Okay, hi everyone. I’ve been lurking for a bit but this is my first post, so apologies if I ramble or sound confused (I probably am!).
We finally switched our Prisma Access to use only FQDN objects in the security policies, like the best practice guides suggest. I was so nervous about breaking everything, but I figured it was time to stop using IP addresses.
Well... it was a bit of a shock. So many things I thought were simple turned out to have weird hidden connections. Our internal timekeeping app, for example, kept failing. Turns out it wasn't just talking to its own server—it was reaching out to a random analytics subdomain we didn't even know about. Oops. 😅
Has anyone else gone through this FQDN-only switch? I'd love to hear about the unexpected app dependencies you found. It feels like I'm cleaning out a closet and finding things I forgot I owned.