<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CIE integration in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cie-integration/m-p/616228#M7409</link>
    <description>&lt;P class="p1"&gt;Hi&amp;nbsp;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1372551263"&gt;@Fm12345&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;Thanks for your query on LC!&lt;/P&gt;
&lt;P class="p1"&gt;&lt;BR /&gt;It depends on the customer and their setup. If you are synching everything to Azure, I would expect that information to be there. I believe it's possible to only synch a portion of on prem AD to Azure, though, in which case on prem would be necessary to get everything.&lt;/P&gt;
&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;The on-prem Cloud Identity Engine agent is what pulls OUs from AD, Also you will need to setup CIE on-prem in order to take advantage of most of the Identity Analytics (and ITD) detections.&amp;nbsp;&lt;/P&gt;
&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;There are two reasons you may opt for going the on-prem agent vs the cloud configuration:&lt;/P&gt;
&lt;OL class="ol1"&gt;
&lt;LI class="li1"&gt;You want to collect OU information on users and computers. Azure AD is flat, so while you&amp;nbsp;&lt;I&gt;will&amp;nbsp;&lt;/I&gt;get group information, there's no concept of OUs.&lt;/LI&gt;
&lt;LI class="li1"&gt;The customer is only synching a subset of their directory to Azure AD and you want to be able to identify everything,&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="p1"&gt;If you don't care about OUs, Identity Analytics (and ITD) detections etc,.&amp;nbsp;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;then&amp;nbsp;&lt;/SPAN&gt;I'd just connect Azure AD.&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;If this response was helpful, please click "&lt;STRONG&gt;Accept as Solution&lt;/STRONG&gt;" to acknowledge.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Wed, 06 Nov 2024 10:52:04 GMT</pubDate>
    <dc:creator>nar</dc:creator>
    <dc:date>2024-11-06T10:52:04Z</dc:date>
    <item>
      <title>CIE integration</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cie-integration/m-p/616147#M7405</link>
      <description>&lt;P&gt;In case of hybrid environment,Can we send data to CIE instance from both Azure AD as well as on-prem AD as it supports both.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Or it is enough if we send data only from on-prem AD alone.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2024 15:15:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cie-integration/m-p/616147#M7405</guid>
      <dc:creator>Fm12345</dc:creator>
      <dc:date>2024-11-05T15:15:55Z</dc:date>
    </item>
    <item>
      <title>Re: CIE integration</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cie-integration/m-p/616228#M7409</link>
      <description>&lt;P class="p1"&gt;Hi&amp;nbsp;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1372551263"&gt;@Fm12345&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;Thanks for your query on LC!&lt;/P&gt;
&lt;P class="p1"&gt;&lt;BR /&gt;It depends on the customer and their setup. If you are synching everything to Azure, I would expect that information to be there. I believe it's possible to only synch a portion of on prem AD to Azure, though, in which case on prem would be necessary to get everything.&lt;/P&gt;
&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;The on-prem Cloud Identity Engine agent is what pulls OUs from AD, Also you will need to setup CIE on-prem in order to take advantage of most of the Identity Analytics (and ITD) detections.&amp;nbsp;&lt;/P&gt;
&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;There are two reasons you may opt for going the on-prem agent vs the cloud configuration:&lt;/P&gt;
&lt;OL class="ol1"&gt;
&lt;LI class="li1"&gt;You want to collect OU information on users and computers. Azure AD is flat, so while you&amp;nbsp;&lt;I&gt;will&amp;nbsp;&lt;/I&gt;get group information, there's no concept of OUs.&lt;/LI&gt;
&lt;LI class="li1"&gt;The customer is only synching a subset of their directory to Azure AD and you want to be able to identify everything,&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="p1"&gt;If you don't care about OUs, Identity Analytics (and ITD) detections etc,.&amp;nbsp;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;then&amp;nbsp;&lt;/SPAN&gt;I'd just connect Azure AD.&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;If this response was helpful, please click "&lt;STRONG&gt;Accept as Solution&lt;/STRONG&gt;" to acknowledge.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2024 10:52:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cie-integration/m-p/616228#M7409</guid>
      <dc:creator>nar</dc:creator>
      <dc:date>2024-11-06T10:52:04Z</dc:date>
    </item>
  </channel>
</rss>

