<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cloud Identity Engine - CIE in Cortex XSIAM Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cloud-identity-engine-cie/m-p/1255630#M421</link>
    <description>&lt;P data-end="650" data-start="647"&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1401872841"&gt;@A.Velusamy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="650" data-start="647"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="938" data-start="652"&gt;We are currently using &lt;STRONG data-end="706" data-start="675"&gt;Cloud Identity Engine (CIE)&lt;/STRONG&gt; in our XSIAM environment, and it has been very useful. One of the main benefits is the additional identity context that becomes visible within incidents and alerts, which helps analysts investigate security events more efficiently.&lt;/P&gt;
&lt;P data-end="1267" data-start="940"&gt;We have integrated CIE with &lt;STRONG data-end="988" data-start="968"&gt;Active Directory&lt;/STRONG&gt;, and it provides valuable visibility into user identities, group memberships, authentication activities, and associated assets. We have also developed correlation rules based on identity-related logs, which help us better understand user activity and improve detection coverage.&lt;/P&gt;
&lt;P data-end="1267" data-start="940"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="1573" data-start="1269"&gt;In addition to Active Directory, CIE supports integrations with cloud identity providers such as &lt;STRONG data-end="1399" data-start="1366"&gt;Microsoft Entra ID (Azure AD)&lt;/STRONG&gt;, &lt;STRONG data-end="1409" data-start="1401"&gt;Okta&lt;/STRONG&gt;, and other identity sources. This enables XSIAM to correlate user activity across both on-premises and cloud environments, providing a more complete identity view.&lt;/P&gt;
&lt;P data-end="1573" data-start="1269"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="1727" data-start="1575"&gt;The identity data collected through CIE is leveraged by XSIAM analytics and detection logic to identify suspicious and anomalous user behavior, such as:&lt;/P&gt;
&lt;UL data-end="1943" data-start="1728"&gt;
&lt;LI data-end="1761" data-start="1728" data-section-id="k0dfrq"&gt;Unusual authentication patterns&lt;/LI&gt;
&lt;LI data-end="1795" data-start="1762" data-section-id="fn4wux"&gt;Privilege escalation activities&lt;/LI&gt;
&lt;LI data-end="1821" data-start="1796" data-section-id="n8p8je"&gt;Excessive failed logins&lt;/LI&gt;
&lt;LI data-end="1851" data-start="1822" data-section-id="1ubbar8"&gt;Impossible travel scenarios&lt;/LI&gt;
&lt;LI data-end="1892" data-start="1852" data-section-id="bbronm"&gt;Abnormal access to sensitive resources&lt;/LI&gt;
&lt;LI data-end="1943" data-start="1893" data-section-id="1qwr3oa"&gt;Suspicious account usage across multiple systems&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="1991" data-start="1945"&gt;Overall, we have found CIE to be valuable for:&lt;/P&gt;
&lt;UL data-end="2477" data-start="1993"&gt;
&lt;LI data-end="2044" data-start="1993" data-section-id="4iivmc"&gt;Enhanced incident visibility and identity context&lt;/LI&gt;
&lt;LI data-end="2108" data-start="2045" data-section-id="eijrxi"&gt;Active Directory, Entra ID, and Okta user activity monitoring&lt;/LI&gt;
&lt;LI data-end="2158" data-start="2109" data-section-id="11hignk"&gt;Identity-based correlation rules and detections&lt;/LI&gt;
&lt;LI data-end="2191" data-start="2159" data-section-id="a5ddxc"&gt;Improved user-to-asset mapping&lt;/LI&gt;
&lt;LI data-end="2247" data-start="2192" data-section-id="bmna3j"&gt;Better detection of suspicious and anomalous behavior&lt;/LI&gt;
&lt;LI data-end="2299" data-start="2248" data-section-id="htrpzd"&gt;Faster and more effective incident investigations&lt;/LI&gt;
&lt;LI data-end="2356" data-start="2300" data-section-id="19ax6nn"&gt;Improved identity threat detection and response (ITDR)&lt;/LI&gt;
&lt;LI data-end="2417" data-start="2357" data-section-id="e2wtcl"&gt;Better risk-based analysis and user-centric investigations&lt;/LI&gt;
&lt;LI data-end="2477" data-start="2418" data-section-id="htakb8"&gt;Centralized visibility across multiple identity providers&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="2771" data-start="2479"&gt;In our experience, enabling CIE significantly improves the quality of investigations by providing richer identity context and helping analysts quickly understand who is behind an activity, what systems they have access to, and whether the observed behavior is normal or potentially malicious.&lt;/P&gt;
&lt;P data-end="2771" data-start="2479"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please help out other users and “Accept as Solution” if a post helps solve your problem !&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/blogs/how-and-why-to-accept-solutions/ba-p/553827" target="_blank"&gt;Read more about how and why to accept solutions.&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-end="2771" data-start="2479"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="2771" data-start="2479"&gt;&lt;SPAN&gt;Best Regards,&lt;BR /&gt;Vinothkumar.C&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-end="2771" data-start="2479"&gt;SBA Info Solutions pvt ltd - Chennai.&lt;/P&gt;</description>
    <pubDate>Mon, 08 Jun 2026 11:40:07 GMT</pubDate>
    <dc:creator>Vinothkumar_SBA</dc:creator>
    <dc:date>2026-06-08T11:40:07Z</dc:date>
    <item>
      <title>Cloud Identity Engine - CIE</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cloud-identity-engine-cie/m-p/1255525#M419</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Is anyone using Cloud Identity Engine in XSIAM? How useful is it, and could you share your use case and experience?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2026 18:18:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cloud-identity-engine-cie/m-p/1255525#M419</guid>
