Create a passive identity agent identity source

Configure the passive identity agent identity source to enable user identity monitoring and enhance access control in your network environment.

This provides high-level tasks required to configure the passive identity agent identity source in the Cloud-Delivered Firewall Management Center and to deploy agent software to your Microsoft Active Directory (AD) servers.

Before you begin

Follow these steps to create a passive identity agent identity source:

Procedure


Step 1

Enable the Dynamic Attributes Connector.

The dynamic attributes connector is a requirement to use the passive identity agent.

See Enable the dynamic attributes connector.

Step 2

Create a realm for your Microsoft AD domain and domain controllers.

Realms are connections between the Cloud-Delivered Firewall Management Center and the user accounts on the servers you monitor. They specify the connection and authentication filter settings for the server.

For more information, see Create an LDAP realm or an Active Directory realm and realm directory.

Step 3

Create a passive identity agent identity source.

The identity source allows the Cloud-Delivered Firewall Management Center and passive identity agent to communicate with each other. Create standalone, primary, or secondary agents, to match your requirements.

For more information, refer to:

Step 4

Configure API token authentication for the passive identity agent with Cloud-Delivered Firewall Management Center.

Step 5

Install the passive identity agent software.

The installation method for the agent varies according to your deployment.

You can install a passive identity agent on the AD domain controller, directory server, or on any client connected to the domain you wish to monitor.

For more information, see: