Want to learn more about the new features introduced for the Cloud Identity Engine in
April 2024?
The following table provides a snapshot of new features introduced for the Cloud Identity
Engine app in April 2024. Refer to the Cloud Identity Engine documentation for more
information on how to use the Cloud Identity Engine.
Feature
Description
Support for Saudi Arabia (SA) Region
The Cloud Identity Engine now supports access in the Saudi Arabia
(SA) region for customers who must store the data that the Cloud
Identity Engine synchronizes from their directories in that region
to ensure compliance with their local data regulation requirements.
To maintain compatibility, your Cloud
Identity Engine region must be the same as the region you configure
in any associated Palo Alto Network apps or other app integrations.
If you're using a Cloud Identity agent, refer to Configure the Cloud Identity
Agent to learn how to configure the agent to
communicate within a specific region.
Support for Retrieval of Attributes from Okta Subdomains
If you use the Cloud Identity Engine as a mapping source for your
Palo Alto Networks firewall, you can now configure the Cloud
Identity Engine to collect information from a subdomain for an Okta
cloud-based directory. This capability allows you to retrieve
information for groups from a subdomain as well as the primary
domain for the Okta cloud-based directory for group mapping.
After you enter the CLI command on the firewall to enable detection
of the subdomain by the Cloud Identity Engine, when the firewall
detects a mapping from a subdomain with a configured primary domain,
the firewall stores the mapping for the subdomain in addition to the
mapping for the primary domain so that it can apply the group-based
security policy consistently across your network. This capability is
not enabled by default. You can also optionally disable detection
and collection of information from subdomains.
After you enter the CLI command on the firewall and configure the
subdomain, the group member information is available in the Cloud
Identity Engine. This allows you to create and enforce group-based
policy for subdomains within your Okta directory, enabling new
deployment options and capabilities for using the Cloud Identity
Engine with other Palo Alto Networks applications and devices.
Using the Cloud Identity Engine to retrieve
Okta subdomain information for group mapping requires PAN-OS version
10.2.9.