: New Features Introduced in August 2024
Focus
Focus

New Features Introduced in August 2024

Table of Contents

New Features Introduced in August 2024

Read more about the new features introduced for the Cloud Identity Engine in August 2024, including support for authentication using OpenID Connect (OIDC).
The following table provides a snapshot of new features introduced for the Cloud Identity Engine app in August 2024. Refer to the Cloud Identity Engine documentation for more information on how to use the Cloud Identity Engine.
FeatureDescription
Support for South Korea (KR) Region
The Cloud Identity Engine now supports access in the South Korea (KR) region for customers who must store the data that the Cloud Identity Engine synchronizes from their directories in that region to ensure compliance with their local data regulation requirements.
To maintain compatibility, your Cloud Identity Engine region must be the same as the region you configure in any associated Palo Alto Network apps or other app integrations.
For more information on regions, refer to Regional Data Storage Requirements in the Cloud Identity Engine System Requirements.
For more information on how the Cloud Identity Engine manages the data you allow it to access, including transfer, retention, and security, refer to the Cloud Identity Engine Solution Brief or the Cloud Identity Engine Privacy Datasheet.
Support for OpenID Connect (OIDC) Authentication Type
The Cloud Identity Engine now supports OpenID Connect (OIDC) as an authentication type for:
  • Azure Active Directory
  • Okta
  • PingOne
  • Google
OpenID Connect (OIDC) provides additional flexibility for your Cloud Identity Engine deployment. By supporting single sign-on (SSO) across multiple applications, OIDC simplifies authentication for users, allowing them to log in once with the OIDC provider to access multiple resources without needing to log in repeatedly.
When you configure OIDC as your authentication type, the Cloud Identity Engine uses OIDC to communicate with your IdP and collect attributes for Security policy enforcement. Enabling OIDC authentication for the Cloud Identity Engine improves the authentication experience for users, since they won't need to reauthenticate as many times to access resources.
Enhancements for IP-Tag Connection
Multiple improvements are now available for the IP-Tag Connection capability, including:
  • For your IP address-to-tag mappings, you can now request a Full Sync to immediately collect all mappings.
  • For AWS connection types, additional Cloud Formation Template (AFT) options are now available.
  • For Google connection types, you can now optionally select your region before testing the connection.