Best Practice Assessment

Turns a Tech Support File or configuration export into a readable compliance report, using the Palo Alto Networks Posture API.

1 · Service account

I don't have a service account — how do I create one?
  1. Palo Alto Networks HubCommon Services → Identity & Access
  2. Select the tenant/TSG the API call should run against
  3. Add Identity → Identity Type: Service Account
  4. Give it a name that is identifiable during an audit (e.g. bpa-report)
  5. Save the Client ID and Client secretthe secret is shown only once
  6. Assign a role (the reference guide suggests All Apps & Services + Superuser)

The TSG ID appears in the tenant selector on the Identity & Access screen.

2 · Configuration file

Drop a Tech Support File (.tgz) or configuration XML here, or click to browse

3 · Report language

Check names and remediation text come from Palo Alto Networks in English and are shown as provided; the report structure and labels are translated.

What happens to your data