Create and Manage HIP Profiles for the Dynamic Privilege Access Prisma Access Agent
Focus
Focus
Prisma Access

Create and Manage HIP Profiles for the Dynamic Privilege Access Prisma Access Agent

Table of Contents

Create and Manage HIP Profiles for the Dynamic Privilege Access
Prisma Access Agent

Learn how to create a collection of HIP objects that are evaluated together, either for monitoring or for security policy enforcement.
Where Can I Use This?
What Do I Need?
  • Prisma Access (Managed by Strata Cloud Manager)
  • Prisma Access
    5.1 Innovation
  • Prisma Access
    license with the Mobile User subscription
  • macOS 12 or later desktop devices or Windows 10 version 2024 or later or Windows 11 desktop devices
  • Role: Superuser
A HIP Profile is a collection of host information profile objects that are evaluated together, either for monitoring or for security policy enforcement. When you create your HIP Profiles, you can combine the HIP objects and HIP Profiles you previously created by using Boolean logic, such that when a traffic flow is evaluated against the resulting HIP Profile, it either matches or does not match. If there is a match, the corresponding policy rule is enforced. If there is no match, the flow is evaluated against the next rule, as with any other policy matching criteria.
  1. From Strata Cloud Manager, select
    Workflows
    Prisma Access Setup
    Access Agent
    Prisma Access Agent
    .
  2. Edit
    the
    Global Agent Settings
    .
  3. Select
    HIP Notifications
    and click
    Add
    .
  4. Click
    Create HIP Profile
    .
  5. Enter a
    Name
    and
    Description
    to identify the profile.
  6. Click within the
    Match
    field to open the HIP Profile builder.
    1. Select the HIP object or profile that you want to use as match criteria from the list.
    2. Select a Boolean operator (
      And
      ,
      And
      ). If you want the HIP Profile to evaluate the object as a match only when the criteria in the object are not true for a flow, select the
      Not
      check box before adding the object.
    3. Select another HIP object or profile to evaluate against the first HIP object.
  7. Continue adding match criteria for the profile that you're building, making sure to select the appropriate Boolean operator radio button (
    And
    or
    And
    ) between each addition, and using the
    Not
    check box when appropriate. The HIP Profile can contain up to 2,048 characters in length.
  8. When creating a complex Boolean expression, you must manually add the parenthesis in the proper places in the
    Match
    text box to ensure that the HIP Profile is evaluated using the logic you intend.
  9. Save
    and
    Add
    your HIP Profile.
  10. To manage your HIP Profiles, you can select an existing profile from the HIP Notifications table or click
    Add
    in the Edit Global Agent Settings page to open the HIP Notifications window.
    From there, click
    Manage HIP Profile
    to view the list of HIP Profiles that you have configured. You can select a HIP Profile and
    Delete
    ,
    Clone
    , or
    Move
    it. You can also
    Add
    a HIP Profile from here.

Recommended For You