If you’re using certificates to authenticate against Active Directory accounts, Prisma Cloud uses the UserPrincipalName field in the SAN to match the certificate to the user in Active Directory.
This is the same process used by Windows clients for authentication, so for most customers, the existing smart card certificates you’re already using can also be used for authentication to Prisma Cloud.