5.1 Strata Cloud Manager (SCM) Architecture and Cloud-Delivered Management

Key Takeaways

  • Strata Cloud Manager (SCM) serves as Palo Alto Networks' unified, cloud-delivered management plane, providing single-pane-of-glass administrative control across physical PA-Series NGFWs, virtualized VM-Series, containerized CN-Series, cloud-native Cloud NGFW (AWS/Azure/GCP), and Prisma Access SSE/SASE infrastructure.
  • Unlike traditional on-premises or cloud-hosted Panorama appliances that rely on device group/template hierarchies and discrete software update cycles, SCM delivers a continuous, cloud-native microservices architecture with automated tenant onboarding, multi-tenant isolation, and zero-touch deployment.
  • Onboarding firewalls into SCM relies on secure outbound TLS connections (port 443) using device certificates, Device Telemetry, and Cloud Services connections without requiring open inbound management ports.
  • SCM unifies network security configuration and operational management across hybrid and multi-cloud environments, eliminating management silos between enterprise network firewalls and cloud instances.
  • Migration from legacy Panorama to SCM is supported by automated migration utilities that convert Device Groups and Templates into SCM Folder hierarchies and cloud-delivered snippets while preserving policy intent.
Last updated: July 2026

5.1 Strata Cloud Manager (SCM) Architecture and Cloud-Delivered Management

Key Concept: Strata Cloud Manager (SCM) is Palo Alto Networks' flagship cloud-delivered management and operations platform. It unifies network security management across physical hardware (PA-Series), virtual appliances (VM-Series), containerized firewalls (CN-Series), cloud-native firewall services (Cloud NGFW for AWS, Azure, and GCP), and Secure Access Service Edge (Prisma Access) under a single cloud-native console.

Modern enterprise security architectures spans traditional on-premises datacenters, remote branch offices, public multi-cloud environments, and hybrid workforce endpoints. Historically, managing these disparate security enforcement points required distinct management consoles or complex multi-tier Panorama deployments. Strata Cloud Manager (SCM) eliminates these management silos by delivering a unified, highly scalable, cloud-native control plane that manages both infrastructure configuration and operational AI/ML insights from a single interface.


Architectural Foundations: SCM vs. Traditional Panorama

To understand SCM, network security engineers must contrast its architecture with legacy management paradigms like Panorama. While Panorama relies on appliance-based software (deployed on M-Series hardware appliances or virtual machines in ESXi, KVM, AWS, or Azure), SCM is built as an elastic, cloud-native software-as-a-service (SaaS) platform hosted in Palo Alto Networks Cloud Services infrastructure.

+-------------------------------------------------------------------------+
|                    STRATA CLOUD MANAGER ARCHITECTURE                    |
+-------------------------------------------------------------------------+
|                      UNIFIED CLOUD CONTROL PLANE                        |
|       (Microservices Architecture / Continuous SaaS Updates)            |
+------------------------------------+------------------------------------+|
|                                    |                                    |
|    MANAGEMENT & CONFIGURATION      |       AI-DRIVEN OPERATIONS         |
|  - Folder Hierarchy & Snippets     |  - AIOps Telemetry Processing      |
|  - Unified Policy Push Mechanics   |  - Best Practice Auditing (BPA)    |
|  - Zero-Touch Provisioning (ZTP)   |  - Anomaly & Capacity Analytics    |
+------------------------------------+------------------------------------+|
                                     |
    +--------------------------------+--------------------------------+
    |               |                |               |                |
+---+---+       +---+---+        +---+---+       +---+---+        +---+---+
|  PA-  |       |  VM-  |        |  CN-  |       | Cloud |        |Prisma |
|Series |       |Series |        |Series |       | NGFW  |        | Access|
| (HW)  |       | (VM)  |        |(K8s)  |       |(AWS/  |        |(SASE) |
|       |       |       |        |       |       |Azure) |        |       |
+-------+       +-------+        +-------+       +-------+        +-------+

The architectural shifts between Panorama and Strata Cloud Manager are detailed below:

Architectural AttributeTraditional Panorama DeploymentStrata Cloud Manager (SCM)
Deployment ModelCustomer-managed appliance (M-Series hardware or VM hypervisor instance).Cloud-delivered SaaS microservices running in Palo Alto Networks Cloud Services.
Software MaintenanceManual PAN-OS upgrades, hotfixes, hypervisor resource management, and HA pairing.Managed automatically by Palo Alto Networks with zero operational maintenance downtime.
Scalability & CapacityLimited by appliance memory, storage, and Log Collector (LC) group sizing.Elastic, cloud-native scaling capable of managing tens of thousands of global firewalls seamlessly.
Configuration ModelHierarchical Device Groups and Template Stacks.Object-oriented Folder Hierarchies, Snippets, and Rulestacks.
Logging & Data RetentionLocal Log Collectors, NFS mounts, or dedicated Panorama M-Series storage.Integrated with Cortex Data Lake (CDL) for hyper-scalable cloud log storage.
Managed TargetsPA-Series, VM-Series, CN-Series, and Prisma Access (via plugin).PA-Series, VM-Series, CN-Series, Cloud NGFW (AWS/Azure/GCP), and Prisma Access natively.
AIOps & AnalyticsRequires separate AIOps app installation or external telemetry forwarding.Natively integrated inline AIOps for proactive health monitoring and best-practice audits.

