<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Use HIP to deny logon to PA with exception in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/use-hip-to-deny-logon-to-pa-with-exception/m-p/425517#M237</link>
    <description>&lt;P&gt;Also before that make a rule with the correct groups so that you don't match the blocking rule:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClXWCA0" target="_blank"&gt;How to Add Groups or Users to Security Policy - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Aug 2021 13:06:40 GMT</pubDate>
    <dc:creator>nikoolayy1</dc:creator>
    <dc:date>2021-08-09T13:06:40Z</dc:date>
    <item>
      <title>Use HIP to deny logon to PA with exception</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/use-hip-to-deny-logon-to-pa-with-exception/m-p/408338#M195</link>
      <description>&lt;P&gt;Has anyone effectively used HIP to deny login to Prisma Access? One of the biggest challenges we had with AnyConnect (and a large reason we are moving away) is that there were no native methods for controlling which device a user was connecting with.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have built a Security Pre-Rule that references the Domain-joined HIP Policy, and I can see the matches in our monitor tab. I would like to deny logon to anyone who does not satisfy this rule EXCEPT those who are members of a specific Active Directory user group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I figure the rules would look something like this:&lt;/P&gt;&lt;P&gt;1) HIP Match on domain = allowed to connect to Portal URL&lt;/P&gt;&lt;P&gt;2) Match on security group membership = allowed to connect to Portal URL&lt;/P&gt;&lt;P&gt;3) Deny all connections to Portal URL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone confirm that this would be effective?&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 15:46:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/use-hip-to-deny-logon-to-pa-with-exception/m-p/408338#M195</guid>
      <dc:creator>Thrace</dc:creator>
      <dc:date>2021-05-21T15:46:28Z</dc:date>
    </item>
    <item>
      <title>Re: Use HIP to deny logon to PA with exception</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/use-hip-to-deny-logon-to-pa-with-exception/m-p/425102#M232</link>
      <description>&lt;P&gt;Have you checked the article below?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/redistribute-hip-information-and-run-hip-reports.html" target="_blank"&gt;https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/redistribute-hip-information-and-run-hip-reports.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For using HIP in the security policy :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/host-information/configure-hip-based-policy-enforcement.html" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/host-information/configure-hip-based-policy-enforcement.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Aug 2021 12:33:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/use-hip-to-deny-logon-to-pa-with-exception/m-p/425102#M232</guid>
      <dc:creator>NikolayDimitrov</dc:creator>
      <dc:date>2021-08-06T12:33:01Z</dc:date>
    </item>
    <item>
      <title>Re: Use HIP to deny logon to PA with exception</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/use-hip-to-deny-logon-to-pa-with-exception/m-p/425517#M237</link>
      <description>&lt;P&gt;Also before that make a rule with the correct groups so that you don't match the blocking rule:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClXWCA0" target="_blank"&gt;How to Add Groups or Users to Security Policy - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 13:06:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/use-hip-to-deny-logon-to-pa-with-exception/m-p/425517#M237</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-08-09T13:06:40Z</dc:date>
    </item>
  </channel>
</rss>

