Prisma AIRS AI Agent Security
What happens when hundreds of AI agents gain access to your tools and data with no way to track them? This solution brief on Prisma AIRS AI Agent Security shows how you can secure both SaaS and custom-built agents across their lifecycle. Download the brief to see how centralized visibility, least-privilege access, and real-time threat prevention keep agents productive without introducing new risk.
What problem does Prisma AIRS AI Agent Security actually solve?
As AI agents and MCP-based workflows spread across your organization, they behave a bit like new employees with broad access and no oversight. Traditional security tools weren’t designed for this pattern and leave two big gaps:
- Agent monitoring: Agents are embedded in SaaS apps, low-code tools, and custom builds, often running as “black boxes.” Security teams can’t easily see how inputs are processed, which APIs are called, or what data is touched.
- Lifecycle risk: Each agent introduces new identities, permissions, and runtime behaviors that can be overpermissive and unpredictable. Existing tools typically don’t understand prompts, tool calls, or MCP workflows.
Prisma AIRS AI Agent Security is designed specifically for this new layer:
- Universal visibility: Centralized visibility into all AI agents – SaaS copilots, low-code agents, and custom-built agents – from one place.
- Enterprise-wide enforcement: A single platform to apply consistent policies across your AI ecosystem, instead of one-off controls per app or team.
- End-to-end protection: Coverage from initial configuration and permissions through to runtime operation and monitoring.
- AI-specific threat prevention: Built-in defenses against prompt injection, memory manipulation, tool misuse, context poisoning, malicious URLs, and credential leakage. The platform protects against over 31 prompt injection techniques, as well as topic abuse, harmful content, and web/DNS-based attacks.
- Granular data control: Fine-grained control over what data an agent can access, use, and share, plus full audit trails for compliance and forensics.
In short, Prisma AIRS helps you rethink how you secure AI agents by adding a dedicated, AI-aware security layer that your existing network, identity, and app security tools don’t provide.
How does Prisma AIRS secure SaaS copilots and MCP-based agents in practice?
Prisma AIRS AI Agent Security brings multiple components together so you can secure both the agents you consume and the ones you build.
1. SaaS AI Agents (e.g., Microsoft Copilot)
SaaS copilots are attractive because they’re preintegrated with tools like Microsoft 365, Teams, and Dynamics, but they typically run as opaque services inside the SaaS provider’s environment.
Prisma AIRS closes this gap by:
- Enforcing least-privileged access to data and apps.
- Continuously monitoring agent activity for risky permissions, privilege escalations, and data leaks.
- Blocking suspicious behavior in real time, such as attempts to access sensitive SharePoint content or leak Teams conversations.
- Logging every action for compliance, traceability, and forensic analysis.
This lets you benefit from SaaS copilots’ productivity gains without accepting opaque security and compliance risk.
2. MCP Relay for Runtime Control
For MCP-based systems, Prisma AIRS introduces an MCP Relay that sits between MCP clients and servers as a mandatory gateway:
- Acts as a centralized proxy for all MCP workflows.
- Calls the Prisma AIRS Runtime API on every interaction to apply advanced security checks.
- Detects and blocks malicious instructions, poisoned tool descriptions, and exposed credentials before they affect workflows.
- Inspects every tool invocation so that context poisoning and credential leakage are consistently caught.
3. Managed MCP Server for On-Demand Protection
The Managed MCP Server adds a hosted runtime enforcement layer that works with any MCP-compatible agent:
- Provides on-demand, developer-friendly protection without new infrastructure.
- Inspects prompts, tool calls, and model responses in real time.
- Blocks key threats, including:
- Prompt injection that tries to alter agent behavior.
- Context poisoning via manipulated tool metadata.
- Malicious URLs and data exfiltration.
- Privilege escalation attempts against underlying systems.
Together, the MCP Relay and Managed MCP Server provide end-to-end runtime protection, giving you a unified, managed security foundation for MCP-based AI ecosystems.
How does Prisma AIRS fit into our broader AI and cloud strategy?
Prisma AIRS is designed to reimagine AI agent security as a horizontal layer that follows your agents wherever they run, instead of being tied to a single app or infrastructure stack.
Broad deployment coverage
The platform supports a wide range of environments:
- SaaS and third-party agents: Secures agents embedded in SaaS apps (e.g., Salesforce, Microsoft) where you don’t control the underlying infrastructure. Prisma AIRS integrates at the agent and workflow level to monitor and protect activity.
- Low-code / no-code platforms: Extends security policies to agents built in tools like Microsoft Power Apps and Google AppSheet, helping ensure nontechnical users can’t deploy insecure agents that bypass traditional controls.
- Custom-built and internal agents: Provides consistent security and governance for agents running on-premises, in private clouds, or in public clouds such as AWS, Azure, and Google Cloud.
This gives you the horizontal coverage needed to manage the growing number of agents across both structured IT environments and more decentralized, user-driven deployments.
Unified security posture for build vs. buy
- For agents you consume: SaaS AI Agent Security enforces least-privileged access, data boundaries, and audit controls for embedded copilots. At runtime, the MCP Relay inspects API and tool calls to block privilege escalation and data exfiltration.
- For agents you build: The Managed MCP Server integrates directly into developer workflows so you can “shift left” on security. It validates code and tool calls on demand, while the MCP Relay acts as a universal checkpoint for all agent traffic.
Flexible consumption model
Prisma AIRS is also designed to fit into existing Palo Alto Networks investments:
- You can use or acquire Flexible Software NGFW (FW-Flex) credits to deploy Prisma AIRS AI Runtime Security instances from Strata Cloud Manager.
- Developers can create a deployment profile for FW-Flex credits, generate an API key in Strata Cloud Manager, and then call Prisma AIRS programmatically from application code.
This combination of deployment flexibility and unified policy control helps you secure AI agents consistently, without forcing changes to your cloud providers, SaaS choices, or development stack.

