What you are evaluating
For a combined public/private evaluation select the Enterprise secure-all-apps edition and required mobile-user scope. Strata Cloud Manager and Panorama management differ; RBI and Secure Agentless Access add-ons must be identified separately.
A useful evaluation context
Consider where existing Palo Alto Networks policy operations or private application requirements make a consistent operating model valuable; verify management and licensing compatibility.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- License editions distinguish secure internet, private application and combined access.
- GlobalProtect supports endpoint-based mobile-user access in the relevant deployment.
- Secure Agentless Access offers supported browser access with version, identity and add-on requirements.
Where it fits in the work
- Confirm the exact edition, management plane and mobile-user allocation.
- Connect a lab private application using the supported connectivity option.
- Apply user/application policy and inspect logs after testing both allowed and denied access.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
A contractor uses a browser to reach a private training application.
Evidence to look for
List the exact service version, identity integration, connection path and optional isolation license before claiming that an unmanaged-device demo represents the purchased service.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- Which policy capabilities disappear if the edition does not support them?
- Which dataplane and service versions are required for agentless access?
- Are private-app connectivity and optional data controls in the proposed design?