Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Prisma Cloud PlatformMedium

A development team is integrating a custom application with Prisma Cloud to automatically retrieve compliance posture data for specific cloud accounts. The application needs to authenticate securely without user interaction and have specific, limited permissions. Which authentication method should the team use for their API calls?

  1. AUser API Key
  2. BBasic Authentication with Console Username/Password
  3. CSAML 2.0
  4. DOAuth 2.0 Client Credentials
Show answer & explanation

Correct answer: D. OAuth 2.0 Client Credentials

OAuth 2.0 Client Credentials is the recommended and most secure method for programmatic access to the Prisma Cloud API from applications that do not involve a user context. It allows for machine-to-machine authentication with granular permissions.

Why the other options are wrong

  • A. User API keys are tied to a specific user and are less suitable for applications requiring independent authentication and granular roles.
  • B. Basic authentication with a user's console credentials is insecure for programmatic access and ties the application to a user account, making auditing difficult.
  • C. SAML 2.0 is an identity federation standard primarily for single sign-on (SSO) for human users, not programmatic API access.

Prisma Cloud API OAuth 2.0 Client Credentials

A secure authentication flow for applications to access the Prisma Cloud API without user interaction, using a client ID and client secret.

  • Enables machine-to-machine communication.
  • Provides granular role-based access control (RBAC) for the application.
  • Recommended for automation and integration scenarios.

Memory trick: For apps, OAuth client credentials are the secure key to the API kingdom.

More Prisma Cloud Platform questions