Learn how to configure the Dynamic Privilege Access (DPA) capability in the Cloud
Identity Engine.
| Where Can I Use This? | What Do I Need? |
|
| The Cloud Identity Engine service is free; however, the
enforcement points utilizing directory data may require specific
licenses. Click here for more
information. |
Enabling Dynamic Privilege Access (DPA) allows you to isolate network resources so
they are only accessible to users on a per-project basis.
Contact your Palo Alto Networks account representative to
activate this functionality.
Syncing new user groups for SAML applications in Azure may
require up to 3 hours for the Cloud Identity Engine to complete the sync. Wait until
the sync is complete before assigning projects to the new group.