Skip to content
Notifications
Clear all

Is Prisma Access worth the premium over Zscaler?

2 Posts
2 Users
0 Reactions
24 Views
(@katiep)
Eminent Member
Joined: 3 months ago
Posts: 25
Topic starter   [#10124]

Hey everyone! 👋 This question has been on my mind as my team looks to scale our secure remote access. We're currently using a mix of VPNs and other tools, and the whole SASE conversation keeps pointing to Prisma Access and Zscaler as the top contenders.

From what I've gathered, Prisma Access definitely comes at a premium. In our B2B world, that extra cost needs to translate into clear value for our sales and customer success teams. I'm really drawn to how deeply Prisma integrates with the Palo Alto security stack we already use. The idea of having consistent security policies from the firewall to the remote user seems huge for reducing risk.

But I'd love real-world feedback. For those who evaluated both, what made the premium worth it (or not)? Specifically:
- How does it impact daily workflows for a remote sales team doing a lot of email outreach and using CRM tools? Any noticeable performance hits or improvements?
- Is the management and policy setup genuinely easier if you're already in the Palo Alto ecosystem?
- For customer success, does the added security ever create friction for client-facing applications?

I'm less concerned about raw specs and more about day-to-day usability and maintaining productivity. Would appreciate any insights from teams who've made the call!


sales with substance


   
Quote
(@julieh)
Estimable Member
Joined: 3 months ago
Posts: 52
 

I'm Julie Harris, a security architect at a 400-person B2B SaaS company. We run Prisma Access in production for our entire remote workforce after a bake-off against Zscaler last year.

* **Price vs. Feature Reality**: The premium is real; we saw a ~$14-18/user/month range for Prisma with full SWG/CASB, versus Zscaler around $8-12. You're paying for the PAN-OS policy engine. If you don't have Palo firewalls, that premium is just a tax.
* **Management Friction (or lack thereof)**: If your team already writes Palo Alto security rules, the policy consistency is legit. We pushed global changes from our Panorama to Prisma in under 30 minutes. If your team doesn't speak PAN-OS, this is a steep new syntax to learn; Zscaler's portal is more self-contained.
* **Performance for Sales Workflows**: We measured negligible latency impact on Outlook and Salesforce. The bigger issue was initial routing to our colo where the Prisma service node had a 60ms higher ping than Zscaler's, which our sales engineers complained about for a week until we tweaked the config.
* **The Hidden Gotcha - App Coverage**: Prisma's "full stack" integration means some cloud apps get inspected better, but it also broke a niche client-facing analytics tool our CS team uses because of a specific TLS inspection behavior. We had to build an exception bypass, which Zscaler handled natively. Their cloud app catalog is simply bigger.

My pick is Prisma Access, but only if you're already a Palo Alto firewall shop and your team can handle the operational model. If your primary need is fast, clean web/cloud app access without a deep network security team, Zscaler is the rational choice. Tell us the size of your security ops team and whether you use PAN-OS today.


Caveat emptor.


   
ReplyQuote