* [Blog](https://www2.paloaltonetworks.com/blog) * [Palo Alto Networks](https://www2.paloaltonetworks.com/blog/corporate/) * [Announcement](https://www2.paloaltonetworks.com/blog/category/announcement/) * PAN-OS 10.1 Innovations E... # PAN-OS 10.1 Innovations Empower Complete Zero Trust Network Security [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww2.paloaltonetworks.com%2Fblog%2F2021%2F07%2Fpan-os-10-1-innovations%2F) [](https://twitter.com/share?text=PAN-OS+10.1+Innovations+Empower+Complete+Zero+Trust+Network+Security&url=https%3A%2F%2Fwww2.paloaltonetworks.com%2Fblog%2F2021%2F07%2Fpan-os-10-1-innovations%2F) [](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww2.paloaltonetworks.com%2Fblog%2F2021%2F07%2Fpan-os-10-1-innovations%2F&title=PAN-OS+10.1+Innovations+Empower+Complete+Zero+Trust+Network+Security&summary=&source=) [](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https://www2.paloaltonetworks.com/blog/2021/07/pan-os-10-1-innovations/&ts=markdown) \[\](mailto:?subject=PAN-OS 10.1 Innovations Empower Complete Zero Trust Network Security) Link copied By [Neha Kumar](https://www.paloaltonetworks.com/blog/author/neha-kumar/?ts=markdown "Posts by Neha Kumar") Jul 01, 2021 6 minutes [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown) [Next-Generation Firewalls](https://www.paloaltonetworks.com/blog/network-security/category/next-generation-firewalls/?ts=markdown) [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [Zero Trust Security](https://www.paloaltonetworks.com/blog/network-security/category/zero-trust-security/?ts=markdown) [Cloud Identity Engine](https://www.paloaltonetworks.com/blog/tag/cloud-identity-engine/?ts=markdown) [Decryption](https://www.paloaltonetworks.com/blog/tag/decryption/?ts=markdown) [Identity](https://www.paloaltonetworks.com/blog/tag/identity/?ts=markdown) [Network Packet Broker](https://www.paloaltonetworks.com/blog/tag/network-packet-broker/?ts=markdown) [OpenConfig](https://www.paloaltonetworks.com/blog/tag/openconfig/?ts=markdown) [PAN-OS](https://www.paloaltonetworks.com/blog/tag/pan-os/?ts=markdown) [PAN-OS 10.1](https://www.paloaltonetworks.com/blog/tag/pan-os-10-1/?ts=markdown) [Simplifying Network Operations](https://www.paloaltonetworks.com/blog/tag/simplifying-network-operations/?ts=markdown) [Zero Trust](https://www.paloaltonetworks.com/blog/tag/zero-trust/?ts=markdown) This post is also available in: [日本語 (Japanese)](https://www2.paloaltonetworks.com/blog/2021/07/pan-os-10-1-innovations/?lang=ja "Switch to Japanese(日本語)") The pandemic has changed the way we work and conduct business for good. [Poll after poll confirms](https://www.paloaltonetworks.com/blog/2021/01/sase-hybrid-workforce/) that people "do not want to go back to the office full time, even once it's safe to do so." With hybrid work environments becoming the new norm, organizations are reconsidering their networking and security infrastructure to support this new reality. Corporations need to ensure that their employees have optimal user experience wherever and whenever they work, while maintaining safe access to the right data and applications for the right users and devices. This is difficult to achieve in a hybrid cloud world where data, applications and user identity are spread across on-premises and cloud sources. Meanwhile, security teams are under pressure to secure the ever-increasing surface area of their organizations efficiently with finite people and limited resources. Palo Alto Networks announced [Complete Zero Trust Network Security](https://www.paloaltonetworks.com/blog/2021/05/zero-trust-for-network-security/) to address these requirements and safeguard productivity in this new reality of a hybrid work environment. In addition to new services such as [SaaS Security service](https://www.paloaltonetworks.com/network-security/saas-security), [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering) and expanded [DNS security](https://www.paloaltonetworks.com/network-security/dns-security.html) capabilities, we introduced innovations in the [core operating system](https://www.paloaltonetworks.com/network-security/pan-os) to continue to empower organizations to move toward Zero Trust. The latest PAN-OS 10.1 innovations simplify identity-based security, simplify and consolidate decryption, enable you to manage firewalls efficiently by using open and programmable platforms, and deliver hyperscale security in physical and virtual environments. Let's look at some of the key innovations introduced in PAN-OS 10.1. ## Simplify Zero Trust for Identity Enterprises today find it hard to consistently verify their users and enforce identity-based security as user information is fragmented between different identity stores, such as Active Directory (on-premises), Okta (cloud), Azure AD (cloud) and more. This has led to network security operators struggling to secure their workforce and enable safe and secure access to applications and data. Configuring, maintaining and synchronizing the network security ecosystem with the multiple identity providers is time-consuming and resource-intensive, resulting in significantly increased effort and delayed projects. With [Cloud Identity Engine](https://www.paloaltonetworks.com/resources/videos/cloud-identity-engine-demo), security teams can now consistently authenticate and authorize their users, regardless of location or where user identity stores live. As a result, security teams can effortlessly allow access to applications and data everywhere -- cloud, on-prem or hybrid -- to quickly move toward a Zero Trust security posture. The [Cloud Identity Engine](https://www.paloaltonetworks.com/blog/2021/06/simplifying-identity-based-security/) offers a cloud-based architecture and assures synchronization of all identity-related data in the cloud to apply controls everywhere in the enterprise: data center, campus, public cloud, branches and remote users. New identity sources can