Provider evidence
Palo Alto Networks Prisma SASE
Palo Alto Networks isn’t just selling SASE, it’s selling one door into a much larger security estate (NGFWs, Prisma Cloud, Cortex XDR/XSIAM, identity security) that most large enterprises already have some footprint in. That shows up directly in its differentiators: it’s one of the few vendors recognised as a Leader in all three of Gartner’s Single-Vendor SASE, SSE and SD-WAN Magic Quadrants simultaneously, and its ‘platformisation’ commercial strategy rewards multi-product commitment with steep discounts.
Technology vendor · UK entity not yet reviewed
Evidence profile: Retail and e-commerce; Manufacturing; platform
Colgate primary case explicitly identifies Prisma SD-WAN and Prisma Access at a manufacturer. Bimbo corroborates manufacturing security, not a separate logistics sector. Westfield primary case documents Prisma SASE for mall operations and retail access. Evidence relates to a mall operator, not every retail format. Grupo Bimbo is a bakery manufacturer. Its connected supply chain does not make it an independent transport/logistics customer. This is sector experience only; scope, UK delivery and suitability for the buyer require separate confirmation.
- https://paloaltonetworks.com/customers/colgate-palmolive-powers-secure-manufacturing-with-palo-alto-networks
- https://paloaltonetworks.com/customers/grupo-bimbo-protects-its-global-connected-supply-chain-with-palo-alto-networks
- https://paloaltonetworks.com/customers/westfield-responds-rapidly-to-a-changing-market-with-prisma-sase
Research only
https://www.paloaltonetworks.com/saseThese capabilities use the same evidence as the provider shortlist and matching. A missing finding is not evidence that a provider lacks the capability.
Capability evidence
| Capability | Finding | Evidence and qualification |
|---|---|---|
| Fully managed service | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| DIY / self-managed model | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Co-managed service | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Multi-tenant MSP / white-label support | Partial | MSPs can securely delegate responsibilities while ensuring only authorized users can read or modify critical security configurations. Hierarchical multitenancy and granular role-based delegated administration are evidenced on the Managed SASE page (source 6) and the 2022 MSP press release (source 14), which describes a cloud-based management portal with hierarchical multitenancy using granular role-based access control. Graded partial rather than yes because no evidence of branded or white-label portals and service templates carrying the MSP's own brand was found on the pages reviewed; the Prisma SASE for MSPs datasheet (source 18) is gated and returned no usable text. Source · Evidence dated 2026-07-29 |
| Professional services and migration support | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Last-mile circuit management | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Lifecycle management | Partial | Palo Alto Networks manages sizing, content versioning, monitoring, upgrades, and security subscriptions. For the cloud service and for SASE Private Location, Palo Alto Networks handles sizing, content versioning, upgrades and security subscriptions as part of the service. Graded partial because hardware replacement and RMA, ION appliance firmware handling, renewals and end-of-life planning were not evidenced: the Support Policies page (source 19) is a link index that returned no substantive text, and no RMA or end-of-life policy document was read in this task. Source · Evidence dated 2026-07-29 |
| Flexible commercial model | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Encrypted overlay fabric | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Dynamic path selection | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Active-active link utilisation | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Application-aware routing | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| QoS and traffic shaping | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Packet loss remediation | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Local internet breakout | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| MPLS coexistence and migration | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Cellular and 5G support | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Cloud on-ramp | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Public cloud gateways | Yes | With Prisma Access, Palo Alto Networks deploys and manages the security infrastructure globally to secure your remote networks and mobile users. The PoPs are Palo Alto Networks' own service, sold under its own brand and covered by its own SLA, so this is yes rather than partner_integrated. Recorded for transparency: the compute those PoPs run on is rented from GCP and AWS (source 11), which is a hosting arrangement rather than reselling another vendor's SASE gateway service. Source · Evidence dated 2026-07-29 |
| Private PoPs / dedicated PoPs | Yes | SASE Private Location enables you to deploy Prisma Access services within your own infrastructure. SASE Private Location is a customer-hosted deployment of Prisma Access services on the customer's own hypervisor and ISP links, with Palo Alto Networks retaining backend management. Corroborated by the sovereignty blog (source 12), which states that for organisations with the most stringent data residency requirements Palo Alto offers SASE Private Location. Colo-Connect (source 9) is a different thing: private connectivity into the shared cloud, not a dedicated PoP. Source · Evidence dated 2026-07-29 |
| Private global backbone | Partner / integrated | Prisma SASE leverages the infrastructure of major hyperscale providers such as Google Cloud Platform (GCP) and Amazon Web Services (AWS). Inter-region transport rides the backbones of Google Cloud and AWS rather than a network owned or controlled by Palo Alto Networks. The same post adds that Prisma SASE benefits from private peering connections between tier 1 cloud providers and other public cloud platforms, SaaS networks and ISPs, which again describes third-party peering. Colo-Connect (source 9) uses GCP interconnect technology, reinforcing the same conclusion. No evidence of Palo Alto-owned fibre, wavelengths or core routing was found. Source · Evidence dated 2026-07-29 |
| Regional breakout and data residency | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Multi-cloud transit fabric | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Flexible edge form factors | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| High availability design | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| SLA-backed service fabric | Yes | If, during any calendar month, the Service availability falls below 99.999%, Customer can submit a claim for credit The published SLA is contractual with service credits and covers three separate measures: service availability at 99.999%, a Monthly Security Processing Latency Percentage at 99.99% and a Monthly SaaS Application Latency Percentage at 99.99%, with credits scaling to 100% where availability falls below 98%. That goes beyond best-effort targets. Support response times and change handling commitments were not evidenced in the SLA text reviewed. Source · Evidence dated 2026-07-29 |
| Integrated next-generation firewall | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Full SASE platform | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| SSE ecosystem integration | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Zero Trust Network Access | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Secure web gateway | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| CASB capability | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Data loss prevention | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Remote user access | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| SOC/SIEM/SOAR integration | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Centralised orchestration | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Customer portal and RBAC | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Observability and digital experience monitoring | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| APIs and automation | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Managed service assurance | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |