Panorama / SCM Linking: When you link a new Panorama or SCM
tenant to Cloud NGFW AWS, the system automatically checks your TSG for an
existing DLP tenant.
If a DLP tenant already exists in the TSG, Cloud NGFW attaches
to the existing DLP tenant ID.
If no DLP tenant exists, Cloud NGFW automatically provisions a
new DLP tenant in the TSG out of the box.
As Cloud NGFW firewall instances are created, their
serial numbers are automatically registered and associated with the TSG's
Enterprise DLP tenant.
For existing Cloud NGFW AWS deployments, Enterprise DLP enablement
depends on your policy management integration:
Panorama Link:Enterprise DLP is not automatically
provisioned for existing (brownfield) Panorama integrations. To enable
the Enterprise DLP tenant, you must open a support ticket with Palo Alto
Networks. Ensure your Panorama link is associated with a TSG containing
at least one active service prior to ticket submission.
Strata Cloud Manager (SCM) Link:
Standard Brownfield Deployments: Enterprise DLP
is not automatically provisioned. You must open a support ticket
with Palo Alto Networks to request tenant provisioning and
linking.
Simplified Onboarding Tenant Workflow: For
existing SCM deployments utilizing the Simplified Onboarding
Workflow, Enterprise DLP is automatically provisioned in the
backend during migration with no additional manual setup
required.
SCM with Simplified Onboarding Tenant Workflow: Tenants
onboarded through the simplified SCM workflow automatically inherit
Enterprise DLP entitlements upon association with a valid TSG, requiring
no additional manual setup or migration steps.