Palo Alto Networks Wildfire provides critical insights into malicious file behavior. To integrate Palo Alto Networks Wildfire with Zscaler MDR via email, follow the procedure below from beginning to end.
Before connecting to Palo Alto Networks Wildfire to Zscaler MDR, make sure the following configuration requirement is met:
Create a Palo Alto Networks Wildfire user account using the Zscaler MDR email provided in Step 1.7.
Step 1: Zscaler MDR–Create a Zscaler MDR email for alerts
Create a Zscaler MDR provided-email to send Wildfire alerts for ingestion.
In the Zscaler MDR portal, click Integrations. If you do not see the required integration, click See all integrations.
.png?sv=2026-02-06&spr=https&st=2026-09-15T02%3A37%3A22Z&se=2026-09-15T02%3A49%3A22Z&sr=c&sp=r&sig=RWb6kEzGazvLEVnwAe7SOE0ueaOcx8iJ4MEsip%2Bhy9s%3D)
In the search bar, type and then select Palo Alto Networks Wildfire.

Click Configure.
Select a display category.
Under the Ingest Format/Method dropdown, select Palo Alto Networks Wildfire via Email.

Click Save Configuration. This will generate the email address you will use to send Palo Alto Wildfire alerts to.

Click Edit Configuration.
With your alert source configured, click Activate.
With your Zscaler MDR email generated, log in to Palo Alto Networks Wildfire.
Step 2: Palo Alto Customer Support Portal–Create a Wildfire User account
Create a Wildfire User account to enable Wildfire to send alerts to the Zscaler MDR alert collector.
Login into the Palo Alto customer support portal with your Wildfire admin account.
From the Members dropdown click WildFire Users.
Click Add Wildfire Users.
Enter the Zscaler MDR provided email address.
Click Submit.
Select the wildfire device you want to connect to Zscaler MDR.

Enter the required information.
Click Submit.
Step 3: Zscaler MDR–Retrieve your Wildfire activation link
To return to a pre existing integration:
In the Zscaler MDR portal, click Integrations.
Scroll down, and then select your third-party security source.
Click Edit Configuration.
Click View Alerts.

Click your Alert ID.

Click the Show original alert dropdown.

To activate the find command, press Control+F (or Command+F on a Mac).
Type and search for sso.paloaltonetworks.com/welcome.
From the HTML section, copy and save the URL.
Example: https://sso.paloaltonetworks.com/welcome/testnumber://support.paloaltonetoworks.com/

To activate your new alert source, copy and paste the URL form Step 3.9 into a new browser window.
Create a new password for your Wildfire account.
Click Create My Account.
Step 4: Palo Alto Networks Wildfire–Configure email alerts
Adjust your Palo Alto Networks Wildfire settings to send generated alerts to your Zscaler MDR-provided email.
Create a Wildfire user account using the Zscaler MDR email provided in Step 1.7.
From your Wildfire dashboard, click Settings.
In the Configure Alerts section, select the types of alerts you want to send Zscaler MDR. We recommend selecting Malware, Grayware, and Phishing as these are the most useful alerts to Zscaler MDR.

Note: If you send Benign alerts, Zscaler MDR will automatically mark them as “not a threat”.
Click Update Notification.