<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best practice for Entra/Azure Services? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Entra-Azure-Services/m-p/204837#M33985</link>
    <description>&lt;P&gt;Updatable Objects use vendor-provided information to populate.&lt;BR /&gt;If the vendor doesn’t provide it at the desired level of granularity (I.e. Microsoft), we can’t.&lt;/P&gt;</description>
    <pubDate>Fri, 02 Feb 2024 02:36:53 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-02-02T02:36:53Z</dc:date>
    <item>
      <title>Best practice for Entra/Azure Services?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Entra-Azure-Services/m-p/204721#M33969</link>
      <description>&lt;P&gt;We currently have a few servers that are being used for Azure/Entra/Intune connector use: Entra Connect, Entra AD Connect, Intune Certificate Connector, etc.&amp;nbsp; While building them out there were so many URLs the server was trying to access we ended up allowing most traffic out without filtering it.&lt;/P&gt;&lt;P&gt;We noticed there are updatable objects for Azure/Entra and would like to use those but there are a ton.&amp;nbsp; Do most people go through each category and only select the US options (assuming you're in the US) and even then I'm not familiar with what categories would be needed for basic Entra/Intune connectivity.&lt;/P&gt;&lt;P&gt;For example... I was going to go through each category and pick out each one of these but then it got to be a bit cumbersome:&lt;/P&gt;&lt;P&gt;Public - Central US&lt;BR /&gt;Public - East US&lt;BR /&gt;Public - North Central US&lt;BR /&gt;Public - South Central US&lt;BR /&gt;Public - West Central US&lt;BR /&gt;Public - West US&lt;/P&gt;&lt;P&gt;Just looking to see what other places are doing to tackle this issue.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2024 21:27:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Entra-Azure-Services/m-p/204721#M33969</guid>
      <dc:creator>VikingsFan</dc:creator>
      <dc:date>2024-01-31T21:27:25Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice for Entra/Azure Services?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Entra-Azure-Services/m-p/204726#M33970</link>
      <description>&lt;P&gt;Thats exactly what I did for one customer, based on location. Another client simply wanted cloud services allowed in general.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2024 22:47:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Entra-Azure-Services/m-p/204726#M33970</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-31T22:47:05Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice for Entra/Azure Services?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Entra-Azure-Services/m-p/204728#M33971</link>
      <description>&lt;P&gt;Appreciate the response!&amp;nbsp; I was hoping there was an easier/better way than going through the 93 Azure Public Services and then checking off potentially 6 geo locations inside each one... that's a lot of clicking. &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&amp;nbsp; It would be nice if CheckPoint had a higher level category like they have for Germany (Azure Germany Services).&lt;/P&gt;&lt;P&gt;Since this will most likely be many, many objects.. I'm guessing these can all go into a network group and then the group applied to the security rule?&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2024 23:21:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Entra-Azure-Services/m-p/204728#M33971</guid>
      <dc:creator>VikingsFan</dc:creator>
      <dc:date>2024-01-31T23:21:58Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice for Entra/Azure Services?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Entra-Azure-Services/m-p/204730#M33972</link>
      <description>&lt;P&gt;I know, I know, lots of clicking in IT world generally haha. Anywho, you are right, you add them, click any, ctrl+a to select all, right click and then select to group them.&lt;/P&gt;
&lt;P&gt;I agree with your point. I also wish there were objects that represent say specific region, rather than 10 or 15 of them, but hey, it is what it is...there are way worse things in life : - )&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2024 23:27:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Entra-Azure-Services/m-p/204730#M33972</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-31T23:27:29Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice for Entra/Azure Services?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Entra-Azure-Services/m-p/204837#M33985</link>
      <description>&lt;P&gt;Updatable Objects use vendor-provided information to populate.&lt;BR /&gt;If the vendor doesn’t provide it at the desired level of granularity (I.e. Microsoft), we can’t.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 02:36:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Entra-Azure-Services/m-p/204837#M33985</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-02-02T02:36:53Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice for Entra/Azure Services?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Entra-Azure-Services/m-p/204913#M34010</link>
      <description>&lt;P&gt;Think I understand.&amp;nbsp; What I was referring to is using exactly what is in the tree list but haven't them pre-grouped by the geolocation.&amp;nbsp; Similar to how China and Germany already have their own top level folder.&amp;nbsp; As it is now, if I wanted only US services, I'll have to go through 93 subfolders and choose up to 6 or 7 US locations under each one.&amp;nbsp; Not sure if you meant the tree structure is exactly how Microsoft sends it and it can't be adjusted.&lt;/P&gt;&lt;P&gt;Not a huge deal and was mainly looking for ideas if there was a better way.&amp;nbsp; Thanks!&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-02-02_15-37-39.png" style="width: 396px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24359i12744CB8B5B5FB76/image-size/large?v=v2&amp;amp;px=999" role="button" title="2024-02-02_15-37-39.png" alt="2024-02-02_15-37-39.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 20:42:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Entra-Azure-Services/m-p/204913#M34010</guid>
      <dc:creator>VikingsFan</dc:creator>
      <dc:date>2024-02-02T20:42:08Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice for Entra/Azure Services?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Entra-Azure-Services/m-p/204915#M34011</link>
      <description>&lt;P&gt;I dont believe there is better way sadly, but I could be mistaken : - )&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 20:56:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Entra-Azure-Services/m-p/204915#M34011</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-02T20:56:18Z</dc:date>
    </item>
  </channel>
</rss>

