New Features - Cloud Identity Engine - June 2026
Simplified Deployment for Tag Collector
When your environment includes air-gapped or restricted endpoints the cloud cannot reach, your firewalls lose access to consistent tag and identity data, creating gaps in policy enforcement. You can now deploy a context collector VM to gather user context locally and distribute it to all managed enforcement points. To learn how the context collector fits into your overall identity architecture, see Cloud Identity Engine Topology.
Context collectors are automatically placed in a dedicated Context Collector folder, isolated from your standard configuration hierarchy, with only the settings relevant to context collection exposed. You can group collectors into subfolders and use the Context Collector label to filter them in health dashboards, config pushes, and software upgrades. Context collectors support high-availability deployment across data centers and availability zones to minimize disruption if a single collector fails.
Context collectors are included at no additional cost for Software Firewall Flex customers and appear in your device inventory as a context collector after registration.