<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Limiting Access to Office365 only in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/limiting-access-to-office365-only/m-p/543982#M111344</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/287536"&gt;@Ants&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The PANW EDL Hosting Service provides a way to identify O365 destinations and update them automatically as &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt; recommended.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/resources/edl-hosting-service" target="_blank"&gt;https://docs.paloaltonetworks.com/resources/edl-hosting-service&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Tue, 30 May 2023 15:28:29 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2023-05-30T15:28:29Z</dc:date>
    <item>
      <title>Limiting Access to Office365 only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/limiting-access-to-office365-only/m-p/543968#M111338</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;So we have a PA FW with PANOS 9.1.x&lt;/P&gt;
&lt;P&gt;We have a requirement for a specific inside vlan to have internet access to office365 only (teams,outlook etc etc)..&lt;/P&gt;
&lt;P&gt;tried with app-id using the office (365-enterprise-access and consumer) access to no avail, Suspect this did not work due to the FW not able to decrypt the ssl traffic.&lt;/P&gt;
&lt;P&gt;we also do not have EDL setup as yet.. might be the go option going forward.&lt;/P&gt;
&lt;P&gt;so the short workaround for now was to create a custom URL group list (*.microsoft.com,*.office.com etc)and allow it on the FWs&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;are there any other methods of doing this?&lt;/P&gt;
&lt;P&gt;I know for instance on Fortinet you can use internet services Database which is easy to configure. but PAN? not so much.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks in adv&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 13:54:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/limiting-access-to-office365-only/m-p/543968#M111338</guid>
      <dc:creator>Ants</dc:creator>
      <dc:date>2023-05-30T13:54:17Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting Access to Office365 only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/limiting-access-to-office365-only/m-p/543969#M111339</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/287536"&gt;@Ants&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;As soon as you want to limit application access you'll really want to push to get SSL decryption enabled and setup. That's the only way that the firewall can fully inspect traffic and allow for the use of app-id reliably; without that you'll be left using custom URL categories that you'll need to self maintain and keep updated.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I personally really recommend that you use EDLs for these exceptions when possible so that they can be dynamically updated without having to commit a change. Assuming you have anyone actively working on changes on the firewall that aren't ready to be committed, having a least a temporary EDL of domains can help bypass delays due to other pending changes.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 13:59:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/limiting-access-to-office365-only/m-p/543969#M111339</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-05-30T13:59:47Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting Access to Office365 only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/limiting-access-to-office365-only/m-p/543982#M111344</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/287536"&gt;@Ants&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The PANW EDL Hosting Service provides a way to identify O365 destinations and update them automatically as &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt; recommended.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/resources/edl-hosting-service" target="_blank"&gt;https://docs.paloaltonetworks.com/resources/edl-hosting-service&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 15:28:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/limiting-access-to-office365-only/m-p/543982#M111344</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-05-30T15:28:29Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting Access to Office365 only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/limiting-access-to-office365-only/m-p/543990#M111345</link>
      <description>&lt;P&gt;thanks for the feedback.. much appreciated.&lt;/P&gt;
&lt;P&gt;will look at implementing the EDL method for time being.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 15:41:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/limiting-access-to-office365-only/m-p/543990#M111345</guid>
      <dc:creator>Ants</dc:creator>
      <dc:date>2023-05-30T15:41:07Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting Access to Office365 only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/limiting-access-to-office365-only/m-p/543993#M111346</link>
      <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/287536"&gt;@Ants&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another way is to make use of the &lt;A href="https://endpoints.office.com/endpoints/worldwide" target="_blank" rel="noopener"&gt;Microsoft Endpoint List&lt;/A&gt; which is published weekly (and updated every Friday as far as I know) to create a custom EDL which can allow only parts of the O365 that you like.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 15:48:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/limiting-access-to-office365-only/m-p/543993#M111346</guid>
      <dc:creator>Alin.Scarlat</dc:creator>
      <dc:date>2023-05-30T15:48:53Z</dc:date>
    </item>
  </channel>
</rss>

