# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Palo Alto Networks Mobile Agent API version: 1.0.0 extends: openapi/palo-alto-networks-mobileagent-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 26 - target: $.paths['/sse/config/v1/mobile-agent/agent-profiles'].get update: x-apievangelist-phrasing: intent: List GlobalProtect agent profiles effect: read questions: - Which GlobalProtect agent profiles are configured for my mobile users? - Can I page through the GlobalProtect app profiles in one Prisma Access folder? instructions: - text: List the GlobalProtect agent profiles in folder {folder}. slots: folder: query.folder - text: Show the first {limit} GlobalProtect agent profiles in {folder}. slots: limit: query.limit folder: query.folder method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/mobile-agent/agent-profiles'].put update: x-apievangelist-phrasing: intent: Change a GlobalProtect agent profile effect: write questions: - Can I change the gateways an existing GlobalProtect agent profile connects to? - How do I turn on HIP collection in a GlobalProtect agent profile I already have? instructions: - text: Update GlobalProtect agent profile {name} in folder {folder} to use gateways {gateways}. slots: name: query.name folder: query.folder gateways: requestBody.gateways - text: Change the operating systems targeted by agent profile {name} in {folder} to {os}. slots: name: query.name folder: query.folder os: requestBody.os method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/mobile-agent/agent-profiles'].post update: x-apievangelist-phrasing: intent: Create a GlobalProtect agent profile effect: write questions: - How do I create a new GlobalProtect agent profile for a group of mobile users? - Can a new GlobalProtect app profile apply only to certain operating systems? instructions: - text: Create a GlobalProtect agent profile named {name} in folder {folder}. slots: name: requestBody.name folder: query.folder - text: Add a new agent profile {name} in {folder} for users {source_user}. slots: name: requestBody.name folder: query.folder source_user: requestBody.source_user method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/mobile-agent/agent-profiles'].delete update: x-apievangelist-phrasing: intent: Delete a GlobalProtect agent profile effect: destructive questions: - Can I remove a GlobalProtect agent profile my mobile users no longer need? - What do I need to specify to delete a GlobalProtect app profile? instructions: - text: Delete GlobalProtect agent profile {name} from folder {folder}. slots: name: query.name folder: query.folder - text: Remove the {name} GlobalProtect app profile in {folder}. slots: name: query.name folder: query.folder method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/mobile-agent/agent-versions'].get update: x-apievangelist-phrasing: intent: List available GlobalProtect agent versions effect: read questions: - Which GlobalProtect app versions can I deploy to my mobile users? - What agent versions does Prisma Access currently offer for GlobalProtect? instructions: - text: List the GlobalProtect agent versions that are available. - text: Show me which GlobalProtect client versions I can choose from. method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/mobile-agent/authentication-settings'].get update: x-apievangelist-phrasing: intent: List GlobalProtect authentication settings effect: read questions: - What authentication settings are configured for GlobalProtect users? - Which authentication profile does GlobalProtect use for each operating system? instructions: - text: List the GlobalProtect authentication settings in folder {folder}. slots: folder: query.folder - text: Show {limit} GlobalProtect authentication settings from {folder}. slots: limit: query.limit folder: query.folder method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/mobile-agent/authentication-settings'].put update: x-apievangelist-phrasing: intent: Edit a GlobalProtect authentication setting effect: write questions: - Can I switch the authentication profile on an existing GlobalProtect authentication setting? - How do I require a client certificate or user credential on an authentication setting I already have? instructions: - text: Edit GlobalProtect authentication setting {name} in {folder} to use authentication profile {authentication_profile}. slots: name: query.name folder: query.folder authentication_profile: requestBody.authentication_profile - text: Change the OS for authentication setting {name} in {folder} to {os}. slots: name: query.name folder: query.folder os: requestBody.os method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/mobile-agent/authentication-settings'].post update: x-apievangelist-phrasing: intent: Create a GlobalProtect authentication setting effect: write questions: - How do I add a new authentication setting for GlobalProtect users on a specific OS? - Can a new GlobalProtect authentication setting require both credentials and a client certificate? instructions: - text: Create a GlobalProtect authentication setting in {folder} for {os} using profile {authentication_profile}. slots: folder: query.folder os: requestBody.os authentication_profile: requestBody.authentication_profile - text: Add an authentication setting in {folder} for {os} with credential-or-cert requirement {user_credential_or_client_cert_required}. slots: folder: query.folder os: requestBody.os user_credential_or_client_cert_required: requestBody.user_credential_or_client_cert_required method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/mobile-agent/authentication-settings'].delete