QuestionQ13

Integration and Automation

An organization uses Cloud Identity Engine (CIE) to collect user information from its on-premises Active Directory (AD) for employees and from a separate Azure AD for external partners. Because of compliance regulations, the firewalls protecting the internal network must not contain any identity information about external partners. Conversely, firewalls in the partner-facing DMZ must be aware only of partner identities.

Which CIE feature is intended to meet this data-partitioning requirement?

  • A Panorama templates, which can be used to push different User-ID agent configurations to each firewall group
  • B Segments, which can be configured to create distinct, filter-based views of users and groups that are then redistributed only to the appropriate firewalls
  • C Multiple tenants, where a separate CIE tenant is required for each user directory to maintain isolation
  • D Directory sync filtering, which is used at the source to prevent specific OUs from being imported into CIE
Explanation

CIE User Context segments define which identity data is collected from and shared with specified firewalls. Publishing and subscribing segments allow employee and partner identity data to be redistributed only to their respective firewall groups, preserving the required isolation.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!