      <dc:creator>A.Velusamy</dc:creator>
      <dc:date>2026-06-05T18:18:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cloud Identity Engine - CIE</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cloud-identity-engine-cie/m-p/1255630#M421</link>
      <description>&lt;P data-end="650" data-start="647"&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1401872841"&gt;@A.Velusamy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="650" data-start="647"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="938" data-start="652"&gt;We are currently using &lt;STRONG data-end="706" data-start="675"&gt;Cloud Identity Engine (CIE)&lt;/STRONG&gt; in our XSIAM environment, and it has been very useful. One of the main benefits is the additional identity context that becomes visible within incidents and alerts, which helps analysts investigate security events more efficiently.&lt;/P&gt;
&lt;P data-end="1267" data-start="940"&gt;We have integrated CIE with &lt;STRONG data-end="988" data-start="968"&gt;Active Directory&lt;/STRONG&gt;, and it provides valuable visibility into user identities, group memberships, authentication activities, and associated assets. We have also developed correlation rules based on identity-related logs, which help us better understand user activity and improve detection coverage.&lt;/P&gt;
&lt;P data-end="1267" data-start="940"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="1573" data-start="1269"&gt;In addition to Active Directory, CIE supports integrations with cloud identity providers such as &lt;STRONG data-end="1399" data-start="1366"&gt;Microsoft Entra ID (Azure AD)&lt;/STRONG&gt;, &lt;STRONG data-end="1409" data-start="1401"&gt;Okta&lt;/STRONG&gt;, and other identity sources. This enables XSIAM to correlate user activity across both on-premises and cloud environments, providing a more complete identity view.&lt;/P&gt;
&lt;P data-end="1573" data-start="1269"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="1727" data-start="1575"&gt;The identity data collected through CIE is leveraged by XSIAM analytics and detection logic to identify suspicious and anomalous user behavior, such as:&lt;/P&gt;
&lt;UL data-end="1943" data-start="1728"&gt;
&lt;LI data-end="1761" data-start="1728" data-section-id="k0dfrq"&gt;Unusual authentication patterns&lt;/LI&gt;
&lt;LI data-end="1795" data-start="1762" data-section-id="fn4wux"&gt;Privilege escalation activities&lt;/LI&gt;
&lt;LI data-end="1821" data-start="1796" data-section-id="n8p8je"&gt;Excessive failed logins&lt;/LI&gt;
&lt;LI data-end="1851" data-start="1822" data-section-id="1ubbar8"&gt;Impossible travel scenarios&lt;/LI&gt;
&lt;LI data-end="1892" data-start="1852" data-section-id="bbronm"&gt;Abnormal access to sensitive resources&lt;/LI&gt;
&lt;LI data-end="1943" data-start="1893" data-section-id="1qwr3oa"&gt;Suspicious account usage across multiple systems&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="1991" data-start="1945"&gt;Overall, we have found CIE to be valuable for:&lt;/P&gt;
&lt;UL data-end="2477" data-start="1993"&gt;
&lt;LI data-end="2044" data-start="1993" data-section-id="4iivmc"&gt;Enhanced incident visibility and identity context&lt;/LI&gt;
&lt;LI data-end="2108" data-start="2045" data-section-id="eijrxi"&gt;Active Directory, Entra ID, and Okta user activity monitoring&lt;/LI&gt;
&lt;LI data-end="2158" data-start="2109" data-section-id="11hignk"&gt;Identity-based correlation rules and detections&lt;/LI&gt;
&lt;LI data-end="2191" data-start="2159" data-section-id="a5ddxc"&gt;Improved user-to-asset mapping&lt;/LI&gt;
&lt;LI data-end="2247" data-start="2192" data-section-id="bmna3j"&gt;Better detection of suspicious and anomalous behavior&lt;/LI&gt;
&lt;LI data-end="2299" data-start="2248" data-section-id="htrpzd"&gt;Faster and more effective incident investigations&lt;/LI&gt;
&lt;LI data-end="2356" data-start="2300" data-section-id="19ax6nn"&gt;Improved identity threat detection and response (ITDR)&lt;/LI&gt;
&lt;LI data-end="2417" data-start="2357" data-section-id="e2wtcl"&gt;Better risk-based analysis and user-centric investigations&lt;/LI&gt;
&lt;LI data-end="2477" data-start="2418" data-section-id="htakb8"&gt;Centralized visibility across multiple identity providers&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="2771" data-start="2479"&gt;In our experience, enabling CIE significantly improves the quality of investigations by providing richer identity context and helping analysts quickly understand who is behind an activity, what systems they have access to, and whether the observed behavior is normal or potentially malicious.&lt;/P&gt;
&lt;P data-end="2771" data-start="2479"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please help out other users and “Accept as Solution” if a post helps solve your problem !&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/blogs/how-and-why-to-accept-solutions/ba-p/553827" target="_blank"&gt;Read more about how and why to accept solutions.&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-end="2771" data-start="2479"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="2771" data-start="2479"&gt;&lt;SPAN&gt;Best Regards,&lt;BR /&gt;Vinothkumar.C&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-end="2771" data-start="2479"&gt;SBA Info Solutions pvt ltd - Chennai.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2026 11:40:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cloud-identity-engine-cie/m-p/1255630#M421</guid>
      <dc:creator>Vinothkumar_SBA</dc:creator>
      <dc:date>2026-06-08T11:40:07Z</dc:date>
    </item>
  </channel>
</rss>

