Skip to content
Is Palo Alto Prisma...
 
Notifications
Clear all

Is Palo Alto Prisma Access too expensive for a 200-user mid-market?

4 Posts
4 Users
0 Reactions
27 Views
(@crusty_pipeline)
Honorable Member
Joined: 5 months ago
Posts: 502
Topic starter   [#8791]

Let's cut through the marketing slides first: Prisma Access isn't a ZTNA product, it's a full-blown SASE platform that *includes* ZTNA capabilities. You're not buying a scalpel; you're buying the entire operating theater and a team of nurses. For a 200-user mid-market company, that's often massive overkill, and your CFO is going to have a stroke when the quote lands.

The sticker shock isn't just about user licenses. The real cost sinks are in the add-ons and the data processing. They'll get you on:
* **Threat Prevention** and **DNS Security** add-ons (which you'll almost certainly need, because why else buy Palo Alto?)
* **Data Loss Prevention** (DLP) modules, priced by data volume scanned.
* Egress data fees if you're routing all your internet-bound traffic through their backbone (which is the default model).

I've seen the quotes. You're likely looking at a per-user, per-month cost that starts with a number higher than your average SaaS application, and that's before you commit to the 1, 3, or 5-year term for a "discount."

The architectural question you should be asking isn't just about cost, but about fit. Do you actually need:
* A full cloud firewall for all internet traffic?
* SD-WAN lite capabilities for your branch offices?
* The complexity of their policy layers (Network Security, App-ID, User-ID) for a 200-person shop?

If your primary need is replacing a clunky VPN for remote access to specific internal apps (the classic ZTNA use case), you're paying for a jet engine to power a bicycle. There are simpler, agent-based ZTNA vendors whose entire platform is focused on that secure access piece, and their pricing model reflects that singular focus.

Here's a crude, anonymized snippet from a Terraform config I used to model out a competitor's setup for a similar-sized client. Notice the simplicity of the policy structure compared to the NGFW rulebase you'd be maintaining in Prisma:

```hcl
resource "ztna_application" "finance_app" {
name = "netsuite-prod"
internal_host = "10.10.10.25:8443"
domains = ["netsuite.company.com"]
}

resource "ztna_access_policy" "finance_group" {
application_id = ztna_application.finance_app.id
user_group_id = data.ztna_group.finance_team.id
# No network rules, just user-to-app
}
```

That's the core of ZTNA. Prisma Access does that, but it's buried under a mountain of other network security constructs you may not need.

My blunt advice: before you even take the sales call, document your exact requirements. If it's 90% "secure remote app access," look at pure-play ZTNA. If you're also trying to consolidate branch office security, replace on-prem firewalls, and get advanced threat on all web traffic, then maybe the SASE bundle makes sense. For 200 users, the math rarely works unless you have very deep pockets or are already wedded to the Palo Alto ecosystem.

-- old salt



   
Quote
(@andrewh)
Reputable Member
Joined: 3 months ago
Posts: 363
 

That's a really helpful breakdown, thanks. I hadn't even considered the egress data fees angle.

When you say >the entire operating theater<, that clicks. For a company my size, we're probably just trying to secure a few apps, not rebuild the whole network perimeter in the cloud. It sounds like we'd be paying for a ton of infrastructure we don't actually need.

Is there a simpler ZTNA tool you'd recommend looking at instead, or is that still overkill for basic remote access?



   
ReplyQuote
(@ci_cd_junkie)
Honorable Member
Joined: 7 months ago
Posts: 476
 

Exactly, and that's the key distinction. You're looking for a scalpel, not an operating theater. For a few apps and basic remote access, a full SASE platform is absolutely overkill.

I've seen teams in your size range get great results with tools like Twingate or Cloudflare Access. They're fundamentally ZTNA-first, so you're not paying for the massive security stack you won't use. They're also often way simpler to deploy, since you can integrate them directly with your identity provider and avoid managing a whole new network perimeter.

Have you looked at what your current IdP (like Okta or Entra ID) offers for app gateways? Sometimes the simplest solution is already in your stack.


pipeline all the things


   
ReplyQuote
(@crm_trailblazer_7)
Honorable Member
Joined: 5 months ago
Posts: 433
 

You're spot on with the "paying for infrastructure we don't need" assessment. That's the core financial misalignment with full SASE for mid-market.

user200's suggestions are solid, but run your own POC. We tested Twingate against a basic access requirement. The Palo Alto quote was 5x higher, and 60% of the line items were for features we had no deployment plan for, like CASB.

Check if your IdP's gateway meets your actual security benchmarks before adding another vendor. Most basic remote access needs are already covered there.


Show me the query.


   
ReplyQuote