* [Blog](https://www.paloaltonetworks.com/blog) * [Palo Alto Networks](https://www.paloaltonetworks.com/blog/corporate/) * [Secure the Cloud](https://www.paloaltonetworks.com/blog/category/secure-the-cloud/) * Secure Cloud Access: Why ... # Secure Cloud Access: Why We Choose Palo Alto Networks [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.paloaltonetworks.com%2Fblog%2F2019%2F06%2Fcloud-secure-cloud-access-why-we-choose-palo-alto-networks%2F) [](https://twitter.com/share?text=Secure+Cloud+Access%3A+Why+We+Choose+Palo+Alto+Networks&url=https%3A%2F%2Fwww.paloaltonetworks.com%2Fblog%2F2019%2F06%2Fcloud-secure-cloud-access-why-we-choose-palo-alto-networks%2F) [](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.paloaltonetworks.com%2Fblog%2F2019%2F06%2Fcloud-secure-cloud-access-why-we-choose-palo-alto-networks%2F&title=Secure+Cloud+Access%3A+Why+We+Choose+Palo+Alto+Networks&summary=&source=) [](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https://www.paloaltonetworks.com/blog/2019/06/cloud-secure-cloud-access-why-we-choose-palo-alto-networks/&ts=markdown) \[\](mailto:?subject=Secure Cloud Access: Why We Choose Palo Alto Networks) Link copied By [Gilbert Martin](https://www.paloaltonetworks.com/blog/author/gilbert-martin/?ts=markdown "Posts by Gilbert Martin") Jun 12, 2019 6 minutes [Secure the Cloud](https://www.paloaltonetworks.com/blog/category/secure-the-cloud/?ts=markdown) [Azure AD](https://www.paloaltonetworks.com/blog/tag/azure-ad/?ts=markdown) [Cloud Security](https://www.paloaltonetworks.com/blog/tag/cloud-security/?ts=markdown) [globalprotect](https://www.paloaltonetworks.com/blog/tag/globalprotect/?ts=markdown) [Panorama](https://www.paloaltonetworks.com/blog/tag/panorama/?ts=markdown) [VM-Series](https://www.paloaltonetworks.com/blog/tag/vm-series/?ts=markdown) This post is also available in: [繁體中文 (Chinese (Traditional))](https://www.paloaltonetworks.com/blog/2019/07/cloud-secure-cloud-access-why-we-choose-palo-alto-networks/?lang=zh-hant "Switch to Chinese (Traditional)(繁體中文)") [Nederlands (Dutch)](https://www.paloaltonetworks.com/blog/2019/07/cloud-secure-cloud-access-why-we-choose-palo-alto-networks/?lang=nl "Switch to Dutch(Nederlands)") [Français (French)](https://www.paloaltonetworks.com/blog/2019/07/cloud-secure-cloud-access-why-we-choose-palo-alto-networks/?lang=fr "Switch to French(Français)") [Deutsch (German)](https://www.paloaltonetworks.com/blog/2019/07/cloud-secure-cloud-access-why-we-choose-palo-alto-networks/?lang=de "Switch to German(Deutsch)") [Italiano (Italian)](https://www.paloaltonetworks.com/blog/2019/07/cloud-secure-cloud-access-why-we-choose-palo-alto-networks/?lang=it "Switch to Italian(Italiano)") [日本語 (Japanese)](https://www.paloaltonetworks.com/blog/2019/07/cloud-secure-cloud-access-why-we-choose-palo-alto-networks/?lang=ja "Switch to Japanese(日本語)") [한국어 (Korean)](https://www.paloaltonetworks.com/blog/2019/07/cloud-secure-cloud-access-why-we-choose-palo-alto-networks/?lang=ko "Switch to Korean(한국어)") [Español (Spanish)](https://www.paloaltonetworks.com/blog/2019/07/cloud-secure-cloud-access-why-we-choose-palo-alto-networks/?lang=es "Switch to Spanish(Español)") *Low TCO. Faster Time to Resolution. Immediate Security Value. Check!* [Apttus](https://apttus.com/) was born in the cloud. We provide AI-driven SaaS offerings to our customers, including Quote-to-Cash, Contract Management, Digital Commerce and Supplier Relationship Management solutions. Our "all in" cloud approach has helped us better serve our more than 700 customers around the globe. Some organizations still have a difficult time understanding how to run modern cloud infrastructure. So, understandably, they take the crawl before you walk, walk before you run approach. This looks something like: Take a lift-and-shift approach and migrate applications "as is" to the public cloud infrastructure (IaaS); optimize key components of the migrated application to leverage the managed services (PaaS) on offer in the public cloud; et al. We chose to bypass the first two stages and run headfirst into cloud, taking advantage of the benefits provided by Azure, primarily, and AWS. We can do more with less, taking advantage of these platform-as-a-service (PaaS) options. But we needed a way to ensure secure access to our cloud infrastructure and applications for our global operations. **What Business and Security Issues Were We Looking to Solve?** In a nutshell, we needed fast, reliable and secure access to our cloud infrastructure driving our business and services, and we needed to ensure that we could quickly debug and resolve customer issues. Before we deployed Palo Alto Networks VM-Series Virtualized Next-Generation Firewalls, we faced two key security challenges. *++Lack of centralized cloud access management++* We create pods -- essentially a collection of cloud resources needed to create a service and run our solutions. With each pod, we spin up a virtual machine (VM), which acts as jump host and gives operations teams access to the pod. Today, we have over 100 pods, and each pod access is time and resource intensive. The existing access management model does not provide visibility or control and remains a resource hog. A significant amount of time is wasted, and in business, time wasted is money lost. *++Slow, insecure and hair-pinned cloud access model++* We