Zero Networks is expanding its integration with Palo Alto Networks, adding automated threat containment, deeper internal traffic inspection, and controls designed to secure AI agents across enterprise environments.
The expanded integration builds on the companies’ existing work around microsegmentation and firewall policy orchestration. Customers can now use Zero Networks to identify and contain threats at the individual-asset level, redirect selected traffic to Palo Alto Networks security services, and manage enforcement via Strata Cloud Manager.
The companies are also connecting Zero Networks AI Segmentation with Palo Alto Networks Prisma AIRS to govern AI agents and inspect AI-related traffic.
Integration targets lateral movement and automated containment
Zero Networks continuously maps communication between assets and creates least-privilege policies based on observed activity. Those policies are enforced at the asset level to close unnecessary pathways that attackers could use for lateral movement.
Under the expanded integration, selected traffic from protected workloads can be redirected to Palo Alto Networks firewalls for Layer 7 inspection. If malicious or unauthorized activity is detected, traffic can be blocked and the affected asset contained.
Linux traffic redirection is available now, with Windows support planned, according to Zero Networks.
Strata Cloud Manager adds unified policy visibility
The companies are also bringing enforcement data into Strata Cloud Manager, providing security teams with visibility into Zero Networks-discovered assets, segmentation policies, and Palo Alto Networks controls. Dynamic tagging is designed to keep policies current as workloads, IP addresses, and infrastructure change.
“Customers should not have to stitch together separate controls for their firewalls, internal assets, and AI agents,” said Benny Lakunishok, co-founder and CEO of Zero Networks. “This expanded integration creates one continuous enforcement model.”
Zero Networks has also been extending its segmentation technology into additional enterprise environments, including Kubernetes, where it launched an Access Matrix this year designed to help security and DevOps teams identify connectivity risks and limit lateral movement.
Prisma AIRS extends security controls to AI agents
The Palo Alto Networks integration extends that approach to AI infrastructure. Zero Networks can identify AI agents and restrict the applications, databases, models, and other systems each agent can reach based on its identity and intended purpose.
Selected AI traffic can then be redirected to Prisma AIRS for inspection of prompts, responses, and data flows.
The move aligns with Palo Alto Networks’ growing focus on securing autonomous AI. Channel Insider has previously reported on the company’s investments in AI agent and endpoint security, including acquisitions intended to expand Prisma AIRS as enterprises deploy agents with access to sensitive systems and data.
Zero Networks continues its channel-first MSP push
The announcement follows Zero Networks’ broader push into the IT channel. Earlier this year, the company moved to a 100% channel-first go-to-market model and reported 45% year-over-year growth in MSP partnerships as providers increasingly look to incorporate identity-driven containment into managed security offerings.
“We really see the channel embracing what we do and how we do it, and I think it’s crucial we stick to our three pillars for operating in the channel: we build trust, we make our partners profitable, and at the end of the day, our technology works for the end-user customers,” VP of Sales and GTM, Adam Hofeler, told Channel Insider in February.
For MSPs and security partners, the expanded Palo Alto Networks integration could create opportunities around segmentation, AI governance, and managed containment as customers seek to apply consistent controls across on-premises, cloud, operational technology, Kubernetes, and AI environments.
The expanded integration is available now, including automated microsegmentation, dynamic asset tagging, policy synchronization, and Linux traffic redirection.





