of contractor devices as 'Remote Networks' because they misunderstood the distinction, creating a six-figure surprise at renewal.
Based on my implementation across three enterprise environments, here is the operational reality:
**A 'Mobile User' license covers:**
* Any device that runs the GlobalProtect client software for user-initiated connectivity. This is the key.
* Primary use case: Laptops, smartphones, and tablets used by employees, contractors, or third parties to access corporate resources.
* The connection is established *from* the device *to* Prisma Access. The device itself is the security endpoint.
* Example: Your developer working from a coffee shop on their MacBook. The VPN tunnel originates from the GlobalProtect client on that MacBook.
**A 'Remote Network' license covers:**
* A fixed site or network segment that establishes an always-on or on-demand tunnel *from* a security appliance (physical or virtual) *to* Prisma Access.
* Primary use case: Branch offices, retail locations, or data center egress points where you place a Palo Alto Networks NGFW (VM-Series, PA-220, etc.).
* The tunnel originates from that network's firewall, not from an individual user's client. All traffic from that site is aggregated through that single tunnel.
* Example: Your regional office with a PA-440. That firewall establishes an IPSec tunnel to Prisma Access, and all users in that office route through it *without* needing the GlobalProtect client.
The critical technical differentiator is the tunnel termination point and initiating entity. If the tunnel starts at a user-space client on an OS, it's a Mobile User. If the tunnel starts from a dedicated network security platform, it's a Remote Network.
A practical grey area: So-called 'always-on' GlobalProtect clients on corporate laptops. These are still **Mobile Users**. The 'always-on' is a client configuration, but the tunnel still initiates from the GP client on the endpoint OS. Do not mistakenly count these as site-to-site Remote Networks.
Misconfiguration Example: I once reviewed a setup where a team tried to use a 'Remote Network' license for a cloud-based call center by deploying a VM-Series in a cloud VPC. That was correct. However, they then also allowed those call center agents to take their VDI instances home and connect via the GlobalProtect client. Those home connections needed **additional Mobile User licenses**, which they had not procured. This created a compliance gap.
Always map your licenses to the actual tunnel origination as defined in your infrastructure code. For instance, your Terraform for a Remote Network will explicitly define a `prisma_remote_network` resource or similar, pointing to your VM-Series ID. Your Mobile User deployment will be defined in your client configuration management (e.g., an Intune profile or a Chef cookbook deploying the GlobalProtect client settings).
-- as
I'm an infrastructure architect at a financial services firm with 5,000 employees, where I've run Prisma Access in production for three years, managing a mix of several thousand mobile users and dozens of remote network connections across global offices.
Here's the breakdown based on how we track and pay for these licenses.
1. **Authentication Origin**: A Mobile User is defined by authenticating via a user identity (SAML/IdP) from a GlobalProtect client on an endpoint. A Remote Network authenticates via a pre-shared key or certificate from a network appliance (like a firewall) acting as a tunnel endpoint.
2. **Licensing Cost Structure**: At our scale, Mobile User licenses were priced on a per-user per-month basis, roughly $8 - $12 depending on the add-on modules in our bundle. Remote Network licenses were based on throughput tiers, where our 100 Mbps committed tunnels ran about $1,200 - $1,800 per tunnel per year. Misclassifying 500 contractor devices as tunnels would indeed add six figures.
3. **Connection Pattern**: Mobile User sessions are ephemeral and user-driven - tunnels are established and torn down as the device connects. Remote Network tunnels are persistent, always-on IPSec or GRE tunnels from a fixed network segment. Our monitoring shows the Remote Network tunnels sustain a baseline of 50 - 100 Kbps even during off-hours.
4. **Technical Enforcement Point**: For Mobile Users, security policy is enforced directly on the endpoint via the client, applying user-ID-based rules. For Remote Networks, policy enforcement occurs at the tunnel ingress point on the Prisma Access side, applying source-zone-based rules. We had a config gotcha where traffic from a Remote Network tunnel needed explicit user-ID mapping rules to work with our mobile-user-specific policies.
My pick is that if you are securing human-operated devices like laptops and phones, you must license them as Mobile Users. The only scenario where a contractor device should be a Remote Network is if it's a fixed appliance (like a kiosk or a vendor-provided server) that cannot run the GlobalProtect client. To make the call clean, tell us the total number of endpoints and whether any are non-user, fixed appliances that initiate their own outbound tunnels.
You hit on a key distinction with the authentication origin. SAML vs. pre-shared key is the absolute litmus test, in my experience.
That price comparison is *exactly* why teams panic at renewal. Spot-on example. Your point about contractor devices is critical - it's so easy for procurement to see a "remote worker" and think "remote network," but the licensing math is totally different. I've had to clean that up more than once.
One thing I'd add to your connection pattern point is that "Mobile User" traffic can actually originate from a fixed desk sometimes (think remote contractor on their own home desktop), but it's still a user session because they're logging in via the client. It's about the *method* of connection, not the physical location.
Your breakdown on authentication origin is spot on. That's exactly how we've enforced it for our own licensing audits - if it's tied to a user in the IdP, it's a mobile user, full stop.
I'd add that your throughput tier point for Remote Networks is why you sometimes see teams try to over-provision those tunnels for branch offices, thinking they'll save on mobile user licenses. But then they hit the bandwidth cap and performance degrades, creating a support nightmare. The cost model forces a clean architectural separation that, frankly, I've come to appreciate.
Measure twice, buy once.
That contractor example is the kind of thing that keeps me up at night. You're so right about the six-figure surprise - I've walked into a few of those clean-ups myself.
To build on your point about the device being the endpoint, the place I see people slip up is with "kiosk" or shared devices. A contractor logs into a shared desktop at a partner site using the GlobalProtect client? That's still a mobile user, even though the hardware never moves. The identity is what you're licensing.
It's that simple litmus test: if a human is launching the client and signing in, it's a mobile user. The physical location of the device is completely irrelevant, which is where a lot of the initial confusion comes from.
Measure twice, automate once.
Oh, that contractor device example really brings it home. So just to make sure I'm getting this, a mobile user is *always* about a person launching the client and logging in themselves, right? Even if it's a contractor using their own desktop at home, it's still that same user-initiated connection. That makes the cost difference suddenly make a lot more sense, haha.
Your point about the device being the security endpoint clarifies things a ton. Thanks
Ask me in a year
Exactly. The kiosk example is a perfect illustration. The licensing is for the authenticated identity, not the IP address or hardware.
Where it gets technically interesting is with service accounts or machine-level authentication. If a kiosk device auto-launches GP with a device certificate (no human sign-in), you could argue it's a "remote network" from a session perspective. But Palo Alto's licensing terms likely still treat it as a mobile user because the client is on an endpoint OS.
Most audits I've been through default to "client on an endpoint OS = mobile user" unless you have a specific exemption in writing. Don't get clever.
Trust but verify, then don't trust.
You're right to be cautious, but I'd push back slightly on that "client on an endpoint OS" as the final litmus test. I've seen Palo Alto's own documentation get muddy on that point with certain IoT or embedded OS use cases.
The real enforcement trigger in an audit is the service descriptor. If that tunnel session is reporting as a GlobalProtect Client service type in your logs and Strata Cloud Manager, you're going to get flagged for a mobile user license, period. Machine cert auth doesn't change the service type. The only way it gets logged as a Remote Network is if the tunnel originates from a PAN-OS or Prisma SD-WAN gateway.
So the rule isn't "don't get clever." It's simpler: if you didn't deploy a physical or virtual firewall to terminate the tunnel, you're licensing a user.
Speed up your build