* [Blog](https://origin-researchcenter.paloaltonetworks.com/blog) * [Security Operations](https://origin-researchcenter.paloaltonetworks.com/blog/security-operations/) * [AI and Cybersecurity](https://origin-researchcenter.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/) * Identity Meets the SOC: R... # Identity Meets the SOC: Redefining the Last Perimeter [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Forigin-researchcenter.paloaltonetworks.com%2Fblog%2Fsecurity-operations%2Fidentity-meets-the-soc-redefining-the-last-perimeter%2F) [](https://twitter.com/share?text=Identity+Meets+the+SOC%3A+Redefining+the+Last+Perimeter&url=https%3A%2F%2Forigin-researchcenter.paloaltonetworks.com%2Fblog%2Fsecurity-operations%2Fidentity-meets-the-soc-redefining-the-last-perimeter%2F) [](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Forigin-researchcenter.paloaltonetworks.com%2Fblog%2Fsecurity-operations%2Fidentity-meets-the-soc-redefining-the-last-perimeter%2F&title=Identity+Meets+the+SOC%3A+Redefining+the+Last+Perimeter&summary=&source=) [](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https://origin-researchcenter.paloaltonetworks.com/blog/security-operations/identity-meets-the-soc-redefining-the-last-perimeter/&ts=markdown) \[\](mailto:?subject=Identity Meets the SOC: Redefining the Last Perimeter) Link copied By [Emran Mazumder](https://www.paloaltonetworks.com/blog/author/emran-mazumder/?ts=markdown "Posts by Emran Mazumder") and [David Trigano](https://www.paloaltonetworks.com/blog/author/david-trigano/?ts=markdown "Posts by David Trigano") Aug 06, 2026 8 minutes [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown) [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown) [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown) [Cybersecurity](https://www.paloaltonetworks.com/blog/category/cybersecurity/?ts=markdown) [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown) [News and Events](https://www.paloaltonetworks.com/blog/security-operations/category/news-and-events/?ts=markdown) [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown) [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [Use-Cases](https://www.paloaltonetworks.com/blog/security-operations/category/use-cases/?ts=markdown) [Cortex XDR](https://www.paloaltonetworks.com/blog/tag/cortex-xdr/?ts=markdown) [Identity](https://www.paloaltonetworks.com/blog/tag/identity/?ts=markdown) [Identity Security Operations](https://www.paloaltonetworks.com/blog/tag/identity-security-operations/?ts=markdown) [Identity Threat Detection and Response](https://www.paloaltonetworks.com/blog/tag/identity-threat-detection-and-response/?ts=markdown) [IdSecOps](https://www.paloaltonetworks.com/blog/tag/idsecops/?ts=markdown) [ITDR](https://www.paloaltonetworks.com/blog/tag/itdr/?ts=markdown) ## Why we are at an inflection point with identity Let's start with a hard truth that every security leader is waking up to: **adversaries aren't breaking into enterprise networks anymore. They are simply logging in.** For years, the cybersecurity industry operated under a relatively straightforward assumption: if we built higher walls at the perimeter, deployed robust Identity and Access Management (IAM), and rolled out Multi-Factor Authentication (MFA), our environments would be safe. We treated the "front door" of identity as a binary gatekeeper. But today, with adversarial Frontier AI at the doorsteps, we must assume that the gate has been breached. Identity has officially become the primary attack surface. Once a threat actor bypasses those initial gatekeepers, whether through sophisticated session hijacking, social engineering, or compromised service accounts, they don't trigger traditional alarms. They don't need to deploy noisy malware. Instead, they blend completely invisibly into your regular, daily corporate traffic. An explosion of non-human identities, like service accounts, API tokens, and autonomous AI agents, now drives**over 90% of incident response cases** [^**1**^](#bottom-notes). The crisis is speed: attackers exfiltrate data in 72 minutes, while it takes security teams 12 hours to manually investigate. Fighting machine-speed threats with manual workflows is futile, identity context must live directly inside the SOC. ### What an Ideal ITDR Solution Must Solve **[Identity Threat Detection and Response (ITDR)](https://www.paloaltonetworks.com/cyberpedia/identity-threat-detection-and-response-itdr)** is a security discipline focused on monitoring, protecting, and defending identity infrastructure from credential misuse, privilege escalation, and unauthorized access across both human and machine identities. To outpace modern automated identity attacks, an ideal ITDR solution must fulfill core capabilities within a single continuous workflow. It starts by ingesting and cross-referencing multi-domain telemetry across endpoints, network, cloud infrastructure, SaaS applications, and identity systems. The platform then applies contextual stitching to correlate cross-vector signals, transitioning security operations from standard password verification to actively verifying human and machine intent. Grounded in continuous behavioral baselines, it calculates dynamic, real-time risk scores that immediately trigger adaptive access policies, such as step-up MFA when abnormal behavior is