Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Prisma Cloud PlatformEasy

An organization is deploying Prisma Cloud for a multi-cloud environment and needs to integrate its existing identity provider (IdP) for single sign-on (SSO) for all users accessing the Prisma Cloud console. The IdP supports standard federation protocols. Which integration method should the security team configure in Prisma Cloud for user authentication?

  1. AAPI Key Authentication
  2. BLocal User Management
  3. CSAML 2.0 Integration
  4. DOAuth 2.0 Client Credentials
Show answer & explanation

Correct answer: C. SAML 2.0 Integration

SAML 2.0 (Security Assertion Markup Language) is the industry standard protocol for enabling single sign-on (SSO) with an external Identity Provider, allowing users to authenticate once with their corporate credentials and access Prisma Cloud without re-entering them.

Why the other options are wrong

  • A. API Key authentication is for programmatic access, not for human users to log into the console via SSO.
  • B. Local user management means creating users directly in Prisma Cloud, which does not provide SSO with an external IdP.
  • D. OAuth 2.0 Client Credentials is for machine-to-machine API authentication, not for human user SSO.

Prisma Cloud SAML 2.0 Integration

The process of configuring Prisma Cloud to use an external Identity Provider (IdP) for user authentication via the SAML 2.0 protocol, enabling Single Sign-On (SSO).

  • Allows users to log in with existing corporate credentials.
  • Centralizes user management and authentication.
  • Enhances security and user experience.

Memory trick: For user SSO, SAML is the standard key.

More Prisma Cloud Platform questions