USER-ID policies + FULL azure ad

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

USER-ID policies + FULL azure ad

L1 Bithead

Hello everyone ,

I'm having a problem that I can't solve.

I'll explain the context.
I am in full AZURE AD.
My computers are enrolled via INTUNE

I would like to be able to set up user-based firewall rules.
I set up the "cloud identity engine" (linked to azure ad), I can see my groups and my users in the palo alto.
When I create a firewall rule and I associate a user to it, the rule has no effect on this user.
Do you have an idea ?

Thanks in advance

1 ACCEPTED SOLUTION

Accepted Solutions

L2 Linker

I have some questions, but I think you are missing the User-IP mapping as the cloud identity engine won't provide IP. So far I heard only GP always one can help

View solution in original post

5 REPLIES 5

Cyber Elite
Cyber Elite

Hello,

I would check the policy you created against a traffic log to see if you accidentally missed something. Also check how the users names are displayed in the logs vs how they are in the policy.

Regards,

HI @OtakarKlier

Thank you for taking the time to look at my question?


Here is some screenshot of my configuration



LCutman_0-1683288245280.pngLCutman_1-1683288313607.png

 

LCutman_2-1683288364154.png

 

LCutman_3-1683288461114.png

 

LCutman_4-1683288776698.pngLCutman_5-1683288939342.pngLCutman_6-1683288976593.png

 


 

Cyber Elite
Cyber Elite

Hello,

Honestly I never had to deal with Azure AD, bt something is off. I would open a case with PAN support on this one. Also just a few suggestions:

  1. I would recommend having a zone protection profile for you inside zones as well as external zones.
  2. Hopefully you are using a secure DNS. I understand that the google DNS was just ICMP only.

Regards,

L2 Linker

I have some questions, but I think you are missing the User-IP mapping as the cloud identity engine won't provide IP. So far I heard only GP always one can help

Good morning
I simply did a test with a ping to 8.8.8.8

But the configuration is not finalized yet

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!