Policy Object: Auto-Tag Actions
Focus
Focus
Network Security

Policy Object: Auto-Tag Actions

Table of Contents

Policy Object: Auto-Tag Actions

Automatically enforce users and IP addresses based on behavior and activity.
Where Can I Use This?What Do I Need?
  • NGFW (Cloud Managed)
  • NGFW (PAN-OS & Panorama Managed)
  • Prisma Access
Check for any license or role requirements for the products you're using.
NGFWs and Prisma Access can automatically tag the users or IP addresses associated with a log entry. When you use auto-tags to build policy, you can automatically enforce users and IP addresses based on behavior and activity. You don't need to manually and retroactively adjust policy or groups. For example, when you create a filter for the URL logs for yes in the Credential Detected column, you can apply a tag to the user that enforces an authentication policy that requires the user to authenticate using multi-factor authentication (MFA).
Local tagging is supported for Prisma Access deployments; tag redistribution is not supported.
To get started, set up an auto-tag and then use it to populate a dynamic address group or a dynamic user group. Then, add the dynamic user group to a security rule.
Auto-tagging works by telling your configuration to tag a policy object when it receives a log that matches specific criteria and establish IP address-to-tag or user-to-tag mapping. For example, when the a threat log is generated, you can set your configuration up to tag the source IP address or source user in the threat log with a specific tag name. You can then use these tags to automatically populate policy objects such as dynamic user groups or dynamic address groups, which can then be used to automate security actions in security, authentication, or decryption policies.
Dynamic user groups do not support auto-tagging from HIP Match logs.

Use Auto-Tagging to Automate Security Actions

Follow these steps to automatically tag the users or IP addresses associated with a log entry and enforce users and IP addresses based on behavior and activity.
Use auto-tagging selectively. It is designed for tagging a small number of users or IP addresses based on specific log categories—not for large volumes of traffic. To maintain performance and avoid unintended policy impact, limit auto-tag filters to a narrow set of logs.