In addition to using the Cloud Identity Engine to
retrieve user and group information, you can
use the Cloud Identity Engine to populate user group names in security policy rules.
This integration eliminates the need to configure an on-premises or VM-series
next-generation firewall as a
Master Device for this purpose; however,
Master Devices are still supported.
You
can also use Cloud Identity Engine to populate group names in Panorama
Managed
multi-tenant deployments,
which is not possible when using a Master Device.
To enable
the Cloud Identity Engine to populate group names in security policy
rules, complete the following steps.