- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
on 07-21-2023 07:23 AM - edited on 07-21-2023 10:41 AM by jforsythe
Palo Alto Networks, a leading cybersecurity company, has recently partnered with Chrome Enterprise, Google's business-focused solution for Chrome devices. This integration aims to enhance IT infrastructure management, improve application security, and streamline user access. By combining the capabilities of Palo Alto Networks' solutions with Chrome Enterprise's robust features, organizations can achieve a safer workforce and a more efficient enterprise environment.
The integration between Palo Alto Networks and Chrome Enterprise represents a significant advancement in IT infrastructure management and security. By enabling centralized device management, enhancing security visibility, and providing a seamless user experience, this partnership empowers enterprises to protect their workforce and data more effectively. With the Connectors Framework and Reporting Connectors, security investigations become more efficient, enabling proactive threat detection and automated incident response. As organizations embrace the Chrome Enterprise Connection program, they can leverage the power of Palo Alto Networks' solutions to strengthen their security posture and streamline operations in an ever-evolving threat landscape.
Through this partnership, customers gain the ability to centrally manage their IT infrastructure endpoints. Managed devices, including MacOS, Linux, Windows, iOS, and Android, can be seamlessly integrated with Palo Alto Networks' XDR agent installation. Additionally, unmanaged devices can leverage this integration by ingesting Google Chrome into the XDR management console for enhanced security management. This centralization simplifies device management and ensures consistent security measures across the organization.
The partnership between Palo Alto Networks and Chrome Enterprise significantly contributes to creating a safer workforce and world. With central management capabilities for enterprise devices, organizations gain full control and visibility over managed devices. Furthermore, unmanaged devices benefit from increased security visibility, which encompasses various aspects such as Chrome Browser extension installations, malware downloads, malicious website visits, and data leakage. By proactively addressing these security threats, businesses can better protect their employees and sensitive information.
For enterprises enrolled in the Chrome Enterprise Recommended program, the partnership delivers an enhanced employee experience. The integration enables seamless utilization of Google Chrome Enterprise security features, providing end-users with transparent protection against potential threats. Simultaneously, the integration allows for centralized management through a single console, simplifying security measures and ensuring consistent adherence to security protocols.
The announcement of the Connectors Framework and Reporting Connectors was driven by an increase in security investigations. These two features play a crucial role in today's security landscape by consolidating all alerts into a unified view, granting Security Operations Center (SOC) teams complete visibility across all devices, irrespective of whether agents are installed. Leveraging the integration of Palo Alto Networks' XSOAR and XSIAM, security teams can automate playbooks to remediate security events promptly. For instance, upon detecting multiple suspicious actions from a user, such as visiting malicious websites or attempting unauthorized data uploads, the system can automatically sign out the user, reset their password, and prompt re-validation.
Note: If you don’t enter a Vendor or Product, Cortex XDR will label the dataset as “unknown_unknown_raw”.
4. Click Save & Generate Token and copy the token that is generated. You will need to enter this into the admin console in the following section.
For more information, you can refer to the Cortex Help Center: Set up an HTTP Log Collector to Receive Logs:
Under the additional settings, you can specify which events you want to send to Palo Alto Networks Cortex XDR.
Press the Add Configuration to save.
Select the Organizational Unit that has reporting events enabled and select the Chrome Palo Alto Networks connector that was created in the previous step and hit Save.
After the integration, you can get logs/alerts from the Chrome Browser in the XDR/XSIAM console.
Generate incidents based on Correlation Rules
Dashboard for Chrome-related security alerts.
Automate and remediate incidents/alerts with playbooks if you using XSIAM or Cortex XSOAR.
To use this functionality, it seems to be necessary to have the Cortex XDR Pro per GB license. Wouldn't it be possible to use Cortex XDR Per endpoint?
I'm thinking about the BeyondCorp/Chrome Enterprise + Cortex XDR integration, which is an integration based on the number of endpoints.