<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article How the EDL Hosting Service Helps to Safely Enable M365 in Prisma Access Cloud Management Articles</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-cloud-management/how-the-edl-hosting-service-helps-to-safely-enable-m365/ta-p/408765</link>
    <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;Many SaaS Applications, Microsoft 365 being one great example, publish a list of endpoints that firewall rules must allow connectivity to in order for the services to function properly.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;As part of our security best practices, we have always recommended that a security policy should not only restrict access based on App-ID (for example, ms-office365), but also by the application’s destination endpoints (ip/domains).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;However, the endpoint list in some cases is dynamic ( Microsoft updates its M365 endpoints on a periodic basis).&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;Keeping up with the changes and updating your policies in accordance with that becomes challenging. And that often leads to administrators configuring the policy with a destination of “any” and loosening up the access.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;Additionally, there might be&amp;nbsp; cases where you want to preferentially treat traffic going to certain endpoints. Examples would be bypassing SSL decryption for Optimized endpoints as Microsoft recommends &lt;/SPAN&gt;&lt;A href="https://docs.microsoft.com/en-us/microsoft-365/enterprise/microsoft-365-network-connectivity-principles?view=o365-worldwide#new-office-365-endpoint-categories" target="_blank" rel="noopener"&gt;&lt;SPAN style="font-weight: 400;"&gt;here&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="font-weight: 400;"&gt; or providing QoS priority to ‘OneDrive’ endpoints.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;Again, the challenge to keep up with the changing endpoint list remains.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4&gt;&lt;SPAN style="font-weight: 400;"&gt;External Dynamic Lists&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;PAN-OS has always had support for External Dynamic Lists (EDLs) which are tailor-made for such use cases. EDLs are configurable objects on PAN-OS that can be referenced within policies to represent a list of IPs (or URLs). The list membership is dynamic and PAN-OS will, based on a configurable frequency, check for updates to the list from the specified source to keep the object updated.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Now all we need is a “source” from which endpoint lists can be consumed.&lt;/STRONG&gt;&lt;/P&gt;
&lt;H2&gt;&amp;nbsp;&lt;/H2&gt;
&lt;H2&gt;&lt;SPAN style="font-weight: 400;"&gt;Introducing the EDL Hosting Service&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;EDL Hosting Service is a globally available Palo Alto Networks-managed service that hosts&amp;nbsp; curated lists which can be consumed by any Palo Alto Networks NGFW (including Prisma Access) in the form of EDLs. An admin only has to configure the EDL and point it to a source URL the EDL Hosting Service provides for the feed of interest. This is a one-time setup.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;With the current release, the service provides hosting for All &lt;/SPAN&gt;&lt;STRONG&gt;Microsoft 365&lt;/STRONG&gt;&lt;SPAN style="font-weight: 400;"&gt; endpoints organized into categories you can easily scan and choose from based on what’s relevant to you.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;EDLs also provide support for adding your custom exceptions to these lists and give you full control.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;The service keeps up with all updates from Microsoft and categorizes the feeds into multiple lists based on either the:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;&lt;I&gt;Region&lt;/I&gt;&lt;/STRONG&gt;&lt;SPAN style="font-weight: 400;"&gt;: Worldwide, Germany, 21 Vianet (China), US Gov DoD, US Gov GCC-High&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;&lt;I&gt;Service Areas&lt;/I&gt;&lt;/STRONG&gt;&lt;SPAN style="font-weight: 400;"&gt;: Exchange Online, Sharepoint and OneDrive, Skype and Teams, Any (includes all service areas)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;&lt;I&gt;Category&lt;/I&gt;&lt;/STRONG&gt;&lt;SPAN style="font-weight: 400;"&gt;: Optimize, Allow, Default, All (includes all three categories)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;&lt;I&gt;Type&lt;/I&gt;&lt;/STRONG&gt;&lt;SPAN style="font-weight: 400;"&gt;: IPv4, IPv6, URL&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;The EDLs automatically stay updated from the hosted feeds,and policies do not have to be touched once configured.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;You can refer to the documentation &lt;/SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/resources/edl-hosting-service.html" target="_blank" rel="noopener"&gt;&lt;SPAN style="font-weight: 400;"&gt;here&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="font-weight: 400;"&gt; for more details on how to leverage this service in helping you safely enable Microsoft 365.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Thu, 27 May 2021 21:48:53 GMT</pubDate>
    <dc:creator>dhshah</dc:creator>
    <dc:date>2021-05-27T21:48:53Z</dc:date>
    <item>
      <title>How the EDL Hosting Service Helps to Safely Enable M365</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-cloud-management/how-the-edl-hosting-service-helps-to-safely-enable-m365/ta-p/408765</link>
      <description>&lt;P&gt;Check out how the newly introduced EDL Hosting service can help with safely enabling Microsoft 365 in your environment.&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 21:48:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-cloud-management/how-the-edl-hosting-service-helps-to-safely-enable-m365/ta-p/408765</guid>
      <dc:creator>dhshah</dc:creator>
      <dc:date>2021-05-27T21:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: How the EDL Hosting Service Helps to Safely Enable M365</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-cloud-management/how-the-edl-hosting-service-helps-to-safely-enable-m365/tac-p/1223791#M10</link>
      <description>&lt;P&gt;is there any option to select US region specifically&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 17:17:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-cloud-management/how-the-edl-hosting-service-helps-to-safely-enable-m365/tac-p/1223791#M10</guid>
      <dc:creator>spavanilatha</dc:creator>
      <dc:date>2025-03-13T17:17:51Z</dc:date>
    </item>
  </channel>
</rss>

