Sales Plays
Better Together
Bundles
Cross-platform sales plays that combine multiple PAN products for maximum customer value and competitive displacement.
10 Combined Plays
Cross-Platform Sales Plays
Each bundle combines products that are stronger together — solving customer problems that no single product addresses alone.
Problem
Legacy VPN creates performance bottlenecks, backhauling traffic to data centers. No ZTNA 2.0 continuous inspection. Unmanaged/BYOD devices lack security controls at the browser layer.
Why Better Together
Same GP agent transitions to Prisma Access 6.2 cloud delivery — no new client software, and GlobalProtect is not retired (this is a migration to the Prisma Access Agent, not an EOL). Prisma Browser extends protection to unmanaged/BYOD devices. Only enterprise browser natively integrated with SASE — and, as of PAN-OS 12.2, identified natively by the NGFW.
Value
Displaces
Ideal Customer
Problem
Aging PA-Series approaching end of support — PA-7000 Series went end-of-sale Dec 31, 2025, PA-5450 goes end-of-sale Nov 22, 2026, and the K2-Series reached end-of-life Feb 28, 2026. Panorama on-prem hardware is expensive to maintain. No AI-driven posture assessment. No unified visibility across firewalls + SASE + SD-WAN.
Why Better Together
New hardware on PAN-OS 12.2 "Ceres" provides quantum readiness (Quantum-Safe Security GA Jan 30, 2026; PQC now extends to GlobalProtect). SCM replaces Panorama with cloud-native management + Strata Copilot AI assistant and six AI Network Security Agents. SCM shipped Panorama-migration tooling mid-2026. SCM has exactly two tiers — Essentials (free) and Pro (paid) — and SCM Pro is bundled into the ESA via a single auth code.
Value
Displaces
Ideal Customer
Problem
XDR provides endpoint detection but SOC still manages separate SIEM and SOAR. Alert fatigue from multiple consoles. Legacy SIEM (Splunk) is expensive at scale.
Why Better Together
XSIAM 3.6 is a superset of XDR 5.2 — existing agents and data upgrade directly. No new agent deployment. Adds SIEM + SOAR, with ASM, Exposure Management and ITDR 2.0 available as modules. XSIAM Professional Assistant maps Splunk rules automatically. Tiers are NG-SIEM, Enterprise and Premium (Enterprise Plus is retired).
Value
Displaces
Ideal Customer
Problem
EDR protects the OS but has limited visibility into in-browser activity. 70–80% of credential theft begins in browser sessions. Phishing attacks increasingly happen entirely in-browser with no file download (no EDR signal).
Why Better Together
XDR secures the OS layer; Prisma Browser secures the browser layer. This is now a shipping product integration, not a roadmap story: Prisma Browser native integration with Cortex XDR and XSIAM shipped with XDR 5.2 (Jul 20, 2026), so browser telemetry lands in the Cortex data lake and XSIAM correlates endpoint + browser events into unified incidents. PAN-OS 12.2 adds NGFW-native Prisma Browser identification. Covers managed + unmanaged devices, and Agentic Endpoint Security (AES) is integral to the 5.2 agent with zero additional deployment.
Value
Displaces
Ideal Customer
Problem
Network security and SOC operate in silos. SASE detections must be manually exported to SIEM. ADEM user experience data is isolated from security investigations.
Why Better Together
Prisma SASE natively sends telemetry to the Cortex XDL 2.0 data lake (15+ PB/day across 1,100+ integrations). XSIAM's ML models run across both endpoint AND network telemetry. If XSIAM detects a compromised user, it triggers Prisma Access to revoke the ZTNA session automatically. Enhanced Application Log (EAL) ingestion became free in XSIAM 3.5, cutting Prisma SASE ingestion cost ~10–15%.