detected. Finally, it must execute an automated, closed-loop playbook to deliver surgical containment, instantly neutralizing active threats before exfiltration can occur. ## Introducing Cortex ITDR 2.0 Today, we are proud to unveil [Cortex ITDR 2.0](https://www.paloaltonetworks.com/cortex/itdr), which brings identity intelligence directly into the security operations platform, stitching together endpoints, networks, cloud, SaaS, and Identity. * **Conditional Access Policy (CAP)** : Trigger dynamic step-up MFA in Okta and Entra ID based on behavioral drift, and test policies safely in Simulation Mode. * **Active Directory Security Posture Management (AD-SPM)** : Continuously audit Active Directory via existing XDR agents to uncover misconfigurations, excessive privileges, and hidden attack paths. * **Unified Single-Pane Visibility:** The Unified User Card consolidates Active Directory, endpoint, and cloud context into a single view with behavioral heat maps and risk trendlines. * **Idira + Cortex Integration** : Fuse privileged access intelligence with cross-domain telemetry to execute surgical, automated containment without business downtime. * **Secure and Govern Access with Granular RBAC** : New standardized structure featuring dedicated roles (Viewer, Administrator), allowing for precise permissions for identity security and Conditional Access Policies. Let's take a closer look at these capabilities and how they redefine identity security. ### Conditional Access Policy (CAP) Detection without rapid response is just documenting a breach in real time. Dynamic Conditional Access Policies (CAP) turn passive notifications into active, automated containment. * **Zero-Friction Deployment:** Build new rules instantly using guided templates. The platform translates your security requirements into a plain-English rule summary, so your team can verify, save, and push policies live without any guesswork. * **Simulation vs. Enforcement:** Safely run "dry runs" of new policies in Simulation Mode to monitor real-world impact before flipping the switch to active, real-time Enforcement. * **Dynamic Step-Up MFA:** Automatically trigger a multi-factor authentication challenge in Okta \& EntraID the microsecond a user's behavior drifts from their baseline. ![](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/07/Conditional-Access-Policy-template.jpg) Image 1: Conditional Access Policy (CAP) template ### **Proactive Identity Hardening (AD-SPM)** You cannot secure what you haven't hardened. **Active Directory Security Posture Management (AD-SPM)** shifts your defense from reactive to proactive. Using your existing XDR agents, Cortex continuously audits Active Directory for structural weaknesses, flagging: * Misconfigured accounts and excessive privileges * Weak, exposed, or compromised passwords * Stale accounts and hidden attack paths that lead straight to your crown jewels ### The Unified User Card: All Identity Context in One Place Pivoting between Active Directory, endpoint consoles, and identity logs during an investigation slows down triage, giving attackers time to move laterally. The **Unified User Card** in Cortex ITDR 2.0 consolidates this disjointed data into a single interface. Analysts can immediately track the entire behavioral lifecycle of a user without switching consoles: * **Geographical Anomalies:** Cortex automatically baselines typical login locations. If a user's login activity suddenly deviates from their normal footprint, it is instantly flagged on the card. * **Behavioral Heat Maps:** Instantly spot spikes in suspicious activity over the course of the week. This interactive visual maps out alert density, allowing analysts to immediately identify *when* a compromise began. * **Continuous Risk Trendlines:** See at a glance whether a user's risk score is trending upward, pointing to a slow-burn compromise before it turns into a full-scale crisis. * **Suspicious Behavior Timelines:** Every high-risk action, privilege change, or security alert is laid out chronologically on the card, giving analysts the full, contextualized story in seconds. ![](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/07/User-activity-timeline.jpg) Image 2: User activity timeline ![](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/07/Issues-and-insights-Heat-map.jpg) Image 3: Issues and insights Heat map ![](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/07/User-Risk-Score-Trend.jpg) Image 4: User Risk Score Trend ### Idira Integration with Cortex Cortex ITDR 2.0 integrates natively with Idira's Identity Security Platform, introducing **17 new, out-of-the-box detectors** built specifically to monitor your Idira identity provider environment. By combining Idira's privileged access intelligence with Cortex's behavioral analytics, we've built an active, automated security loop inside the SOC. * **Full-Lifecycle Identity Telemetry:** Cortex ingests deep identity context across the entire user and privileged session lifecycle, capturing anomalies *pre-authentication* (risky behavior before login) and *at-authentication* (the login event itself). * **Cross-Domain Correlation:** By stitching Idira's identity and vault signals together with native endpoint, network, and cloud telemetry, Cortex surfaces complex, multi-stage attacks that any single domain would