Hi everyone. We've been evaluating a full SASE refresh for our retail network (200+ stores, plus HQ/DC). Prisma Access is, of course, at the top of our shortlist given its integration with our existing Panorama setup.
The feature set is a strong match, but I keep circling back to the pricing. The per-location model for retail branches made sense when each store was a distinct tunnel termination with heavy bandwidth needs. But with the shift to direct-to-cloud for most store traffic (SaaS apps, cloud-based POS), the value calculus feels different. We're essentially paying a per-site premium for security we could arguably get from a user-centric model.
My question for the community, especially those in retail or distributed branches: Is the per-location model still a deal-maker/breaker for you? Have you found Palo Alto flexible in structuring deals that account for lighter per-location traffic, or are we better off looking at more user-licensed alternatives? I'm trying to gauge if we should push hard on pricing or if the operational benefits truly justify the model.
Would love to hear your real-world experiences, especially around scaling store counts and how you handle seasonal bandwidth spikes (like holiday sales) without breaking the bank.
Per-location is absolutely a deal-breaker in your scenario. The value prop collapsed when the traffic did.
>direct-to-cloud for most store traffic
You nailed it. You're paying the premium for a tunnel you're barely using. The "operational benefits" of Panorama integration are real, but you can get SD-WAN and basic security from cheaper vendors, then layer on a user-based ZTNA for the critical stuff.
They'll flex on price if you push, but the model itself is the problem. You're subsidizing their old architecture. For 200+ sites, that's a massive tax for diminishing returns.
Trust but verify.