Integrate Device Security with Cloud Identity Engine
Focus
Focus
Device Security

Integrate Device Security with Cloud Identity Engine

Table of Contents

Integrate Device Security with Cloud Identity Engine

Integrate Device Security with Cloud Identity Engine to retrieve Active Directory attributes for your devices, enabling better Security policy management.
Where Can I Use This?What Do I Need?
  • Device Security (Managed by Strata Cloud Manager)
  • (Legacy) IoT Security (Standalone portal)
One of the following subscriptions:
  • Device Security subscription for an advanced Device Security product (Enterprise Plus, Industrial OT, or Medical)
  • Device Security X subscription
One of the following Cortex XSOAR setups:
  • A free, cohosted, limited-featured Cortex XSOAR instance
  • A full-featured Cortex XSOAR server
If you have on-premises Active Directory (AD) synchronized with Cloud Identity Engine (CIE), you can integrate Device Security with CIE to learn whether your IoT devices are part of your AD information. This integration helps you identify managed and unmanaged devices on your network, providing more context to create effective Security policy rules.
Through the integration, Device Security retrieves devices and device attributes from CIE and matches the devices existing ones in your Device Security inventory based on hostname. Device Security can't learn new devices from the CIE integration. After matching devices, Device Security updates the device attributes for those devices in your asset inventory. These attributes include AD join status, AD groups, domain name, last login, and operating system information. When viewing the Device Details page, Device Security displays the source for attributes learned from Active Directory through the CIE integration as PAN-OS. Device Security queries CIE for device information when you first enable the integration, and then queries CIE once a day as long as the integration is active.
Toggling the integration off and back on won't trigger a new sync if it's less than 24 hours since the last one.
You can filter your device inventory based on AD join status or AD attributes, and create security policy rules that account for a device's domain membership. This contextual data enriches your device inventory, supporting more comprehensive security analysis. When accounting for AD status and groups, Security policy rules can enforce network and resource access based on your organization's management requirements.
This integration requires an active in the same tenant service group (TSG) as your Device Security tenant. You can enable or disable the CIE integration in Device Security.
  1. Activate Cloud Identity Engine and provide it with visibility scope in the same TSG as your Device Security tenant.
  2. In your Device Security portal, navigate to IntegrationsCloud Identity Engine Integration.
  3. Select the toggle to enable the integration with Cloud Identity Engine.
    Device Security automatically learns about your existing CIE from the hub. If your CIE information does not appear, check on the CIE setup and the CIE visibility scope.