<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Prisma direct access to Azure in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/prisma-direct-access-to-azure/m-p/530557#M109482</link>
    <description>&lt;P&gt;yes - i am using Prisma access via Global Protect to connect from home for remote access.&amp;nbsp; I am using LDAP.&amp;nbsp; I have created a domain controller in the cloud and the Azure connection where it is hosted in the cloud has a site to site with my work Palo Alto fw.&amp;nbsp; Is their a way i can connect from prisma direct to the Azure cloud connection without tromboning into my network. ie is their some sort of prisma express route into azure&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 09 Feb 2023 21:50:24 GMT</pubDate>
    <dc:creator>ohareka</dc:creator>
    <dc:date>2023-02-09T21:50:24Z</dc:date>
    <item>
      <title>Prisma direct access to Azure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prisma-direct-access-to-azure/m-p/529926#M109368</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I connect from home via Prisma to on-prem.&amp;nbsp; I have a few domain controllers setup for pre-logon etc.&lt;/P&gt;
&lt;P&gt;- what if my domain controllers were all offline or the firewall was offline&lt;/P&gt;
&lt;P&gt;- can i have a domain controller in Azure&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have setup a site to site VPN from Azure to my firewall and can copy data across but dont know yet how to get my Prisma IP range to talk to it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Should i be concerned about tromboning (latency) if i did get the Prisma clients talking to Azure&lt;/P&gt;
&lt;P&gt;or should i be looking at something that allows Prisma to talk direct to Azure&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;any links to documents are welcome&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Feb 2023 20:23:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prisma-direct-access-to-azure/m-p/529926#M109368</guid>
      <dc:creator>ohareka</dc:creator>
      <dc:date>2023-02-05T20:23:56Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma direct access to Azure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prisma-direct-access-to-azure/m-p/530301#M109438</link>
      <description>&lt;P&gt;I assume you're talking about prims access?&lt;/P&gt;
&lt;P&gt;Are you currently using LDAP for authentication? If the SC connection is broken, or the ADs were to crash you will no longer be able to logon.&lt;/P&gt;
&lt;P&gt;You could consider switching to SAML which should be a little more resilient to failure (and as additional redundancy you could consider setting up a secondary portal, new feature in plugin 3.2.1, to still have LDAP available in case the SAML IdP were to die).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can set up an SC to your azure environment but ADS doesn't work with LDAP authentication so you'd need to switch to SAML anyway&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2023 12:21:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prisma-direct-access-to-azure/m-p/530301#M109438</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2023-02-08T12:21:55Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma direct access to Azure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prisma-direct-access-to-azure/m-p/530557#M109482</link>
      <description>&lt;P&gt;yes - i am using Prisma access via Global Protect to connect from home for remote access.&amp;nbsp; I am using LDAP.&amp;nbsp; I have created a domain controller in the cloud and the Azure connection where it is hosted in the cloud has a site to site with my work Palo Alto fw.&amp;nbsp; Is their a way i can connect from prisma direct to the Azure cloud connection without tromboning into my network. ie is their some sort of prisma express route into azure&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 21:50:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prisma-direct-access-to-azure/m-p/530557#M109482</guid>
      <dc:creator>ohareka</dc:creator>
      <dc:date>2023-02-09T21:50:24Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma direct access to Azure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prisma-direct-access-to-azure/m-p/541513#M110991</link>
      <description>&lt;P&gt;Also except SAML with the cloud identity engine SCIM is also an option and for on-prem AD the CIE has an agent:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cloud-identity/cloud-identity-engine-getting-started/choose-directory-type/configure-an-on-premises-directory" target="_blank"&gt;https://docs.paloaltonetworks.com/cloud-identity/cloud-identity-engine-getting-started/choose-directory-type/configure-an-on-premises-directory&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cloud-identity/cloud-identity-engine-getting-started/choose-directory-type/configure-a-cloud-based-directory" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cloud-identity/cloud-identity-engine-getting-started/choose-directory-type/configure-a-cloud-based-directory&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 07:31:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prisma-direct-access-to-azure/m-p/541513#M110991</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2023-05-09T07:31:14Z</dc:date>
    </item>
  </channel>
</rss>