enforce centralized VPN usage for accessing cloud resources. Our users and employees would go through our corporate office to allow them to connect with single sign on (SSO). Then, they would connect from the corporate office to the data center. Given our team is global, with users and branches in India and several other countries, this introduced latency and slow connectivity into the system. As such, we couldn't effectively troubleshoot, and it became increasingly difficult to run the business. **Palo Alto Networks VM-Series: A Decentralized Access Gateway to Cloud Resources** The old way of doing things simply wasn't working. So, we spearheaded an initiative to develop an architecture where operations teams weren't required to route through the corporate office as well as eliminate the need for a jump host in every pod. At the heart of this new security design sat Palo Alto Networks VM-Series. We deployed the [GlobalProtect](https://www.paloaltonetworks.com/sase/access?ts=markdown) subscription on our [VM-Series Virtualized Next-Generation Firewalls](https://www.paloaltonetworks.com/prisma/environments?ts=markdown) to act as the access gateway, and we're using [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown) as the centralized security manager. Because the VM-Series connects directly into Azure AD for central user termination, we are now able to manage access and use a single identity source. Further, we gain granular visibility, control and the ability to segment and isolate pods from each other. **Who Cares? Let's Talk Outcomes** Since deploying Palo Alto Networks VM-Series in the cloud, we've seen significant savings in the amount of time required to pinpoint customer issues and resolve them. But that's not all; check out the summary of cost savings and ROI below: [](https://www.paloaltonetworks.com/blog/wp-content/uploads/2019/06/Screen-Shot-2019-06-11-at-10.39.21-AM.png?ts=markdown) [![](https://www.paloaltonetworks.com/blog/wp-content/uploads/2019/06/Screen-Shot-2019-06-11-at-10.39.21-AM.png)](https://www.paloaltonetworks.com/blog/wp-content/uploads/2019/06/Screen-Shot-2019-06-11-at-10.39.21-AM.png?ts=markdown) Obviously, there are several cloud firewalls available in the market. We chose Palo Alto Networks for ++3 distinct reasons++: 1. \*\*Palo Alto Networks VM-Series has native integration with Azure AD.\*\*The integration with Azure AD in the cloud was crucial for Apttus. We're able to centralize control of all user on/off boarding with Azure AD SSO, including activity and audit trails. 2. **The ability to manage the firewalls centrally through Panorama was hugely beneficial.** Managing all firewalls is essential to keep configuration state and all firewall software up to date. The VM-Series also integrated with our SIEM system for additional security monitoring. 3. **The VM-Series is deployable through infrastructure as code (IaC).** Our cloud infrastructure deployment is done as "infrastructure as code." We're able to programmatically decouple and deploy the VM-Series, along with the rest of the infrastructure components, in the cloud within minutes. It establishes an idempotent practice across all our regions. **If Nothing Else, Remember These 3 Key Things** As I mentioned earlier, we dove headfirst into the cloud running our apps on cloud-based modern infrastructure. And we rely on Palo Alto Networks to enable us to quickly and securely drive our business forward. As you think about your security and business evolution, I want to leave you with a few key thoughts and recommendations: 1. **With security, separate operations from IT:** If you don't, you're likely to sacrifice on the agility gains that the cloud affords. It's not necessary to go through the same paper processes on both sides of the fence. This is especially true for large organizations where it could take weeks, or even months, to fully cross the t's and dot the i's. 2. **You can scale security in cloud.** I implore you, you don't need as many access points (or Bat-Signals as I like to refer to them) to get into your system quickly and securely. Take advantage of cloud-native services like Azure AD -- it was built to scale. You can easily authenticate your users within the cloud -- no connection back to on-prem required. 3. **Choose security offerings that can be managed as IaC.** We've had great success with Palo Alto Networks using infrastructure as code. We achieve high levels of security, low latency and improved time to resolution for customer support. But you don't have to take my word, you can take a test drive in your own environment. [**Sign up on the Azure Marketplace.