Learn how to enable User-ID on the Cloud NGFW for Azure.
Cloud NGFW protects your Azure vNet and Azure virtual WAN traffic with
advanced user awareness. The user identity, as opposed to an IP address, is an
integral component of an effective security infrastructure. Knowing who is accessing
each of the applications on your network, and who may have transmitted a threat or
is transferring files, can strengthen security policies and reduce incident response
times. User-ID™, a standard feature on the Palo Alto Networks firewalls, enables you
to leverage user information stored in a wide range of repositories. To learn more
about User-ID concepts,
User-ID overview.
To enforce policy from User-ID or Groups:
- Firewall must be able to map the IP addresses to the user names.
- User-ID provides various mechanisms for collecting the user mapping
information. To learn more, see User-ID Concepts.
If the mapping methods are unable to capture the mapping, then you can configure the
Authentication Policy to redirect users to an Authentication portal login. Users can
provide credentials which will be checked against the identity provider and enforce
access accordingly. Learn more about
authentication policy.
To enable a Users—and group-based policy, the firewall requires a list of all
available users and their corresponding group memberships.
You can enable User-ID on Cloud NGFW for Azure using the following
methods: