Learn how to download the Cloud Identity agent and install
it on a supported Active Directory or OpenLDAP-based directory server.
| Where Can I Use This? | What Do I Need? |
|
| The Cloud Identity Engine service is free; however, the
enforcement points utilizing directory data may require specific
licenses. Click here for more
information. |
Before installing the Cloud Identity agent,
verify that the time on the agent host is correct and synced to
a valid NTP server. If the time on the server host is incorrect,
the Cloud Identity Engine may not be able to sync your directory
attributes successfully.
After you
activate your Cloud Identity Engine
tenant, download the Cloud Identity agent from the Cloud Identity Engine app on the
hub and install it on a supported directory server. Palo Alto Networks strongly
recommends using TLS 1.3. If TLS 1.2 is not already
enabled on the Windows server that will
host the agent, install the
update to enable TLS 1.2 before you
install the agent.
Because the
User-ID agent and the
Cloud Identity agent require the same port, you must use a dedicated
host for each agent type. Do not install both agent types on the
same host.