Policy Object: Auto-Tag Actions
Automatically enforce users and IP addresses based on behavior and activity.
| Where Can I Use This? | What Do I Need? |
- NGFW (Cloud Managed)
- NGFW (PAN-OS & Panorama Managed)
- Prisma Access
| Check for any license or role requirements for the products you're using. |
NGFWs and Prisma Access can automatically tag the users or IP addresses associated with a
log entry. When you use auto-tags to build policy, you can automatically enforce users
and IP addresses based on behavior and activity. You don't need to manually and
retroactively adjust policy or groups. For example, when you create a filter for the URL
logs for yes in the Credential Detected
column, you can apply a tag to the user that enforces an authentication policy that
requires the user to authenticate using multi-factor authentication (MFA).
Local tagging is supported for Prisma Access deployments; tag redistribution is not
supported.
To get started, set up an auto-tag and then use it to populate a dynamic address group or
a dynamic user group. Then, add the dynamic user group to a security rule.
Auto-tagging works by telling your configuration to tag a policy object when it receives
a log that matches specific criteria and establish IP address-to-tag or user-to-tag
mapping. For example, when the a threat log is generated, you can set your configuration
up to tag the source IP address or source user in the threat log with a specific tag
name. You can then use these tags to automatically populate policy objects such as
dynamic user groups or dynamic address groups, which can then be used to automate
security actions in security, authentication, or decryption policies.
Dynamic user groups do not support auto-tagging from HIP Match
logs.
Use Auto-Tagging to Automate Security Actions
Follow these steps to automatically tag the users or IP addresses associated with
a log entry and enforce users and IP addresses based on behavior and
activity.
Use auto-tagging
selectively. It is designed for tagging a small number of users or IP
addresses based on specific log categories—not for large volumes of traffic.
To maintain performance and avoid unintended policy impact, limit auto-tag
filters to a narrow set of logs.