February 26, 2024 Release
Secure Edge New Features: February 26, 2024
Security Subscriptions
CASB inline cloud application activity controls—You can configure rules to control activities on the cloud applications for a Cloud Access Security Broker (CASB) profile. Juniper Secure Edge now supports the following newly added cloud applications and features:
Gmail—Login, Read, Compose, Send, Upload Attachment, and Download Attachment
SharePoint—Login, Upload, Download, and Share
Slack—Login, Chat, Audio/Video, and File Transfer
[See Add Rules to a CASB Profile.]
Service Management
Sites—You can now see a hierarchy-based structure on the Sites page (Secure Edge > Service Management > Sites). You can also perform the following tasks:
Expand the specific site name to view details about the customer premises equipment (CPE) devices on the Sites page.
Enable external probe settings when creating a site.
Configure the following Traffic Forwarding settings:
Two or more CPE devices for a single site
External interfaces to CPE devices
One or more tunnels to a CPE device depending on the number of users per site
Tunnel type as either IPsec or GRE to forward the traffic
Configure CPE routing settings such as the primary service location.
[See About the Sites Page.]
External Probe
External Probe—You can now configure the probe settings to enable external probe for a site. With this configuration, customer premises equipment (CPE) devices can monitor the tunnel health status. To navigate to the External Probe page, select Secure Edge > Service Management > External Probe.
Administration
Log streaming—With log streaming, you can now forward audit logs, session logs, and security events from Juniper Secure Edge Cloud to an external security information and event management (SIEM) system via webhook, such as Microsoft Sentinel. On the Log Streaming page, you can configure the type of log to forward to the external SIEM system. [See About the Log Streaming Page.]
Additionally, you can create a log stream report. You can create a report for the current or previous month or the entire period of data transfer to the SIEM system. [See Create Log Streaming Report Definitions.]
Identity Management
User group retrieval from Microsoft Entra ID and Okta—You can now configure the identity provider (IdP) settings in Juniper Secure Edge to retrieve user group information from Microsoft Entra ID (previously known as Azure Active Directory) and Okta. Prior to this release, you had to deploy on-premises Juniper® Identity Management Service (JIMS) collector to retrieve user group information from Active Directory.
To retrieve user group information, log in to the Juniper Security Director Cloud portal, navigate to Secure Edge > Identity > User Authentication > SAML, and enter the required information to configure IdP. Juniper Secure Edge receives user group information from Microsoft Entra ID or Okta. You can use the user groups to manage security policies.