completely miss on its own. * **Instant Containment:** When an identity threat is validated, the SOC can trigger immediate, automated containment actions directly through Idira, instantly locking the account, rotating compromised secrets, revoking active sessions, credential theft, and signing the user out across the entire ecosystem. ![](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/08/Risky-Apps-Idira.png) Image 5: Block execution of Risky Applications * **Intelligent Guardrails:** Because these automated playbooks are backed by continuous risk scoring, response actions are surgically targeted. The platform neutralizes active adversary activity instantly without disrupting the daily, legitimate work of your business, and rolls restrictions back once the threat has been alleviated. ![](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/07/Idira-Endpoint-Privilege-Manager-Response-Playbook.jpg) Image 6: Idira's Endpoint Privilege Manager (EPM) Response Playbook ### **Secure and Govern Identity Access with Granular RBAC** In this release of ITDR we are introducing a new standardized structure featuring dedicated roles (Viewer, Administrator), allowing for precise permissions for identity security and Conditional Access Policies. This will help you with governance by enforcing strict least-privilege access over sensitive Conditional Access Policies, allowing SOC analysts to safely investigate identity context without risking unauthorized system changes. ## **Identity Security Tools and SecOps Platforms Can No Longer Exist in Silos** For years, enterprises have treated Identity and Access Management (IAM) and the Security Operations Center (SOC) as two entirely separate worlds. That division is a fundamental architectural flaw and threat actors are exploiting it every single day. Authentication is no longer the finish line of a security strategy; it is merely the starting line for behavioral monitoring. Continuing to treat identity as a separate silo, managed by an isolated team using disconnected tools, is an operational failure. Cortex ITDR 2.0 is a necessary architectural correction. By forcing identity telemetry directly into the SOC platform, it marks the shift from passive identity management to true [IDSecOps](https://www.paloaltonetworks.com/blog/identity-security/identitysecops-closed-loop-model-ai-speed-defense/) (Identity Security Operations), eliminating the blind spots human analysts can no longer bridge on their own. In today's threat landscape, visibility without immediate containment is useless, and containment without identity context is blind. It's time to bridge the gap and build a unified defense See how easy it is to secure your identity infrastructure and automate responses from a single console.[**Request a live Cortex demo today**](https://www.paloaltonetworks.com/cortex/request-demo) [Read the IDSecOps Blog](https://www.paloaltonetworks.com/blog/identity-security/identitysecops-closed-loop-model-ai-speed-defense/) [Read the IDSecOps eBook](https://www.paloaltonetworks.com/resources/ebooks/unify-identity-and-security-operations-to-stop-ai-attacks) [Visit the ITDR webpage](https://www.paloaltonetworks.com/cortex/itdr) *** ** * ** *** Sources \[1\] [https://www.paloaltonetworks.com/resources/research/unit-42-incident-response-report](https://www.paloaltonetworks.com/resources/research/unit-42-incident-response-report) \[2\] [https://www.paloaltonetworks.com/idira/identity-security-landscape-report](https://www.paloaltonetworks.com/idira/identity-security-landscape-report) *** ** * ** *** ## Related Blogs ### [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [News and Events](https://www.paloaltonetworks.com/blog/security-operations/category/news-and-events/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Securing the Agentic Endpoint](https://origin-researchcenter.paloaltonetworks.com/blog/2026/02/securing-the-agentic-endpoint/) ### [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown), [Use-Cases](https://www.paloaltonetworks.com/blog/security-operations/category/use-cases/?ts=markdown) [#### Boosting Identity Security with Cortex XDR/XSIAM Honey Users](https://origin-researchcenter.paloaltonetworks.com/blog/security-operations/boosting-identity-security-with-cortex-xdr-honey-users/) ### [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown), [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [News and Events](https://www.paloaltonetworks.com/blog/security-operations/category/news-and-events/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown), [Use-Cases](https://www.paloaltonetworks.com/blog/security-operations/category/use-cases/?ts=markdown) [#### From Silos to Synergy: How Cortex XDL Transforms XDR to Elevate Threat Detection](https://origin-researchcenter.paloaltonetworks.com/blog/security-operations/from-silos-to-synergy-how-cortex-xdl-transforms-xdr-to-elevate-threat-detection/) ### [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown), [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [News and Events](https://www.paloaltonetworks.com/blog/security-operations/category/news-and-events/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown), [Use-Cases](https://www.paloaltonetworks.com/blog/security-operations/category/use-cases/?ts=markdown) [#### SE Labs Awards Palo Alto Networks