05-02-2023 06:08 AM
Hello everyone ,
I'm having a problem that I can't solve.
I'll explain the context.
I am in full AZURE AD.
My computers are enrolled via INTUNE
I would like to be able to set up user-based firewall rules.
I set up the "cloud identity engine" (linked to azure ad), I can see my groups and my users in the palo alto.
When I create a firewall rule and I associate a user to it, the rule has no effect on this user.
Do you have an idea ?
Thanks in advance
05-05-2023 02:38 PM
I have some questions, but I think you are missing the User-IP mapping as the cloud identity engine won't provide IP. So far I heard only GP always one can help
05-04-2023 02:55 PM
Hello,
I would check the policy you created against a traffic log to see if you accidentally missed something. Also check how the users names are displayed in the logs vs how they are in the policy.
Regards,
05-05-2023 05:16 AM
HI @OtakarKlier
Thank you for taking the time to look at my question?
Here is some screenshot of my configuration
05-05-2023 07:32 AM
Hello,
Honestly I never had to deal with Azure AD, bt something is off. I would open a case with PAN support on this one. Also just a few suggestions:
Regards,
05-05-2023 02:38 PM
I have some questions, but I think you are missing the User-IP mapping as the cloud identity engine won't provide IP. So far I heard only GP always one can help
05-09-2023 01:58 AM
Good morning
I simply did a test with a ping to 8.8.8.8
But the configuration is not finalized yet
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!