<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CIEM JIT Features in Prisma Cloud Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/ciem-jit-features/m-p/566406#M1108</link>
    <description>&lt;P&gt;Hi Rajnishnsit2000,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Prisma Cloud CIEM is purpose-built to directly solve the challenges of managing permissions across AWS, Azure, and GCP. Prisma Cloud CIEM automatically calculates users' effective permissions across cloud service providers, detects overly permissive access, and suggests corrections to reach least privilege.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Specific to your question about zero standing access to AWS, &lt;BR /&gt;On a high level, Prisma Cloud's CIEM Module consists of 3 Pillars (Source, Granter, and Destination). The module integrates with identity provider (IdP) services like AWS IAM Identity Center and Okta to ingest single sign-on (SSO) data. It allows identities to request temporary access to resources on an as-needed basis, reducing the risk of having long-lasting unused permissions. With the JIT functionality, users and machine identities can be granted access only when they need it and for a limited time, reducing the overall attack surface and exposure of critical resources to potential threats. For example a user/machine may need to perform a job only at 9:30 am for 30mins. With JIT, you make sure that user/machine has a role that allow access only during that time and for that duration.&lt;/P&gt;
&lt;P&gt;To learn more about Zero Standing Privileges (ZSP)? (And How They Work): &lt;A href="https://www.strongdm.com/blog/zero-standing-privileges" target="_blank"&gt;https://www.strongdm.com/blog/zero-standing-privileges&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;References/Resources:&lt;/STRONG&gt;&amp;nbsp; &amp;nbsp;You can find some great detailed resources about Prisma Cloud CIEM module here at the following links:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;A href="https://live.paloaltonetworks.com/t5/prisma-cloud-articles/leveraging-prisma-cloud-to-enforce-least-privilege/ta-p/558174" target="_blank"&gt;https://live.paloaltonetworks.com/t5/prisma-cloud-articles/leveraging-prisma-cloud-to-enforce-least-privilege/ta-p/558174&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://live.paloaltonetworks.com/t5/prisma-cloud-videos/february-2023-ciem-the-simple-way-to-secure-your-cloud-identity/ta-p/532724" target="_blank"&gt;https://live.paloaltonetworks.com/t5/prisma-cloud-videos/february-2023-ciem-the-simple-way-to-secure-your-cloud-identity/ta-p/532724&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.paloaltonetworks.com/prisma/cloud/cloud-infrastructure-entitlement-mgmt" target="_blank"&gt;https://www.paloaltonetworks.com/prisma/cloud/cloud-infrastructure-entitlement-mgmt&lt;/A&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Let us know us if this helps with your inquiry, or if you have further questions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;</description>
    <pubDate>Mon, 20 Nov 2023 23:13:56 GMT</pubDate>
    <dc:creator>WLejulus</dc:creator>
    <dc:date>2023-11-20T23:13:56Z</dc:date>
    <item>
      <title>CIEM JIT Features</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/ciem-jit-features/m-p/566305#M1106</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;Can I check where can I find out more details on the CIEM JIT functionality?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/prisma/cloud/cloud-infrastructure-entitlement-mgmt" target="_blank"&gt;https://www.paloaltonetworks.com/prisma/cloud/cloud-infrastructure-entitlement-mgmt&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;"&lt;SPAN&gt;Just-in-Time (JIT) Access&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="display-2 large"&gt;Provides a Zero Trust approach to permission management by limiting access to resources based on specific time-limited permissions. Users and machine identities can be granted access only when they need it and for a limited time, reducing the overall attack surface and exposure of critical resources to potential threats.&lt;/P&gt;
&lt;UL class="check-list"&gt;
&lt;LI class="check-list-item"&gt;
&lt;H4 class="check-list-item-title"&gt;Utilize zero standing privileges:Allows identities to request temporary access to resources on an as-needed basis, reducing the risk of having long-lasting unused permissions.&lt;/H4&gt;
&lt;/LI&gt;
&lt;LI class="check-list-item"&gt;
&lt;H4 class="check-list-item-title"&gt;Automate or manually approve access: Enables both automatic and manual approval based on the organization configurations.&lt;/H4&gt;
&lt;/LI&gt;
&lt;LI class="check-list-item"&gt;
&lt;H4 class="check-list-item-title"&gt;Active monitoring:Visibility into active sessions — with the ability to kill unwanted sessions in real time."&lt;/H4&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How it plans to provide Zero standing access for AWS IAM identity center and other cloud providers.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Raj&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 05:07:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/ciem-jit-features/m-p/566305#M1106</guid>
      <dc:creator>rajnishnsit2000</dc:creator>
      <dc:date>2023-11-20T05:07:47Z</dc:date>
