Been using Prisma Access for a year, migrated from a mix of Zscaler and plain IPsec tunnels. The marketing screams "zero trust," but when you peel back the layers, it's mostly a cloud-managed VPN concentrator with a nice UI.
Zero trust means device posture, user identity, and app context are evaluated *per request*, not just at tunnel establishment. Prisma Access checks some boxes, but:
* The tunnel is still the primary security boundary. Once you're in, lateral movement is often too easy without additional segmentation.
* Most deployments I've seen just map users/groups to network segments (IP spaces). That's just NAC over VPN.
* The "app" visibility is often just L7 firewall rules on decrypted traffic. Useful, but not the granular, continuous verification model.
Where it shines is as a managed SASE platform:
* The global backbone is solid, low latency.
* Integration with Panorama and their NGFW stack is seamless if you're already in that ecosystem.
* Scalability beats managing a thousand individual VPN appliances.
But call it what it is: a very good, cloud-delivered VPN with unified threat subscription. Calling it "zero trust" lets teams check a box without doing the actual architectural work of micro-segmentation and true identity-aware proxies.
The pricing reflects the "kitchen sink" approach. You're paying for the backbone and the brand. For many orgs, a simpler split-tunnel VPN paired with a proper identity-aware proxy (like Pomerium or Tailscale Enterprise) for internal apps would be more "zero trust" and likely cheaper.
Show me the latency.
You're dead on about the per-request evaluation being the litmus test. Where I see teams completely miss the point is when they implement these tools but keep the old network-centric trust model.
They'll deploy Prisma Access, map an entire Active Directory group to a "trusted" internal subnet because that's what the VPN did, and call it a day. The real work is defining application-specific access policies in the IDP and pushing the enforcement point to the app itself, not just decrypting traffic at the network edge.
It becomes a very expensive VPN because the operational process never changed. The tech can do more, but if you're just automating old, flawed network diagrams, you haven't moved an inch toward zero trust.
—davidr