update: x-apievangelist-phrasing: intent: Delete a GlobalProtect authentication setting effect: destructive questions: - Can I remove a GlobalProtect authentication setting I no longer use? - What happens if I delete a GlobalProtect authentication setting from a folder? instructions: - text: Delete GlobalProtect authentication setting {name} from folder {folder}. slots: name: query.name folder: query.folder - text: Remove the {name} GlobalProtect auth setting in {folder}. slots: name: query.name folder: query.folder method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/mobile-agent/enable'].get update: x-apievangelist-phrasing: intent: Check whether GlobalProtect is enabled effect: read questions: - Is the mobile agent (GlobalProtect) turned on for my Prisma Access configuration? - How can I tell if mobile users are enabled in my tenant? instructions: - text: Check whether the GlobalProtect mobile agent is enabled. - text: Tell me if mobile agent support is switched on for my configuration. method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/mobile-agent/enable'].post update: x-apievangelist-phrasing: intent: Enable the GlobalProtect mobile agent effect: write questions: - How do I turn on GlobalProtect for mobile users in Prisma Access? - What call switches the mobile agent on for my configuration? instructions: - text: Enable the GlobalProtect mobile agent for my configuration. - text: Turn on mobile user support with GlobalProtect. method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/mobile-agent/global-settings'].get update: x-apievangelist-phrasing: intent: Show GlobalProtect global settings effect: read questions: - Which agent version and manual gateway are set in my GlobalProtect global settings? - Where can I see the tenant-wide GlobalProtect settings? instructions: - text: Show the global settings configured for GlobalProtect. - text: Get the current GlobalProtect global agent version setting. method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/mobile-agent/global-settings'].put update: x-apievangelist-phrasing: intent: Edit GlobalProtect global settings effect: write questions: - Can I pin all mobile users to a specific GlobalProtect agent version? - How do I set a manual gateway in the GlobalProtect global settings? instructions: - text: Set the GlobalProtect global agent version to {agent_version}. slots: agent_version: requestBody.agent_version - text: Update the GlobalProtect global manual gateway to {manual_gateway}. slots: manual_gateway: requestBody.manual_gateway method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/mobile-agent/infrastructure-settings'].get update: x-apievangelist-phrasing: intent: Show GlobalProtect infrastructure settings effect: read questions: - What portal hostname, DNS servers and IP pools are set for GlobalProtect in a folder? - Where do I see the SSE infrastructure settings for mobile users in one folder? instructions: - text: Show the GlobalProtect infrastructure settings in folder {folder}. slots: folder: query.folder - text: List the SSE mobile agent portal and IP pool settings for {folder}. slots: folder: query.folder method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/mobile-agent/infrastructure-settings'].put update: x-apievangelist-phrasing: intent: Edit GlobalProtect infrastructure settings effect: write questions: - Can I change the DNS servers on my existing GlobalProtect infrastructure settings? - How do I update the portal hostname for GlobalProtect mobile users? instructions: - text: Edit infrastructure settings {name} in {folder} to use portal hostname {portal_hostname}. slots: name: requestBody.name folder: query.folder portal_hostname: requestBody.portal_hostname - text: Replace the IP pools in GlobalProtect infrastructure settings {name} in {folder} with {ip_pools}. slots: name: requestBody.name folder: query.folder ip_pools: requestBody.ip_pools method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/mobile-agent/infrastructure-settings'].post update: x-apievangelist-phrasing: intent: Create GlobalProtect infrastructure settings effect: write questions: - What do I need to create GlobalProtect infrastructure settings through the SSE config API? - Can I enable IPv6 or WINS when setting up GlobalProtect infrastructure for the first time? instructions: - text: Create GlobalProtect infrastructure settings {name} in {folder} with portal {portal_hostname}, DNS {dns_servers} and IP pools {ip_pools}. slots: name: requestBody.name folder: query.folder portal_hostname: requestBody.portal_hostname dns_servers: requestBody.dns_servers ip_pools: requestBody.ip_pools - text: Set up new SSE mobile infrastructure settings {name} in folder {folder}. slots: name: requestBody.name folder: query.folder method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/mobile-agent/infrastructure-settings'].delete update: x-apievangelist-phrasing: intent: Delete GlobalProtect infrastructure settings effect: destructive questions: - Can I remove a set of GlobalProtect infrastructure settings from a folder? - What identifies the infrastructure settings I want to delete? instructions: - text: Delete GlobalProtect infrastructure settings {name} from folder {folder}. slots: name: query.name folder: query.folder - text: Remove the SSE mobile infrastructure settings called {name} in {folder}. slots: name: query.name folder: query.folder method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/mobile-agent/locations'].get update: x-apievangelist-phrasing: intent: List Prisma Access locations for GlobalProtect