**](https://azuremarketplace.microsoft.com/en/marketplace/apps/paloaltonetworks.vmseries-ngfw?tab=Overview) *** ** * ** *** ## Related Blogs ### [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [Secure the Cloud](https://www.paloaltonetworks.com/blog/category/secure-the-cloud/?ts=markdown) [#### Destination Cloud: Start Secure, Stay Secure With the Latest VM-Series Enhancements](https://www.paloaltonetworks.com/blog/2019/02/destination-cloud-start-secure-stay-secure-latest-vm-series-enhancements/) ### [Cloud Computing](https://www.paloaltonetworks.com/blog/category/cloud-computing-2/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [Secure the Cloud](https://www.paloaltonetworks.com/blog/category/secure-the-cloud/?ts=markdown) [#### Microsoft Ignite: Showcasing Our Cloud Offerings and the Depth of Our Microsoft Partnership](https://www.paloaltonetworks.com/blog/2018/09/microsoft-ignite-showcasing-cloud-offerings-depth-microsoft-partnership/) ### [Cloud Computing](https://www.paloaltonetworks.com/blog/category/cloud-computing-2/?ts=markdown), [Events](https://www.paloaltonetworks.com/blog/category/events/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [Secure the Cloud](https://www.paloaltonetworks.com/blog/category/secure-the-cloud/?ts=markdown) [#### Visit Us at VMworld 2018 USA](https://www.paloaltonetworks.com/blog/2018/08/visit-us-vmworld-2018-usa/) ### [Cloud Computing](https://www.paloaltonetworks.com/blog/category/cloud-computing-2/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [Secure the Cloud](https://www.paloaltonetworks.com/blog/category/secure-the-cloud/?ts=markdown) [#### Understanding the Differences Between Azure Firewall and the VM-Series](https://www.paloaltonetworks.com/blog/2018/08/cloud-understanding-differences-azure-firewall-vm-series/) ### [Next-Generation Firewalls](https://www.paloaltonetworks.com/blog/network-security/category/next-generation-firewalls/?ts=markdown), [Uncategorized](https://www.paloaltonetworks.com/blog/category/uncategorized/?ts=markdown) [#### VM-Series Virtual Firewalls Top SecureIQLab Cloud Firewall Test](https://www.paloaltonetworks.com/blog/network-security/secureiqlab-report-adv-cloud-firewall-vmseries/) ### [DevSecOps](https://www.paloaltonetworks.com/blog/cloud-security/category/devsecops/?ts=markdown), [Secure the Cloud](https://www.paloaltonetworks.com/blog/category/secure-the-cloud/?ts=markdown) [#### Achieving Comprehensive Cloud Security: The Power of Consolidation](https://www.paloaltonetworks.com/blog/cloud-security/cloud-security-consolidation/) ### Subscribe to the Blog! Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more. ![spinner](https://www.paloaltonetworks.com/blog/wp-content/themes/panwblog2023/dist/images/ajax-loader.gif) Sign up Please enter a valid email. By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) and acknowledge our [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown). Please look for a confirmation email from us. If you don't receive it in the next 10 minutes, please check your spam folder. This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply. {#footer} {#footer} ## Products and Services * [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown) * [Secure AI by Design](https://www.paloaltonetworks.com/precision-ai-security/secure-ai-by-design?ts=markdown) * [Prisma AIRS](https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security?ts=markdown) * [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown) * [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown) * [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [Industrial OT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown) * [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown) * [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown) * [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown) * [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown) * [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown) * [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown) * [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) * [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown) * [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown) ## Company * [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown) * [Careers](https://jobs.paloaltonetworks.com/en/) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown) * [Customers](https://www.paloaltonetworks.com/customers?ts=markdown) * [Investor Relations](https://investors.paloaltonetworks.com/) * [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown) * [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown) ## Popular Links * [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown) * [Communities](https://www.paloaltonetworks.com/communities?ts=markdown) * [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) * [Event Center](https://events.paloaltonetworks.com/) * [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center) * [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) * [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown) * [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown) * [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown) * [Tech Docs](https://docs.paloaltonetworks.com/) * [Unit 42](https://unit42.paloaltonetworks.com/) * [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd) ![PAN logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg) * [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) * [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown) * [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) * [Documents](https://www.paloaltonetworks.com/legal?ts=markdown) Copyright © 2026 Palo Alto Networks. All Rights Reserved * [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks) * [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown) * [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/) * [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks) * [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks) * EN Select your language