Learn how to define the notification messages that your end users see
when a security rule with a HIP Profile is enforced.
Where Can I Use This? | What Do I Need? |
- Prisma Access (Managed by Strata Cloud Manager)
|
- Prisma Access 5.1 Preferred or Innovation
- Prisma Access
license with the
Mobile User subscription
- Prisma Access Agent version:
25.1.0.14
- macOS 14 and later or Windows 10 version 2024 and later desktop devices
- Contact your Palo Alto Networks account representative to
activate the Prisma Access Agent feature
|
When the HIP report matches the HIP profile or object, a corresponding
HIP notification is sent. You can define the notification messages that end users
see.
Deciding whether to display a notification message when the user's
configuration matches or does not match a HIP Profile in the policy depends largely
on your policy and what a HIP match (or nonmatch) means for the user.
That
is, does a match mean they are granted full access to your network resources, or
does it mean they have limited access due to a noncompliance issue?
For example, suppose you create a HIP Profile that matches if the
required corporate antivirus and antispyware software patches are not installed. You
could create a HIP notification message for users who match the HIP Profile,
informing them that they need to install the patches. Alternatively, if your HIP
Profile matches when those same patches are installed, you might want to create the
message for users who do not match the profile.