Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Prisma Cloud PlatformMedium

A security engineer is tasked with integrating Prisma Cloud with their organization's existing identity provider (IdP) for centralized user authentication. They need to ensure that users can log into Prisma Cloud using their existing corporate credentials and that their roles are automatically provisioned based on groups defined in the IdP. Which integration protocol is primarily used for this purpose in Prisma Cloud?

  1. ALDAP.
  2. BOAuth 2.0.
  3. CSAML 2.0.
  4. DHTTPS.
Show answer & explanation

Correct answer: C. SAML 2.0.

SAML 2.0 (Security Assertion Markup Language) is the industry standard protocol used by Prisma Cloud for federated identity and single sign-on (SSO) integration with external identity providers, enabling centralized authentication and automated role provisioning based on IdP group memberships.

Why the other options are wrong

  • A. LDAP is primarily a directory service protocol for retrieving user information, not for federated SSO with role mapping.
  • B. OAuth 2.0 is primarily for authorization (granting limited access to resources), not for user authentication and role provisioning from an IdP.
  • D. HTTPS is a secure transport protocol, not an identity integration protocol.

Prisma Cloud SAML 2.0 Integration

The process of configuring Prisma Cloud as a Service Provider (SP) to integrate with an external Identity Provider (IdP) using SAML 2.0 for Single Sign-On (SSO) and user provisioning based on IdP group attributes.

  • Enables centralized authentication with corporate credentials.
  • Supports automatic role mapping based on IdP group memberships.
  • Industry standard for federated identity management.

Memory trick: To connect identities, SAML is the secure bridge for SSO and roles.

More Prisma Cloud Platform questions