<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Applying Umbrella policy to Active Directory identities in Cloud Security</title>
    <link>https://community.cisco.com/t5/cloud-security/applying-umbrella-policy-to-active-directory-identities/m-p/5141682#M1950</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/141301"&gt;@mski7861&lt;/a&gt; without the Roaming Client or the VA, Umbrella won't know which user the DNS request comes from. It's the VA that sends the client IP address and user information with the DNS request to the Umbrella cloud.&lt;/P&gt;</description>
    <pubDate>Mon, 08 Jul 2024 19:52:58 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2024-07-08T19:52:58Z</dc:date>
    <item>
      <title>Applying Umbrella policy to Active Directory identities</title>
      <link>https://community.cisco.com/t5/cloud-security/applying-umbrella-policy-to-active-directory-identities/m-p/5141663#M1947</link>
      <description>&lt;P&gt;Can I apply and enforce an umbrella DNS policy to a Active Directory user that doesn't have the Umbrella Roaming Client installed?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 19:15:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/applying-umbrella-policy-to-active-directory-identities/m-p/5141663#M1947</guid>
      <dc:creator>mski7861</dc:creator>
      <dc:date>2024-07-08T19:15:25Z</dc:date>
    </item>
    <item>
      <title>Re: Applying Umbrella policy to Active Directory identities</title>
      <link>https://community.cisco.com/t5/cloud-security/applying-umbrella-policy-to-active-directory-identities/m-p/5141671#M1948</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/141301"&gt;@mski7861&lt;/a&gt; yes, configure the clients to use the Umbrella Virtual Appliance (VA) for DNS resolution. &lt;A href="https://docs.umbrella.com/deployment-umbrella/docs/1-introduction" target="_blank"&gt;https://docs.umbrella.com/deployment-umbrella/docs/1-introduction&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;And also ensure the the VA is integrated with AD &lt;A href="https://docs.umbrella.com/deployment-umbrella/docs/active-directory-integration-with-the-virtual-appliances" target="_blank"&gt;https://docs.umbrella.com/deployment-umbrella/docs/active-directory-integration-with-the-virtual-appliances&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 19:23:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/applying-umbrella-policy-to-active-directory-identities/m-p/5141671#M1948</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-07-08T19:23:10Z</dc:date>
    </item>
    <item>
      <title>Re: Applying Umbrella policy to Active Directory identities</title>
      <link>https://community.cisco.com/t5/cloud-security/applying-umbrella-policy-to-active-directory-identities/m-p/5141676#M1949</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;thank you for the response.&amp;nbsp; In this case we aren't using the VA nor does the client want another appliance in the environment.&amp;nbsp; We are directly integrated with Azure,&lt;/P&gt;
&lt;P&gt;I created a test policy configured in allow-only mode and applied the test AD user identity to the policy.&amp;nbsp; The host I tested with had the roaming client installed.&amp;nbsp; I logged into the host (with the RC installed) as the test user defined in the policy and it blocked all internet traffic as expected.&amp;nbsp; I then uninstalled the roaming client and rebooted, then tested the same machine and same user however this time I was able to access all URLs.&amp;nbsp; I even ran the policy tester for the test user and it shows the allow-only policy will be applied.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm just trying to figure out what is required to apply a policy to a Azure AD user or group identity.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 19:32:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/applying-umbrella-policy-to-active-directory-identities/m-p/5141676#M1949</guid>
      <dc:creator>mski7861</dc:creator>
      <dc:date>2024-07-08T19:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: Applying Umbrella policy to Active Directory identities</title>
      <link>https://community.cisco.com/t5/cloud-security/applying-umbrella-policy-to-active-directory-identities/m-p/5141682#M1950</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/141301"&gt;@mski7861&lt;/a&gt; without the Roaming Client or the VA, Umbrella won't know which user the DNS request comes from. It's the VA that sends the client IP address and user information with the DNS request to the Umbrella cloud.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 19:52:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/applying-umbrella-policy-to-active-directory-identities/m-p/5141682#M1950</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-07-08T19:52:58Z</dc:date>
    </item>
    <item>
      <title>Re: Applying Umbrella policy to Active Directory identities</title>
      <link>https://community.cisco.com/t5/cloud-security/applying-umbrella-policy-to-active-directory-identities/m-p/5141692#M1951</link>
      <description>&lt;P&gt;Ohhhh so that's where the value of the VA comes into play &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;Thank you for the clarification and your response!&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 19:59:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/applying-umbrella-policy-to-active-directory-identities/m-p/5141692#M1951</guid>
      <dc:creator>mski7861</dc:creator>
      <dc:date>2024-07-08T19:59:30Z</dc:date>
    </item>
  </channel>
</rss>