be configured in about 10 minutes, versus days or months, saving time in deployment and management of identity-based controls on your network security infrastructure. ![Transition from on-premises to cloud identity with PAN-OS 10.1 innovations.](https://www.paloaltonetworks.com/blog/wp-content/uploads/2021/06/word-image-69.png) On Premises to Cloud Identity ## Consolidate and Simplify Decryption Deploying decryption is crucial before securing all content, however, deploying and maintaining decryption has been a challenge for the industry. Organizations that deploy third-party security controls as part of their overall security suite need to decrypt traffic multiple times to realize the benefits of their entire security stack. Doing so introduces operational complexity, increases network latency and negatively impacts the end-user experience. Although firewall vendors offer decryption, they seldom send all the traffic to third-party security tools, which creates blind spots. As a result, enterprises buy additional appliances such as SSL decryption and dedicated packet broker appliances to decrypt, filter and forward traffic to security tools, increasing cost and operational complexity. Palo Alto Networks makes it [easy to deploy and maintain decryption](https://www.paloaltonetworks.com/blog/2020/08/network-advances-in-decryption/) with comprehensive visibility, support for modern protocols, easy troubleshooting and new hardware Next-Generation Firewalls (NGFW) and Data Processing Cards with heavily accelerated performance. With [Network Packet Broker](https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-new-features/networking-features/network-packet-broker) in PAN-OS 10.1, NGFWs by Palo Alto Networks can intelligently broker all types of traffic (Decrypted TLS, encrypted TLS and non-TLS) to a suite of third-party security tools from a single device. This allows customers to simplify their network and reduce capital and operating expenses with built-in decryption and broker on the NGFWs. In addition, network security teams can now optimize their network performance and maximize their existing security tools' efficacy by selectively sending only the necessary traffic to a given third-party security tool. For more information, download our "[Decryption: Why, Where and How](https://www.paloaltonetworks.com/resources/whitepapers/decryption-why-where-and-how)" whitepaper. ## Simplify Management of Zero Trust Network Security Infrastructure Network operators face a challenge while trying to enforce Zero Trust across their network. In PAN-OS 10.1 we have introduced two new capabilities to simplify management to better enable your Zero Trust strategy across network security infrastructure. #### OpenConfig (OC) Programmatically managing network services that span multiple network elements in their multi-vendor infrastructure can be difficult due to a lack of common schema/model interfaces. With the support for OC vendor-neutral data models, Palo Alto Networks brings additional automation capabilities to the NGFWs. Customers can now manage NGFWs with OC to automate network service configuration across their infrastructure and stream telemetry to quickly resolve NGFW health and performance issues for their entire deployment. #### Scheduled Push When it comes to managing configuration changes in the management tools, administrators accumulate all the changes and have to wait for the next change management window to push the changes to the firewalls. Change management windows are typically off hours to avoid outages and admins' need to be present to push the changes interactively during that time. With PAN-OS 10.1, we are making it simple for admins to automate configuration changes for all firewalls with Scheduled Push with [Panorama](https://www.paloaltonetworks.com/network-security/panorama) -- a network security management solution. Schedule Push reduces human involvement during off hours. Admins can now schedule a one-time or recurring push to firewalls of their choice within Panorama, without having to be present. Admins can also efficiently push changes across their entire deployment in one single push. This also works for multi-virtual system (VSYS) firewalls, so if multiple device groups are mapped to different VSYS on a firewall, a single scheduled push can update the multi-VSYS firewalls. Panorama also gives you the ability to track all the changes. The execution of the scheduled push happens unsupervised, but all details are captured in system logs and configuration logs, including any errors. ## Hyperscale Virtualized Network Security In hyperscale data centers, the need to leverage compute resources as efficiently as possible is paramount. Service providers and enterprises alike strive to maximize efficiency to drive operating expenses down. This is one of the core reasons that organizations adopt virtualization, but it raises a question about how to effectively enforce Zero Trust Network Security in a virtual environment. With the new Intelligent Traffic Offload feature, the [VM-Series](https://www.paloaltonetworks.com/prisma/vm-series) virtual NGFWs eliminate the tradeoff between security and cost in service provider and hyperscale data center environments. Organizations can extend Zero Trust Network Security posture to a virtualized infrastructure without breaking the bank or compromising network performance. ![Turbocharge your VM series performance with Intelligent Traffic Offload Service by PAN-OS 10.1 innovations.](https://www.paloaltonetworks.com/blog/wp-content/uploads/2021/06/word-image.gif) Find out how we're securing the new flexible workplace. For a complete list of new PAN-OS 10.1 innovations, please see our [PAN-OS Release Notes](https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-release-notes/features-introduced-in-pan-os.html). Watch our virtual launch event on-demand: [Complete Zero Trust Network