Managed Targets & Hybrid Ecosystem Integration

SCM acts as the single administrative authority across the entire Palo Alto Networks Zero Trust architecture:

  1. PA-Series Hardware Firewalls: On-premises physical appliances deployed across datacenters, campuses, and branch locations (from PA-400 Series up to PA-7000 Series) connect securely to SCM for centralized security policy, networking, and device management.
  2. VM-Series & CN-Series Virtual Firewalls: Virtual firewalls deployed across private cloud hypervisors (VMware ESXi, Nutanix AHV, KVM) and public cloud compute infrastructure (AWS EC2, Azure VMs, GCP Compute Engine), as well as containerized CN-Series firewalls on Kubernetes and Red Hat OpenShift, inherit baseline security policies directly from SCM folders.
  3. Cloud NGFW: Fully managed, cloud-native firewall-as-a-service instances integrated directly into cloud provider control planes (AWS VPC Router, Azure Virtual WAN, GCP Cloud Router) are administered via SCM, maintaining policy parity between public cloud workloads and physical datacenters.
  4. Prisma Access: Palo Alto Networks' cloud-delivered SASE solution shares SCM's management plane. Security administrators write a single policy rule that applies simultaneously to remote mobile users connected to Prisma Access, branch offices connected via Prisma SD-WAN, and core datacenters protected by PA-Series firewalls.

Tenant Architecture, Multi-Tenancy, and Onboarding Workflows

SCM is built upon a multi-tenant cloud architecture that isolates customer data while allowing flexible administrative structures for enterprise organizations and Managed Security Service Providers (MSSPs).

Tenant Structure & Tenant Service Groups (TSGs)

In SCM, an organization's cloud presence is anchored by a Tenant Service Group (TSG). A TSG represents an enterprise identity container in the Palo Alto Networks Cloud Hub. Within a TSG, administrators configure Role-Based Access Control (RBAC), integrate enterprise Identity Providers (IdPs) via SAML 2.0 or OpenID Connect (OIDC) such as Microsoft Entra ID or Okta, and segment administrative access using sub-tenants or folder scopes.

Device Onboarding Mechanics

Connecting a firewall—whether a physical PA-Series or virtual VM-Series—to Strata Cloud Manager requires a secure, outbound-initiated control plane connection. The onboarding workflow follows four distinct phases:

+--------------------+      +--------------------+      +--------------------+
|   1. REGISTRATION   |      |   2. TELEMETRY     |      |  3. CLOUD CONTROL  |
| Customer Support   | ---> | Device Telemetry   | ---> | Outbound TLS 443   |
| Portal (CSP) / TSG |      | Service Activated  |      | Handshake to SCM   |
+--------------------+      +--------------------+      +--------------------+
                                                                  |
                                                                  v
                                                        +--------------------+
                                                        |  4. SYNC & MANAGED |
                                                        | Active Management  |
                                                        | State Established  |
                                                        +--------------------+
  1. Licensing & Registration: The firewall serial number is registered to the organization's Customer Support Portal (CSP) account and linked to the designated Tenant Service Group (TSG).
  2. Device Telemetry Activation: On PAN-OS (version 10.2, 11.0, 11.1, or later), administrators enable the Device Telemetry service and install the Cloud Services Plugin / SCM connection agent.
  3. Outbound Control Connection: The firewall initiates a secure, encrypted outbound TLS connection over TCP port 443 to SCM cloud endpoints (*.paloaltonetworks.com). The connection uses mutual TLS (mTLS) authentication anchored by the firewall's Device Certificate (X.509) or Cloud Onboarding Token. No inbound firewall management ports need to be opened to the internet.
  4. Device Management State: Once authenticated, SCM registers the device into its device inventory. The firewall receives its folder assignment, downloads initial candidate configurations, and establishes real-time telemetry streaming to Cortex Data Lake.

Zero-Touch Provisioning (ZTP)

For enterprise branch deployments (such as PA-400 Series appliances), SCM supports Zero-Touch Provisioning (ZTP). Unconfigured branch firewalls ship directly to remote sites. When plugged into power and internet, the firewall contacts the Palo Alto Networks ZTP Cloud Service, retrieves its tenant association, registers with SCM, downloads its assigned SCM Branch folder policy, and begins enforcing security rules within minutes without requiring onsite IT personnel.


Panorama to SCM Migration Strategy

Organizations transitioning from Panorama to SCM utilize the automated Panorama to SCM Migration Tool. This utility parses Panorama XML configuration files, analyzes existing Device Group and Template Stack hierarchies, and maps them to SCM constructs:

  • Device Groups are converted into SCM Folders and Rulestacks.
  • Templates & Template Stacks are converted into SCM Device Profiles and cloud-delivered Snippets.
  • Shared objects (Address Groups, Service Objects, Custom App-IDs) are deduplicated and placed into the SCM All (root) folder for global reuse.
Loading diagram...
Strata Cloud Manager Cloud-Delivered Management Architecture
Test Your Knowledge

Which statement correctly describes the architectural difference between Strata Cloud Manager (SCM) and traditional Panorama?

A
B
C
D
Test Your Knowledge

When onboarding a PA-Series hardware firewall to Strata Cloud Manager, which connection mechanism is required?

A
B
C
D
Test Your Knowledge

Which managed enforcement targets can be administered from a single Strata Cloud Manager tenant console?

A
B
C
D