Plan Your Cloud Identity Engine Deployment
Focus
Focus
Identity

Plan Your Cloud Identity Engine Deployment

Table of Contents

Plan Your Cloud Identity Engine Deployment

Learn about pre-deployment planning for the Cloud Identity Engine.
Where Can I Use This?What Do I Need?
  • NGFW
  • Prisma Access
The Cloud Identity Engine service is free; however, the enforcement points utilizing directory data may require specific licenses. Click here for more information.
Successful implementation of the Cloud Identity Engine begins with evaluating your infrastructure to ensure it meets the necessary connectivity and architectural requirements. Before activating tenants or installing agents, you must configure your network to allow specific traffic between your directory sources, the Cloud Identity Agent, and the cloud service. This includes allowing traffic to region-specific hostnames and ensuring that required ports—such as port 80 for certificate verification and port 443 for secure TLS communication—are open.
You must also prepare your directory domains for integration. For on-premises Active Directory, this involves provisioning a service account with permissions to execute LDAP queries against all target domains and planning agent placement to ensure redundancy if a domain controller becomes unavailable.
Strategic planning also requires defining the scope of your deployment. You must select a Region that aligns with your data residency requirements and other Palo Alto Networks applications, such as Prisma Access, to minimize latency and ensure compliance.