effect: read questions: - Which Prisma Access locations are my GlobalProtect users able to connect to? - What regions are configured for mobile users in a folder? instructions: - text: List the Prisma Access locations configured for GlobalProtect in {folder}. slots: folder: query.folder - text: Show which mobile user regions are set in folder {folder}. slots: folder: query.folder method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/mobile-agent/locations'].put update: x-apievangelist-phrasing: intent: Edit Prisma Access locations for GlobalProtect effect: write questions: - How do I add or remove Prisma Access locations for my mobile users? - Can I change which regions GlobalProtect users connect through? instructions: - text: Set the GlobalProtect Prisma Access locations in {folder} to region {region}. slots: folder: query.folder region: requestBody.region - text: Update the mobile user locations in folder {folder}. slots: folder: query.folder method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/mobile-agent/tunnel-profiles'].get update: x-apievangelist-phrasing: intent: List GlobalProtect tunnel profiles effect: read questions: - Which GlobalProtect tunnel profiles are defined for my mobile users? - Can I see the split tunneling setup across my tunnel profiles? instructions: - text: List the GlobalProtect tunnel profiles in folder {folder}. slots: folder: query.folder - text: Show {limit} tunnel profiles from {folder} starting at offset {offset}. slots: limit: query.limit folder: query.folder offset: query.offset method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/mobile-agent/tunnel-profiles'].put update: x-apievangelist-phrasing: intent: Update a GlobalProtect tunnel profile effect: write questions: - How do I change split tunneling on an existing GlobalProtect tunnel profile? - Can I block direct access to the local network in a tunnel profile I already have? instructions: - text: Update tunnel profile {name} in {folder} with split tunneling {split_tunneling}. slots: name: query.name folder: query.folder split_tunneling: requestBody.split_tunneling - text: Turn off direct local network access on tunnel profile {name} in {folder}. slots: name: query.name folder: query.folder method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/mobile-agent/tunnel-profiles'].post update: x-apievangelist-phrasing: intent: Create a GlobalProtect tunnel profile effect: write questions: - How do I create a new GlobalProtect tunnel profile with split tunneling? - Can a new tunnel profile apply only to certain source users or addresses? instructions: - text: Create a GlobalProtect tunnel profile named {name} in folder {folder}. slots: name: requestBody.name folder: query.folder - text: Add tunnel profile {name} in {folder} for source addresses {source_address}. slots: name: requestBody.name folder: query.folder source_address: requestBody.source_address method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/mobile-agent/tunnel-profiles'].delete update: x-apievangelist-phrasing: intent: Delete a GlobalProtect tunnel profile effect: destructive questions: - Can I remove a GlobalProtect tunnel profile that nobody uses anymore? - What do I pass to delete a tunnel profile from a folder? instructions: - text: Delete GlobalProtect tunnel profile {name} from folder {folder}. slots: name: query.name folder: query.folder - text: Remove the {name} tunnel profile from {folder}. slots: name: query.name folder: query.folder method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/mobile-agent/user-authentication:move'].post update: x-apievangelist-phrasing: intent: Reorder GlobalProtect authentication settings effect: write questions: - How do I change the evaluation order of my GlobalProtect authentication settings? - Can I move one authentication setting before another? instructions: - text: Move authentication setting {name} in {folder} to {where} {destination}. slots: name: query.name folder: query.folder where: requestBody.where destination: requestBody.destination - text: Put authentication setting {name} in folder {folder} at the top of the list. slots: name: query.name folder: query.folder method: generated generated: '2026-09-26' - target: $.paths['/mobile-agent/infrastructure-settings'].get update: x-apievangelist-phrasing: intent: Get mobile agent infrastructure settings (candidate) effect: read questions: - Where can I read the mobile user infrastructure settings that define Prisma Access regions and DNS suffix? - What IP pool and DNS suffix does the mobile agent candidate configuration use? instructions: - text: Get the mobile agent infrastructure settings, including DNS suffix and regions, for folder {folder}. slots: folder: query.folder - text: Show the candidate mobile user infrastructure settings. method: generated generated: '2026-09-26' - target: $.paths['/mobile-agent/infrastructure-settings'].post update: x-apievangelist-phrasing: intent: Stage mobile agent infrastructure in candidate config effect: write questions: - Can I set the DNS suffix and regions for mobile users in the candidate configuration? - Do mobile infrastructure changes take effect before I push the configuration? instructions: - text: Write mobile agent infrastructure settings {name} to the candidate config with IP pool {ip_pool} and DNS suffix {dns_suffix}. slots: name: requestBody.name ip_pool: requestBody.ip_pool dns_suffix: requestBody.dns_suffix - text: Stage mobile user regions {regions} in the candidate infrastructure settings. slots: regions: requestBody.regions method: generated generated: '2026-09-26'