Data Connector - Api Restriction

Jakub Wierzchowski 0 Reputation points
2025-01-22T12:16:32.56+00:00

Dear Prisma Cloud Support Team,

I am experiencing an issue with the integration between Microsoft Sentinel and Prisma Cloud using the Data Connector described in your documentation (Integrating Prisma Cloud with Azure Sentinel using the Data Connector).

When API Restrictions are enabled in Prisma Cloud, the connection between Microsoft Sentinel and Prisma Cloud fails. Disabling the API restriction resolves the issue, but this is not a feasible solution as IP restriction needs to remain enabled in our environment for security compliance.

Specific Problem:

  • I need to determine the specific IP addresses or ranges used by Microsoft Sentinel’s Data Connector to communicate with Prisma Cloud so that I can whitelist only those addresses.
  • Adding the entire range of IP addresses from Azure’s published list (AzureMonitor or AzureCloud) is not practical due to the number of addresses involved.
  • I am looking for a way to whitelist only a minimal set of IP addresses to ensure proper functionality while maintaining strict security controls.

Questions:

  1. Can you provide a definitive list of IP addresses or ranges required for the Microsoft Sentinel Data Connector to function with Prisma Cloud?
  2. Are there any alternative configurations or best practices for enabling the Data Connector while keeping API restrictions enabled in Prisma Cloud?

Any guidance or recommendations to resolve this issue while adhering to our security policies would be greatly appreciated.

Environment Details:

  • Prisma Cloud version: [Your Version]
  • Microsoft Sentinel region: [Your Region]
  • API Restriction: Enabled

Please let me know if you need additional details to investigate this issue.

Thank you for your support!

Best regards,Dear Prisma Cloud Support Team,

I am experiencing an issue with the integration between Microsoft Sentinel and Prisma Cloud using the Data Connector described in your documentation (Integrating Prisma Cloud with Azure Sentinel using the Data Connector).

When API Restrictions are enabled in Prisma Cloud, the connection between Microsoft Sentinel and Prisma Cloud fails. Disabling the API restriction resolves the issue, but this is not a feasible solution as IP restriction needs to remain enabled in our environment for security compliance.

Specific Problem:

  • I need to determine the specific IP addresses or ranges used by Microsoft Sentinel’s Data Connector to communicate with Prisma Cloud so that I can whitelist only those addresses.
  • Adding the entire range of IP addresses from Azure’s published list (AzureMonitor or AzureCloud) is not practical due to the number of addresses involved.
  • I am looking for a way to whitelist only a minimal set of IP addresses to ensure proper functionality while maintaining strict security controls.

Questions:

  1. Can you provide a definitive list of IP addresses or ranges required for the Microsoft Sentinel Data Connector to function with Prisma Cloud?
  2. Are there any alternative configurations or best practices for enabling the Data Connector while keeping API restrictions enabled in Prisma Cloud?

Any guidance or recommendations to resolve this issue while adhering to our security policies would be greatly appreciated.

Please let me know if you need additional details to investigate this issue.

Thank you for your support!

Best regards,

Jakub

Not Monitored
Not Monitored
Tag not monitored by Microsoft.
41,834 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.