Security](https://start.paloaltonetworks.com/zero-trust-security-series#Episode-02). And get ready to secure productivity wherever it takes place. *** ** * ** *** ## Related Blogs ### [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/sase/category/product-features/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Achieve True Zero Trust and Peak Performance with Prisma Access 6.1](https://www2.paloaltonetworks.com/blog/sase/achieve-true-zero-trust-and-peak-performance-with-prisma-access-6-1/) ### [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [News and Events](https://www.paloaltonetworks.com/blog/security-operations/category/news-and-events/?ts=markdown), [Partners](https://www.paloaltonetworks.com/blog/category/partners/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Identity Protection That Spans the Entire Attack Lifecycle](https://www2.paloaltonetworks.com/blog/2024/08/identity-protection-that-spans-the-entire-attack-lifecycle/) ### [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Industrial OT Security](https://www.paloaltonetworks.com/blog/network-security/category/industrial-ot-security/?ts=markdown), [IoT Security](https://www.paloaltonetworks.com/blog/network-security/category/iot-security/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [Zero Trust Security](https://www.paloaltonetworks.com/blog/network-security/category/zero-trust-security/?ts=markdown) [#### Untangling IT-OT Security Knots with a Zero Trust Platform Approach](https://www2.paloaltonetworks.com/blog/2024/05/untangling-it-ot-security-knots/) ### [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Company \& Culture](https://www.paloaltonetworks.com/blog/category/company-culture/?ts=markdown), [Points of View](https://www.paloaltonetworks.com/blog/category/points-of-view/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### More on the PAN-OS CVE-2024-3400](https://www2.paloaltonetworks.com/blog/2024/04/more-on-the-pan-os-cve/) ### [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [SD-WAN](https://www.paloaltonetworks.com/blog/sase/category/sd-wan/?ts=markdown) [#### Why Your Branch of the Future Needs Next-Gen SD-WAN and Prisma SASE](https://www2.paloaltonetworks.com/blog/2023/05/powering-the-branch-of-the-future/) ### [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Enabling Secure Digital Transformation in Healthcare](https://www2.paloaltonetworks.com/blog/2023/04/digital-transformation-in-healthcare/) ### Subscribe to the Blog! Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more. ![spinner](https://www2.paloaltonetworks.com/blog/wp-content/themes/panwblog2023/dist/images/ajax-loader.gif) Sign up Please enter a valid email. By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) and acknowledge our [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown). Please look for a confirmation email from us. If you don't receive it in the next 10 minutes, please check your spam folder. This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply. {#footer} {#footer} ## Products and Services * [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown) * [Secure AI by Design](https://www.paloaltonetworks.com/precision-ai-security/secure-ai-by-design?ts=markdown) * [Prisma AIRS](https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security?ts=markdown) * [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown) * [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown) * [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [Industrial OT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown) * [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown) * [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown) * [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown) * [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown) * [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown) * [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown) * [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) * [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown) * [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown) ## Company * [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown) * [Careers](https://jobs.paloaltonetworks.com/en/) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown) * [Customers](https://www.paloaltonetworks.com/customers?ts=markdown) * [Investor Relations](https://investors.paloaltonetworks.com/) * [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown) * [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown) ## Popular Links * [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown) * [Communities](https://www.paloaltonetworks.com/communities?ts=markdown) * [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) * [Event Center](https://events.paloaltonetworks.com/) * [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center) * [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) * [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown) * [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown) * [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown) * [Tech Docs](https://docs.paloaltonetworks.com/) * [Unit 42](https://unit42.paloaltonetworks.com/) * [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd) ![PAN logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg) * [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) * [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown) * [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) * [Documents](https://www.paloaltonetworks.com/legal?ts=markdown) Copyright © 2026 Palo Alto Networks. All Rights Reserved * [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks) * [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown) * [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/) * [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks) * [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks) * EN Select your language