NNetifyVersion 1010261227

Provider evidence

Palo Alto Networks Prisma SASE

Palo Alto Networks isn’t just selling SASE, it’s selling one door into a much larger security estate (NGFWs, Prisma Cloud, Cortex XDR/XSIAM, identity security) that most large enterprises already have some footprint in. That shows up directly in its differentiators: it’s one of the few vendors recognised as a Leader in all three of Gartner’s Single-Vendor SASE, SSE and SD-WAN Magic Quadrants simultaneously, and its ‘platformisation’ commercial strategy rewards multi-product commitment with steep discounts.

Technology vendor · UK entity not yet reviewed

Evidence profile: Retail and e-commerce; Manufacturing; platform

    Colgate primary case explicitly identifies Prisma SD-WAN and Prisma Access at a manufacturer. Bimbo corroborates manufacturing security, not a separate logistics sector. Westfield primary case documents Prisma SASE for mall operations and retail access. Evidence relates to a mall operator, not every retail format. Grupo Bimbo is a bakery manufacturer. Its connected supply chain does not make it an independent transport/logistics customer. This is sector experience only; scope, UK delivery and suitability for the buyer require separate confirmation.

    Research only

    https://www.paloaltonetworks.com/sase

    These capabilities use the same evidence as the provider shortlist and matching. A missing finding is not evidence that a provider lacks the capability.

    Capability evidence

    CapabilityFindingEvidence and qualification
    Fully managed serviceNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    DIY / self-managed modelYesSee the published provider record for source context; confirm the scope for your deployment.
    Co-managed serviceNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Multi-tenant MSP / white-label supportPartial

    MSPs can securely delegate responsibilities while ensuring only authorized users can read or modify critical security configurations. Hierarchical multitenancy and granular role-based delegated administration are evidenced on the Managed SASE page (source 6) and the 2022 MSP press release (source 14), which describes a cloud-based management portal with hierarchical multitenancy using granular role-based access control. Graded partial rather than yes because no evidence of branded or white-label portals and service templates carrying the MSP's own brand was found on the pages reviewed; the Prisma SASE for MSPs datasheet (source 18) is gated and returned no usable text.

    Source · Evidence dated 2026-07-29
    Professional services and migration supportNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Last-mile circuit managementNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Lifecycle managementPartial

    Palo Alto Networks manages sizing, content versioning, monitoring, upgrades, and security subscriptions. For the cloud service and for SASE Private Location, Palo Alto Networks handles sizing, content versioning, upgrades and security subscriptions as part of the service. Graded partial because hardware replacement and RMA, ION appliance firmware handling, renewals and end-of-life planning were not evidenced: the Support Policies page (source 19) is a link index that returned no substantive text, and no RMA or end-of-life policy document was read in this task.

    Source · Evidence dated 2026-07-29
    Flexible commercial modelNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Encrypted overlay fabricYesSee the published provider record for source context; confirm the scope for your deployment.
    Dynamic path selectionYesSee the published provider record for source context; confirm the scope for your deployment.
    Active-active link utilisationNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Application-aware routingYesSee the published provider record for source context; confirm the scope for your deployment.
    QoS and traffic shapingYesSee the published provider record for source context; confirm the scope for your deployment.
    Packet loss remediationNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Local internet breakoutYesSee the published provider record for source context; confirm the scope for your deployment.
    MPLS coexistence and migrationNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Cellular and 5G supportYesSee the published provider record for source context; confirm the scope for your deployment.
    Cloud on-rampYesSee the published provider record for source context; confirm the scope for your deployment.
    Public cloud gatewaysYes

    With Prisma Access, Palo Alto Networks deploys and manages the security infrastructure globally to secure your remote networks and mobile users. The PoPs are Palo Alto Networks' own service, sold under its own brand and covered by its own SLA, so this is yes rather than partner_integrated. Recorded for transparency: the compute those PoPs run on is rented from GCP and AWS (source 11), which is a hosting arrangement rather than reselling another vendor's SASE gateway service.

    Source · Evidence dated 2026-07-29
    Private PoPs / dedicated PoPsYes

    SASE Private Location enables you to deploy Prisma Access services within your own infrastructure. SASE Private Location is a customer-hosted deployment of Prisma Access services on the customer's own hypervisor and ISP links, with Palo Alto Networks retaining backend management. Corroborated by the sovereignty blog (source 12), which states that for organisations with the most stringent data residency requirements Palo Alto offers SASE Private Location. Colo-Connect (source 9) is a different thing: private connectivity into the shared cloud, not a dedicated PoP.

    Source · Evidence dated 2026-07-29
    Private global backbonePartner / integrated

    Prisma SASE leverages the infrastructure of major hyperscale providers such as Google Cloud Platform (GCP) and Amazon Web Services (AWS). Inter-region transport rides the backbones of Google Cloud and AWS rather than a network owned or controlled by Palo Alto Networks. The same post adds that Prisma SASE benefits from private peering connections between tier 1 cloud providers and other public cloud platforms, SaaS networks and ISPs, which again describes third-party peering. Colo-Connect (source 9) uses GCP interconnect technology, reinforcing the same conclusion. No evidence of Palo Alto-owned fibre, wavelengths or core routing was found.

    Source · Evidence dated 2026-07-29
    Regional breakout and data residencyNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Multi-cloud transit fabricYesSee the published provider record for source context; confirm the scope for your deployment.
    Flexible edge form factorsNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    High availability designNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    SLA-backed service fabricYes

    If, during any calendar month, the Service availability falls below 99.999%, Customer can submit a claim for credit The published SLA is contractual with service credits and covers three separate measures: service availability at 99.999%, a Monthly Security Processing Latency Percentage at 99.99% and a Monthly SaaS Application Latency Percentage at 99.99%, with credits scaling to 100% where availability falls below 98%. That goes beyond best-effort targets. Support response times and change handling commitments were not evidenced in the SLA text reviewed.

    Source · Evidence dated 2026-07-29
    Integrated next-generation firewallYesSee the published provider record for source context; confirm the scope for your deployment.
    Full SASE platformYesSee the published provider record for source context; confirm the scope for your deployment.
    SSE ecosystem integrationNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Zero Trust Network AccessYesSee the published provider record for source context; confirm the scope for your deployment.
    Secure web gatewayYesSee the published provider record for source context; confirm the scope for your deployment.
    CASB capabilityYesSee the published provider record for source context; confirm the scope for your deployment.
    Data loss preventionYesSee the published provider record for source context; confirm the scope for your deployment.
    Remote user accessYesSee the published provider record for source context; confirm the scope for your deployment.
    SOC/SIEM/SOAR integrationYesSee the published provider record for source context; confirm the scope for your deployment.
    Centralised orchestrationNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Customer portal and RBACNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Observability and digital experience monitoringYesSee the published provider record for source context; confirm the scope for your deployment.
    APIs and automationNot confirmedSee the published provider record for source context; confirm the scope for your deployment.
    Managed service assuranceNot confirmedSee the published provider record for source context; confirm the scope for your deployment.