Palo Alto Networks Identity and Access Management
Unified identity and access management capability for managing service accounts, access policies, roles, tenant service groups, and subscriptions across SASE IAM, Tenancy, and Subscription APIs.
What You Can Do
MCP Tools
list-service-accounts
List all SASE service accounts with optional filtering by TSG.
create-service-account
Create a new SASE service account.
get-service-account
Get details of a specific service account by ID.
update-service-account
Update an existing service account.
delete-service-account
Delete a service account by ID.
generate-service-account-credentials
Generate credentials for a service account.
revoke-service-account-key
Revoke a specific key for a service account.
list-access-policies
List all access policies with optional filtering.
create-access-policy
Create a new access policy.
get-access-policy
Get details of a specific access policy by ID.
update-access-policy
Update an existing access policy.
delete-access-policy
Delete an access policy by ID.
list-roles
List all available SASE roles.
list-tenant-service-groups
List all tenant service groups with optional filtering.
create-tenant-service-group
Create a new tenant service group.
get-tenant-service-group
Get details of a specific tenant service group.
update-tenant-service-group
Update an existing tenant service group.
delete-tenant-service-group
Delete a tenant service group.
list-child-tenant-service-groups
List child tenant service groups for a given parent.
list-subscriptions
List all subscriptions for a tenant service group.
get-subscription
Get details of a specific subscription.
get-subscription-entitlements
Get entitlements for a specific subscription.
allocate-licenses
Allocate licenses from a subscription to tenant service groups.