<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Cloud Identity Engine Introduces Group Filtering When Collecting Groups from Entra ID in Cloud Identity Engine Articles</title>
    <link>https://live.paloaltonetworks.com/t5/cloud-identity-engine-articles/cloud-identity-engine-introduces-group-filtering-when-collecting/ta-p/590664</link>
    <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Title_Cloud-Identity-Engine_palo-alto-networks.jpg" style="width: 960px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60577iBC6AE96ED8D13D06/image-size/large?v=v2&amp;amp;px=999" role="button" title="Title_Cloud-Identity-Engine_palo-alto-networks.jpg" alt="Title_Cloud-Identity-Engine_palo-alto-networks.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Executive Summary&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-new-features/identity-features/cloud-identity-engine" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Cloud Identity Engine (CIE)&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; now provides customers with the ability to select the groups they would like to synchronize with CIE from Entra ID (formerly Azure AD) by using filters (for example, group name “&lt;/SPAN&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;starts with&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;” or “&lt;/SPAN&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;matches&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;'' with “&lt;/SPAN&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;Name&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;” and “&lt;/SPAN&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;Unique Identifier&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;”). This reduces the total amount of data shared with CIE to only the data necessary for policy enforcement without the inherent tradeoffs of using System for Cross-domain Identity Management (SCIM).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;How Directories are Used to Enforce Zero Trust Policies&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;To adhere to Zero Trust principles in your network, you need to create policies based on usernames and groups instead of IP addresses. User-based policies and least privilege access policies provide much greater security by ensuring that regardless of where a user is logged in from the same policies will apply to them and that users have access to the minimum resources required to perform their roles.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;To create user-based policies and meet the least privilege access requirements, enforcement points, such as Next Generation Firewalls or Prisma Access, need to collect user information and user groups from a directory source. Using the Directory Synchronization feature (also known as Directory Sync) in the Cloud Identity Engine provides a simplified and unified interface to help retrieve these and achieve the goal of zero trust policy enforcement.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The largest and most popular Cloud-based directory is Microsoft’s Entra ID. Palo Alto Networks provides you with two methods to collect user and user group information from Microsoft’s Entra ID into the Cloud Identity Engine:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Microsoft’s GraphAPIs&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;SCIM&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Making the right choice for your organization is important to ensure that you adhere to your organizational and legal requirements.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Introducing Group Filtering for Entra ID&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The primary use case for using SCIM for data collection from Entra ID is to provide an administrator with fine-grained controls over what data is sent to the Cloud Identity Engine (CIE). While SCIM has accomplished this goal for many of our customers, it has also introduced its own challenges. Because &lt;/SPAN&gt;&lt;SPAN&gt;SCIM is designed to deliver small &lt;/SPAN&gt;&lt;A href="https://docs.microsoft.com/en-us/azure/databricks/administration-guide/users-groups/scim/aad" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;frequent requests for data&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;, it is a great solution for cloud-based applications that perform a one-time lookup to authorize user access. However, it is not as efficient when attempting to gather large volumes of data that will be used continuously. When gathering the required information for Directory Sync, &lt;/SPAN&gt;&lt;SPAN&gt;Microsoft limits the frequency of updates which CIE can make to once every 40 minutes&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;GraphAPIs provide a more efficient solution for use cases such as the frequent updates requested by Directory Sync. The Cloud Identity Engine synchronizes Entra ID information every five minutes to update information for existing users and groups and to add new information. After the synchronization is complete, group and group membership data is available for use by Prisma Access and for security policy enforcement by Next Generation Firewalls. The group filter enhancement provides you with even more customization and control of the data that your instance of Entra ID provides to CIE.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Fig 1_Cloud-Identity-Engine_palo-alto-networks.