- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-25-2023 10:35 AM
How do I train Prisma Access to only pull security group and not distribution group from AD?
Thanks,
08-30-2023 04:31 AM
are you using Cloud Identity Engine or LDAP?
in LDAP you can select which groups to pull, in CIE you can switch from 'dumb' AD integration (pulls everything) to SCIM which allows you to control (from azure or aws or wherever) which groups to sync
11-10-2023 05:57 AM
Experience with Panorama Management:
We tried CIE for our early deployment, but it broke several times. No RCA from the support team since we don't have access to backend logs. You are completely blind. I don't suggest you use CIE for security groups.
If you are not an Azure shop and have a reliable connection to OnPrem from Prisma, go with LADAP.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!