    </item>
    <item>
      <title>Re: CIEM JIT Features</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/ciem-jit-features/m-p/566406#M1108</link>
      <description>&lt;P&gt;Hi Rajnishnsit2000,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Prisma Cloud CIEM is purpose-built to directly solve the challenges of managing permissions across AWS, Azure, and GCP. Prisma Cloud CIEM automatically calculates users' effective permissions across cloud service providers, detects overly permissive access, and suggests corrections to reach least privilege.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Specific to your question about zero standing access to AWS, &lt;BR /&gt;On a high level, Prisma Cloud's CIEM Module consists of 3 Pillars (Source, Granter, and Destination). The module integrates with identity provider (IdP) services like AWS IAM Identity Center and Okta to ingest single sign-on (SSO) data. It allows identities to request temporary access to resources on an as-needed basis, reducing the risk of having long-lasting unused permissions. With the JIT functionality, users and machine identities can be granted access only when they need it and for a limited time, reducing the overall attack surface and exposure of critical resources to potential threats. For example a user/machine may need to perform a job only at 9:30 am for 30mins. With JIT, you make sure that user/machine has a role that allow access only during that time and for that duration.&lt;/P&gt;
&lt;P&gt;To learn more about Zero Standing Privileges (ZSP)? (And How They Work): &lt;A href="https://www.strongdm.com/blog/zero-standing-privileges" target="_blank"&gt;https://www.strongdm.com/blog/zero-standing-privileges&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;References/Resources:&lt;/STRONG&gt;&amp;nbsp; &amp;nbsp;You can find some great detailed resources about Prisma Cloud CIEM module here at the following links:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;A href="https://live.paloaltonetworks.com/t5/prisma-cloud-articles/leveraging-prisma-cloud-to-enforce-least-privilege/ta-p/558174" target="_blank"&gt;https://live.paloaltonetworks.com/t5/prisma-cloud-articles/leveraging-prisma-cloud-to-enforce-least-privilege/ta-p/558174&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://live.paloaltonetworks.com/t5/prisma-cloud-videos/february-2023-ciem-the-simple-way-to-secure-your-cloud-identity/ta-p/532724" target="_blank"&gt;https://live.paloaltonetworks.com/t5/prisma-cloud-videos/february-2023-ciem-the-simple-way-to-secure-your-cloud-identity/ta-p/532724&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.paloaltonetworks.com/prisma/cloud/cloud-infrastructure-entitlement-mgmt" target="_blank"&gt;https://www.paloaltonetworks.com/prisma/cloud/cloud-infrastructure-entitlement-mgmt&lt;/A&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Let us know us if this helps with your inquiry, or if you have further questions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 23:13:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/ciem-jit-features/m-p/566406#M1108</guid>
      <dc:creator>WLejulus</dc:creator>
      <dc:date>2023-11-20T23:13:56Z</dc:date>
    </item>
    <item>
      <title>Re: CIEM JIT Features</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/ciem-jit-features/m-p/566416#M1109</link>
      <description>&lt;P&gt;Hi Wlejulus,&lt;/P&gt;
&lt;P&gt;Thanks a lot for providing all the details.&lt;/P&gt;
&lt;P&gt;Does Palo Alto CIEM covers all the 3 major cloud providers AWS, Azure &amp;amp; GCP?&lt;/P&gt;
&lt;P&gt;And do you have some more config details around this specific zero standing privileges feature set?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Raj&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 02:49:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/ciem-jit-features/m-p/566416#M1109</guid>
      <dc:creator>rajnishnsit2000</dc:creator>
      <dc:date>2023-11-21T02:49:01Z</dc:date>
    </item>
    <item>
      <title>Re: CIEM JIT Features</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/ciem-jit-features/m-p/569791#M1124</link>
      <description>&lt;P&gt;Hi Raj,&lt;/P&gt;
&lt;P&gt;Yes,&amp;nbsp; AWS, Azure, and GCP are supported for CIEM.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Zero Standing Privileges is a&amp;nbsp;concept of requiring users to obtain access as needed and when needed instead of granting continuous access rights.&amp;nbsp; More config details can be found here:&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.paloaltonetworks.com/prisma/cloud/cloud-infrastructure-entitlement-mgmt" target="_blank"&gt;https://www.paloaltonetworks.com/prisma/cloud/cloud-infrastructure-entitlement-mgmt&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://live.paloaltonetworks.com/t5/prisma-cloud-articles/leveraging-prisma-cloud-to-enforce-least-privilege/ta-p/558174" target="_blank"&gt;https://live.paloaltonetworks.com/t5/prisma-cloud-articles/leveraging-prisma-cloud-to-enforce-least-privilege/ta-p/558174&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 22:11:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/ciem-jit-features/m-p/569791#M1124</guid>
      <dc:creator>WLejulus</dc:creator>
      <dc:date>2023-12-13T22:11:14Z</dc:date>
    </item>
  </channel>
</rss>

