<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Prisma Access HIP object Windows patch management in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/prisma-access-hip-object-windows-patch-management/m-p/1260836#M126819</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1555920647"&gt;@K.Herath&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The patch severity values are:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;0 = Low&lt;/P&gt;
&lt;P&gt;1 = Moderate&lt;/P&gt;
&lt;P&gt;2 = Important&lt;/P&gt;
&lt;P&gt;3 = Critical.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So your current setting of Greater Than or Equal To 3 is correct if you want the HIP object to match endpoints with missing Critical patches.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Check options evaluate the missing patches reported by the endpoint:&lt;/P&gt;
&lt;P&gt;has-any:&amp;nbsp;Matches when the endpoint is missing any patch that meets the configured criteria.&lt;/P&gt;
&lt;P&gt;has-none:&amp;nbsp;Matches when none of the configured patch entries are reported as missing.&lt;/P&gt;
&lt;P&gt;has-all:&amp;nbsp;Matches when all configured patch entries are reported as missing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="896" data-start="744"&gt;When the Item Table is populated, the Check selection is evaluated against the patches entered in that table, together with the configured severity.&lt;/P&gt;
&lt;P data-end="896" data-start="744"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="988" data-start="898"&gt;When the Item Table is empty, the severity becomes the primary condition. For example:&lt;/P&gt;
&lt;P data-end="988" data-start="898"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Severity: Greater Than or Equal To 3&lt;/P&gt;
&lt;P&gt;Check: has-any&lt;/P&gt;
&lt;P&gt;Item Table: empty&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="1162" data-start="1079"&gt;This should match a Windows endpoint reporting at least one missing Critical patch.&lt;/P&gt;
&lt;P data-end="1162" data-start="1079"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="1311" data-start="1164"&gt;To block those endpoints, add the HIP object to a HIP profile and reference that profile in a deny security policy above the applicable allow rule.&lt;/P&gt;
&lt;P data-is-only-node="" data-is-last-node="" data-end="1454" data-start="1313"&gt;I would recommend validating the behavior first using the endpoint’s HIP report and the HIP Match logs before applying the deny rule broadly.&lt;/P&gt;</description>
    <pubDate>Tue, 04 Aug 2026 04:01:28 GMT</pubDate>
    <dc:creator>JayGolf</dc:creator>
    <dc:date>2026-08-04T04:01:28Z</dc:date>
    <item>
      <title>Prisma Access HIP object Windows patch management</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prisma-access-hip-object-windows-patch-management/m-p/1260261#M126802</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We have created a HIP profile and configured windows patch management. However, the options under this is not very clear. I have to get some clarifications on this&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Missing Patches - Severity&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL style="direction: ltr; unicode-bidi: embed; margin-top: 0in; margin-bottom: 0in; font-family: Aptos; font-size: 12.0pt; font-weight: normal; font-style: normal;" type="1"&gt;
&lt;OL style="direction: ltr; unicode-bidi: embed; margin-top: 0in; margin-bottom: 0in; font-family: Aptos; font-size: 12.0pt; font-weight: normal; font-style: normal;" type="a"&gt;
&lt;LI style="margin-top: 0; margin-bottom: 0; vertical-align: middle; color: #242424;" value="1"&gt;&lt;SPAN&gt;When the operator is set to Greater Than or Equal To, what values are valid in the field?&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="margin-top: 0; margin-bottom: 0; vertical-align: middle; color: #242424;"&gt;&lt;SPAN&gt;We currently use 3, assuming this represents Critical Windows security patches. Please clarify whether this is correct and what the other values represent.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="margin-top: 0; margin-bottom: 0; vertical-align: middle; color: #242424;"&gt;&lt;SPAN&gt;What do each of the three options in the Check drop-down mean?&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="margin-top: 0; margin-bottom: 0; vertical-align: middle; color: #242424;"&gt;&lt;SPAN&gt;How does each option behave when the Item Table is populated or left empty?&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;STRONG&gt;Enforcement outcome&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL style="direction: ltr; unicode-bidi: embed; margin-top: 0in; margin-bottom: 0in; font-family: Aptos; font-size: 12.0pt; font-weight: normal; font-style: normal;" type="a"&gt;
&lt;LI style="margin-top: 0; margin-bottom: 0; vertical-align: middle; color: #242424;" value="1"&gt;&lt;SPAN&gt;If the HIP profile is attached to a deny security policy, which combinations would block a Windows endpoint with missing Critical security patches?&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="margin-top: 0; margin-bottom: 0; vertical-align: middle; color: #242424;"&gt;&lt;SPAN&gt;What other useful enforcement outcomes can be achieved through different combinations of these settings?&lt;BR /&gt;&lt;BR /&gt;&lt;LI-PRODUCT title="GlobalProtect" id="GlobalProtect"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="Prisma Access" id="Prisma_Access"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/OL&gt;</description>
      <pubDate>Wed, 29 Jul 2026 00:41:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prisma-access-hip-object-windows-patch-management/m-p/1260261#M126802</guid>
      <dc:creator>K.Herath</dc:creator>
      <dc:date>2026-07-29T00:41:24Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Access HIP object Windows patch management</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prisma-access-hip-object-windows-patch-management/m-p/1260836#M126819</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1555920647"&gt;@K.Herath&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The patch severity values are:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;0 = Low&lt;/P&gt;
&lt;P&gt;1 = Moderate&lt;/P&gt;
&lt;P&gt;2 = Important&lt;/P&gt;
&lt;P&gt;3 = Critical.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So your current setting of Greater Than or Equal To 3 is correct if you want the HIP object to match endpoints with missing Critical patches.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Check options evaluate the missing patches reported by the endpoint:&lt;/P&gt;
&lt;P&gt;has-any:&amp;nbsp;Matches when the endpoint is missing any patch that meets the configured criteria.&lt;/P&gt;
&lt;P&gt;has-none:&amp;nbsp;Matches when none of the configured patch entries are reported as missing.&lt;/P&gt;
&lt;P&gt;has-all:&amp;nbsp;Matches when all configured patch entries are reported as missing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="896" data-start="744"&gt;When the Item Table is populated, the Check selection is evaluated against the patches entered in that table, together with the configured severity.&lt;/P&gt;
&lt;P data-end="896" data-start="744"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="988" data-start="898"&gt;When the Item Table is empty, the severity becomes the primary condition. For example:&lt;/P&gt;
&lt;P data-end="988" data-start="898"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Severity: Greater Than or Equal To 3&lt;/P&gt;
&lt;P&gt;Check: has-any&lt;/P&gt;
&lt;P&gt;Item Table: empty&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="1162" data-start="1079"&gt;This should match a Windows endpoint reporting at least one missing Critical patch.&lt;/P&gt;
&lt;P data-end="1162" data-start="1079"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="1311" data-start="1164"&gt;To block those endpoints, add the HIP object to a HIP profile and reference that profile in a deny security policy above the applicable allow rule.&lt;/P&gt;
&lt;P data-is-only-node="" data-is-last-node="" data-end="1454" data-start="1313"&gt;I would recommend validating the behavior first using the endpoint’s HIP report and the HIP Match logs before applying the deny rule broadly.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2026 04:01:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prisma-access-hip-object-windows-patch-management/m-p/1260836#M126819</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2026-08-04T04:01:28Z</dc:date>
    </item>
  </channel>
</rss>

