---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Approve EDL entries for Palo Alto Networks Next-Generation Firewall

# Approve EDL entries for Palo Alto Networks Next-Generation Firewall {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

An approval process for External Dynamic List (EDL) entries is part of the
preconfigured workflow. You approve EDL entries before the entries are activated on EDLs.
One you approve the EDL entry, the firewall retrieves the entry, and your observable is
blocked from that point forward.

## Before you begin

Role required: Approval for EDL entries is assigned to sn_si.admin by default, but
this authority can be assigned as required by your organization. In the following
example, the ServiceNow AI Platform admin
has approval authority.

## About this task

When the approval process is enabled, an EDL entry is not activated or deactivated on the EDL until it is approved.

## Procedure

1. Navigate to AllPalo Alto Networks NGFW IntegrationFirewall EDL Entries and open the EDL record.
2. On the EDL record, scroll to the Approval Requests section.  
   Note:  
   If you have Tabbed forms selected in System Settings, the section appears as a tab on the record.
3. In Approval requests, select an item in the State column to open it.  
   The approval record is displayed.
4. Choose one option for approving the EDL entry.

   | Option | Description |
   | Approve | On the entry record, the Status field changes to Added, and the Active check box is selected. The Deactivatebutton is displayed and active. Work notes show that the request for the EDL entry has been approved. |
   | Reject | On the entry record, the Status field changes to Rejected, and the Active check box is cleared indicating the entry is not blocked on the firewall. Work notes show that the request for the EDL entry has been rejected. |
   |-|-|

   {#paloalto-apprv-edl-entries-sncr__choicetable_xbq_cvh_vdb}  
   After you have approved the EDL entry and it is activated, the Palo Alto Networks Next-Generation Firewall retrieves the EDL entry after the next retrieval interval. After the entry is retrieved, the observable is blocked from that point forward. Note that the Active check box is selected, the status is Added, and the work notes indicate that the request has been approved.

   After the EDL entry is approved and activated, the security incident record is marked with a security tag. The tag is displayed at the
   top of the record.

   The security tag is also displayed on the observable record.
**Previous topic:** [Submit EDL entries from the blocklist for Palo Alto Networks Next-Generation Firewall](https://servicenow-prod.fluidtopics.net/qUEZ4ze3xgn87l8yqggPKw "For observables determined to be malicious, and not associated with a specific ServiceNow AI Platform security incident, you submit External Dynamic List (EDL) entries from the blocklist.")  
**Next topic:** [EDL entry exceptions for Palo Alto Networks Next-Generation Firewall](https://servicenow-prod.fluidtopics.net/iNZctX7fSJN_85AAzJ5CAA "There are restrictions for adding External Dynamic List (EDL) entries to EDLs. If duplicate, compatibility, or CIDR (Classless Inter-Domain Routing) conflicts exist when you try to add EDL entries to EDLs, error messages are displayed that help you resolve these errors.")

*[\>]: and then