AAA Rating and 100% Prevention Against Ransomware](https://origin-researchcenter.paloaltonetworks.com/blog/security-operations/se-labs-awards-palo-alto-networks-aaa-rating-and-100-prevention-against-ransomware/) ### [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [News and Events](https://www.paloaltonetworks.com/blog/security-operations/category/news-and-events/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [Threat Intelligence](https://www.paloaltonetworks.com/blog/category/threat-intelligence-1/?ts=markdown) [#### A Leader in the 2025 Gartner Magic Quadrant for EPP --- 3 Years Running](https://origin-researchcenter.paloaltonetworks.com/blog/2025/07/named-a-leader-gartner-magic-quadrant/) ### [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [News and Events](https://www.paloaltonetworks.com/blog/security-operations/category/news-and-events/?ts=markdown), [Partners](https://www.paloaltonetworks.com/blog/category/partners/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Identity Protection That Spans the Entire Attack Lifecycle](https://origin-researchcenter.paloaltonetworks.com/blog/2024/08/identity-protection-that-spans-the-entire-attack-lifecycle/) ### Subscribe to Security Operations Blogs! Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more. ![spinner](https://origin-researchcenter.paloaltonetworks.com/blog/wp-content/themes/panwblog2023/dist/images/ajax-loader.gif) Sign up Please enter a valid email. By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) and acknowledge our [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown). Please look for a confirmation email from us. If you don't receive it in the next 10 minutes, please check your spam folder. This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply. {#footer} {#footer} Products and Services * [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown) * [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown) * [Prisma AIRS](https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security?ts=markdown) * [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown) * [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown) * [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [Industrial OT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown) * [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown) * [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown) * [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown) * [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown) * [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown) * [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown) * [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown) * [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown) * [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown) * [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown) * [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown) * [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown) * [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown) * [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown) * [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown) * [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown) * [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown) * [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) * [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown) * [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown) Company * [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown) * [Careers](https://jobs.paloaltonetworks.com/en/) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown) * [Customers](https://www.paloaltonetworks.com/customers?ts=markdown) * [Investor Relations](https://investors.paloaltonetworks.com/) * [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown) * [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown) Popular Links * [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown) * [Communities](https://www.paloaltonetworks.com/communities?ts=markdown) * [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) * [Event Center](https://events.paloaltonetworks.com/) * [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center) * [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) * [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown) * [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown) * [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown) * [Tech Docs](https://docs.paloaltonetworks.com/) * [Unit 42](https://unit42.paloaltonetworks.com/) * [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd) ![PAN logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg) * [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) * [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown) * [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) * [Documents](https://www.paloaltonetworks.com/legal?ts=markdown) Copyright © 2026 Palo Alto Networks. All Rights Reserved * [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks) * [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown) * [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/) * [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks) * [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks) * EN Select your language