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60573i5E43D8EBCDB2AF1A/image-size/large?v=v2&amp;amp;px=999" role="button" title="Fig 1_Cloud-Identity-Engine_palo-alto-networks.png" alt="Fig 1_Cloud-Identity-Engine_palo-alto-networks.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;With this enhancement, you can now filter specific groups collected from Entra ID for synchronization with CIE. The filter for Entra ID provides two different types of data that you can use for filtering data:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Group Name&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Unique Identifier&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Group name filters include two operators supported by Entra ID APIs:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;FONT face="courier new,courier"&gt;&lt;I&gt;&lt;SPAN&gt;begins with&lt;/SPAN&gt;&lt;/I&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;FONT face="courier new,courier"&gt;&lt;I&gt;&lt;SPAN&gt;is equal to&lt;/SPAN&gt;&lt;/I&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Unique Identifier filters include the one operator which Entra ID APIs support: &lt;/SPAN&gt;&lt;FONT face="courier new,courier"&gt;&lt;I&gt;&lt;SPAN&gt;is equal to&lt;/SPAN&gt;&lt;/I&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;With these two data types, you have the flexibility to select the groups that are synchronized with CIE without compromising on update frequency.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Start Using the Feature Today!&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;New customers can begin to use this capability immediately. When selecting &lt;/SPAN&gt;&lt;SPAN&gt;&lt;FONT face="courier new,courier"&gt;Directory Sync &amp;gt; Directories &amp;gt; Add New Directory &amp;gt; Set Up &amp;gt; Azure&lt;/FONT&gt;,&lt;/SPAN&gt;&lt;SPAN&gt; you can create a filter for your Entra ID directory right away; From the first first synchronization, Directory Sync will only synchronize the data that is included in the filter.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Fig 2_Cloud-Identity-Engine_palo-alto-networks.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60574i37451618BDB58568/image-size/large?v=v2&amp;amp;px=999" role="button" title="Fig 2_Cloud-Identity-Engine_palo-alto-networks.png" alt="Fig 2_Cloud-Identity-Engine_palo-alto-networks.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Existing customers can migrate their current configurations to use the group filter as well. When selecting &lt;/SPAN&gt;&lt;SPAN&gt;&lt;FONT face="courier new,courier"&gt;Directory Sync &amp;gt; Directories &amp;gt; Actions &amp;gt; Edit&lt;/FONT&gt;,&lt;/SPAN&gt;&lt;SPAN&gt; you can add a filter to your existing directory connection. When Directory Sync completes the next sync of recent changes (“Sync Changes”) , the service removes the existing data and replaces it with the data based on the filter.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Fig 3_Cloud-Identity-Engine_palo-alto-networks.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60575iCD7A43C9DB8D0781/image-size/large?v=v2&amp;amp;px=999" role="button" title="Fig 3_Cloud-Identity-Engine_palo-alto-networks.png" alt="Fig 3_Cloud-Identity-Engine_palo-alto-networks.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Both new and existing customers can add or remove groups from the filter (or remove the filter entirely) using &lt;/SPAN&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;Directory Sync &amp;gt; Directories &amp;gt; Actions &amp;gt; Edit&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please find more information on the &lt;/SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/cloud-identity/cloud-identity-engine-getting-started/choose-directory-type/configure-a-cloud-based-directory/set-up-azure" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;techdocs page here&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Sat, 04 Jan 2025 01:19:14 GMT</pubDate>
    <dc:creator>jtmclaughlin</dc:creator>
    <dc:date>2025-01-04T01:19:14Z</dc:date>
    <item>
      <title>Cloud Identity Engine Introduces Group Filtering When Collecting Groups from Entra ID</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-identity-engine-articles/cloud-identity-engine-introduces-group-filtering-when-collecting/ta-p/590664</link>
      <description>&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-new-features/identity-features/cloud-identity-engine"&gt;&lt;SPAN&gt;Cloud Identity Engine (CIE)&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; now provides customers with the ability to select the groups they would like to synchronize with CIE from Entra ID (formerly Entra ID) by using filters.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Title_Cloud-Identity-Engine_palo-alto-networks.jpg" style="width: 960px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60576i311184DD8E34B73D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Title_Cloud-Identity-Engine_palo-alto-networks.jpg" alt="Title_Cloud-Identity-Engine_palo-alto-networks.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Jan 2025 01:19:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-identity-engine-articles/cloud-identity-engine-introduces-group-filtering-when-collecting/ta-p/590664</guid>
      <dc:creator>jtmclaughlin</dc:creator>
      <dc:date>2025-01-04T01:19:14Z</dc:date>
    </item>
  </channel>
</rss>

