Palo Alto Networks Certified Security Automation Engineer (PCSAE)Cortex XSOAR FundamentalsMedium
A security auditor is reviewing the user management practices in a Cortex XSOAR instance and questions how user sessions are authenticated. The organization uses an external identity provider for all its services. Which user management integration is typically used to centralize user authentication and management with an external identity provider in XSOAR?
- ASAML Integration
- BAPI Key Authentication
- CLDAP/AD Integration
- DLocal User Management
Show answer & explanationAnswer & explanation
Correct answer: A. SAML Integration
SAML (Security Assertion Markup Language) integration is the standard method for connecting Cortex XSOAR to an external Identity Provider (IdP) for centralized user authentication, enabling Single Sign-On (SSO) and leveraging the IdP for user management.
Why the other options are wrong
- B. API Key authentication is for programmatic access, not for interactive user login and management via an IdP.
- C. LDAP/AD integration is used for directory services to import users and groups, but SAML is typically preferred for modern centralized authentication with an IdP.
- D. Local user management means users are created and managed directly within XSOAR, which doesn't centralize with an external IdP.
XSOAR SAML Integration
A method to integrate Cortex XSOAR with an external Identity Provider (IdP) using SAML for centralized user authentication and Single Sign-On (SSO).
- Delegates authentication to an external IdP.
- Enables Single Sign-On (SSO) for users.
- Leverages existing enterprise identity management.
Memory trick: Authentication is about proving 'who you are' to XSOAR, often through a trusted third party.