All of these things are actually configured by your university. They are configuration options for the firewall that enforces the portal. Blame your university IT, not Palo Alto.
The policies are really not excessive, Palo Alto is designing for enterprises which would want many of these restrictions on their assets. It just so happens the software is flexible enough to be used in BYOD settings. The IT professionals in those settings need to do their due diligence and apply appropriate policies. This is a PICNIC/PEBKAC.