Value
Displaces
Ideal Customer
Problem
Security and SRE teams use separate tools (CNAPP vs. Datadog/Dynatrace) for the same cloud environment. Datadog's opaque pricing creates unpredictable costs. High-cardinality AI/ML metrics overwhelm legacy monitoring.
Why Better Together
Chronosphere Telemetry Pipeline routes telemetry to both observability AND security from a single collection layer, and is natively integrated with Cortex XDL 2.0. Security anomalies gain application performance context. 30%+ data volume reduction before XSIAM ingestion. Cortex Cloud 2.2 covers the four current modules — Application Security, Cloud Posture Security, Cloud Runtime Security, Security Operations. Naming discipline: the brand is Chronosphere (acquisition closed Jan 29, 2026, >$300M ARR); there is no product called "Cortex Observability", and the deeper Cortex AgentiX tie-in is not yet GA.
Value
Displaces
Ideal Customer
Problem
Firewall logs are the richest network telemetry but SIEMs receive aggregated data, losing context. Threat hunting requires correlation of firewall + endpoint + identity. SOAR can't trigger firewall changes without custom scripting.
Why Better Together
Strata Logging Service feeds XSIAM natively — full-fidelity firewall logs in real time, no ETL. XSIAM playbooks push dynamic block lists back to the NGFW. Threat detected at endpoint → blocked at firewall within seconds.
Value
Displaces
Ideal Customer
Problem
CISOs managing 15–30 security vendors. Integration overhead consuming 30%+ of security budget. Disparate tools generate siloed data. Board demands proof of consolidated risk posture.
Why Better Together
The only vendor delivering a unified, AI-driven security platform across all seven pillars: Network (PAN-OS 12.2), SASE (Prisma Access 6.2 + Prisma Browser), SOC (XSIAM 3.6), Cloud (Cortex Cloud 2.2), AI Security (Prisma AIRS 3.0), Identity (Idira, formerly CyberArk — acquisition closed Feb 11, 2026, GA May 12, 2026) and Observability (Chronosphere). Single AI platform detects → correlates → responds across every layer in seconds.
Value
Displaces
Ideal Customer
Problem
Organizations deploying AI applications have no inline security for AI-specific threats: prompt injection, data poisoning, sensitive data leakage through LLM APIs. AI agents create new privileged access paths.
Why Better Together
AIRS uses the same PAN-OS infrastructure and the same Software NGFW Credits — a VM-Series can become an AIRS instance via license toggle. Managed from the same SCM console. App-ID/User-ID/Content-ID framework identifies and inspects AI model API calls. Prisma AIRS 3.0 (Mar 23, 2026) spans AI Model Security, AI Runtime Security, AI Agent Security, AI Red Teaming and AI-SPM, with Portkey (closed May 29, 2026) as the AI Gateway. It is also the named replacement for CN-Series, which goes end-of-sale Nov 1, 2026 — AI Runtime Firewall is the successor.
Value
Displaces
Ideal Customer
Problem
Identity-based attacks are the #1 initial access vector. PAM and SIEM operate in silos. Machine identities outnumber humans 80:1 and are largely unmanaged. Zero trust requires real-time enforcement — current PAM is too slow.
Why Better Together
Real-Time Privilege Revocation: XSIAM detects a compromised credential → triggers Idira (formerly CyberArk) to revoke access across all systems. Two pieces of this are now shipping product, not vision: Idira Endpoint Privilege Manager integrates with XSIAM via Cortex Marketplace as of XSIAM 3.5 (May 3, 2026), and ITDR 2.0 landed in XDR 5.2 with Conditional Access Policies for Okta, Entra and on-prem AD, Active Directory Security Posture Management, 17 new detectors and granular RBAC. Attack Stories include full identity context. Portfolio: Idira Privileged Access Manager, Idira Secrets Hub, Certificate Manager, Idira Secure AI Agents — plus Next-Generation Trust Security (Mar 23, 2026) for certificate lifecycle inside SCM.
Value
Displaces
Ideal Customer