<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CIE group (created on EntraID and Okta) visible in CIE but not recognized by PAN-OS firewall in Cloud Identity Engine Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cie-group-created-on-entraid-and-okta-visible-in-cie-but-not/m-p/1264422#M103</link>
    <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I’m troubleshooting a CIE group mapping issue on a firewall and would appreciate some advice.&lt;/P&gt;
&lt;P&gt;The setup is:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;PAN-OS 11.1.13-h9&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Panorama-managed firewall&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;CIE using Okta as the directory source&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Okta receives groups from both its own directory and MS Entra&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;GP uses these groups in Portal Agent Config and Gateway configuration&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;6 existing groups from the same CIE directory work correctly. However, newly created groups are not recognized by the firewall.&lt;/P&gt;
&lt;P&gt;I tested 2 different cases:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;A group created in Entra and synchronized to Okta.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;A group created directly in Okta, to eliminate the Entra-Okta sync path.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;In both cases:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;The group is visible in the CIE directory.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;The group has members.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;The group is added to the GP Portal Agent Config.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;The group is addded to the Gateway configuration.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;The group is also referenced in a Security Policy (suggestion of our PA support)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;The pushed configuration contains the correct group name and domain separator.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;I manually forced a CIE refresh.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The direct lookup fails: &lt;EM&gt;show user group name "cie-domain\GP-Ring1"&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Result: User group 'cie-domain\GP-Ring1' does not exist or does not have members&lt;/P&gt;
&lt;P&gt;The CIE sync status itself reports success, and 6 other groups (created on Okta or Entra) from the same directory are available on the firewall.&lt;/P&gt;
&lt;P&gt;At this point, I’m trying to understand whether:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;CIE groups are only retrieved under specific conditions&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;the group must be associated with an authenticated user before it appears&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;there is a cache or refresh issue on the firewall ??&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;a particular CIE or PAN-OS command is required to request the group explicitly ??&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;An known issue with 11.1.13&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone seen this behavior with CIE and Okta, especially when Okta itself receives groups from both Entra ID and its own directory?&lt;/P&gt;
&lt;P&gt;Thanks !!&lt;/P&gt;</description>
    <pubDate>Tue, 15 Sep 2026 16:44:00 GMT</pubDate>
    <dc:creator>Meed</dc:creator>
    <dc:date>2026-09-15T16:44:00Z</dc:date>
    <item>
      <title>CIE group (created on EntraID and Okta) visible in CIE but not recognized by PAN-OS firewall</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cie-group-created-on-entraid-and-okta-visible-in-cie-but-not/m-p/1264422#M103</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I’m troubleshooting a CIE group mapping issue on a firewall and would appreciate some advice.&lt;/P&gt;
&lt;P&gt;The setup is:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;PAN-OS 11.1.13-h9&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Panorama-managed firewall&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;CIE using Okta as the directory source&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Okta receives groups from both its own directory and MS Entra&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;GP uses these groups in Portal Agent Config and Gateway configuration&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;6 existing groups from the same CIE directory work correctly. However, newly created groups are not recognized by the firewall.&lt;/P&gt;
&lt;P&gt;I tested 2 different cases:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;A group created in Entra and synchronized to Okta.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;A group created directly in Okta, to eliminate the Entra-Okta sync path.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;In both cases:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;The group is visible in the CIE directory.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;The group has members.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;The group is added to the GP Portal Agent Config.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;The group is addded to the Gateway configuration.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;The group is also referenced in a Security Policy (suggestion of our PA support)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;The pushed configuration contains the correct group name and domain separator.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;I manually forced a CIE refresh.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The direct lookup fails: &lt;EM&gt;show user group name "cie-domain\GP-Ring1"&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Result: User group 'cie-domain\GP-Ring1' does not exist or does not have members&lt;/P&gt;
&lt;P&gt;The CIE sync status itself reports success, and 6 other groups (created on Okta or Entra) from the same directory are available on the firewall.&lt;/P&gt;
&lt;P&gt;At this point, I’m trying to understand whether:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;CIE groups are only retrieved under specific conditions&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;the group must be associated with an authenticated user before it appears&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;there is a cache or refresh issue on the firewall ??&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;a particular CIE or PAN-OS command is required to request the group explicitly ??&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;An known issue with 11.1.13&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone seen this behavior with CIE and Okta, especially when Okta itself receives groups from both Entra ID and its own directory?&lt;/P&gt;
&lt;P&gt;Thanks !!&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2026 16:44:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cie-group-created-on-entraid-and-okta-visible-in-cie-but-not/m-p/1264422#M103</guid>
      <dc:creator>Meed</dc:creator>
      <dc:date>2026-09-15T16:44:00Z</dc:date>
    </item>
  </channel>
</rss>

