Select this checkbox to enable session tracking. When enabled, PAN-OS logs additional user and tenant information to
Strata Logging Service. For a subset of the applications
that support tenant-level detection, the additional information
provides granularity at the user account level. With session
tracking enabled, SaaS Security Inline administrators can
submit policy rule recommendations for individual user accounts on
an application tenant.
This capability lets you allow some application traffic for a tenant,
while blocking traffic from specific user accounts on that tenant.
For example, for a trusted vendor, you might allow traffic only for
your organization's Gmail accounts, while blocking traffic for the
vendor's Gmail accounts or personal Gmail accounts.
When you import a policy recommendation that specifies tenant user
accounts, PAN-OS creates the security policy rule for
the recommendation. This security policy rule includes custom SaaS
Users and SaaS Tenant objects that are referenced by the security
policy rule. These custom objects represent the tenant user
accounts. If session tracking is enabled, you can view the SaaS User
and SaaS Custom objects under , and on the SaaS tab for the security policy
rule.
|