<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cloud Identity Engine Directory Sync in Cloud Identity Engine Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cloud-identity-engine-directory-sync/m-p/471473#M12</link>
    <description>&lt;P&gt;Thanks for the reply. The error I see is that the user didn't match a policy in the portal.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have two users in the Azure group that is seen on the firewall via CIE. One user synced from on-prem has the email as the UPN and the other user is a guest in Azure and has a guestuser_email.com#EXT#@xxxxxx.onmicrosoft.com UPN. The users have to log in with email address format to Azure via SAML which works for both users. The on-prem user can map to a portal policy, but guest user cannot. The on-prem user appears in the group with email (same as login), but the guest user shows as UPN which isn't the same as the email login format.&lt;BR /&gt;&lt;BR /&gt;Even though the guest user shows as UPN in the group, the email address used for login is an alternative user id and therefore should be able to map the user to the group referenced in the portal policy. I believe that should be the case.&lt;/P&gt;</description>
    <pubDate>Tue, 08 Mar 2022 19:01:04 GMT</pubDate>
    <dc:creator>CCIE11129</dc:creator>
    <dc:date>2022-03-08T19:01:04Z</dc:date>
    <item>
      <title>Cloud Identity Engine Directory Sync</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cloud-identity-engine-directory-sync/m-p/452631#M6</link>
      <description>&lt;P&gt;I have Cloud Identity Engine synced to Azure AD and see both groups and users in the hub. I configured a firewall to use CIE, but it doesn't appear to be working. I can see the groups and select them in policies, but no users from those groups are seen on the firewall. "show user cloud-identity-engine client stat" shows groups, but they show as unmapped (not sure if it should show mapped). "show user cloud-identity-engine status all" shows the name of the directory APP, but all stats are 0 or say never. Same with "show user cloud-identity-engine statistics all". Any help would be appreciated.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Dec 2021 02:10:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cloud-identity-engine-directory-sync/m-p/452631#M6</guid>
      <dc:creator>CCIE11129</dc:creator>
      <dc:date>2021-12-11T02:10:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cloud Identity Engine Directory Sync</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cloud-identity-engine-directory-sync/m-p/470329#M8</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Housing1_0-1646346073427.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39454i54A575F96A2E39D6/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Housing1_0-1646346073427.png" alt="Housing1_0-1646346073427.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;What did you map here? I am having issues like you&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 22:21:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cloud-identity-engine-directory-sync/m-p/470329#M8</guid>
      <dc:creator>Housing1</dc:creator>
      <dc:date>2022-03-03T22:21:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cloud Identity Engine Directory Sync</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cloud-identity-engine-directory-sync/m-p/470341#M9</link>
      <description>&lt;P&gt;Housing1,&lt;/P&gt;
&lt;P&gt;I'm not doing authentication with Cloud Identity Engine. I'm just trying to get the directory sync part of it working.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 23:21:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cloud-identity-engine-directory-sync/m-p/470341#M9</guid>
      <dc:creator>CCIE11129</dc:creator>
      <dc:date>2022-03-03T23:21:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cloud Identity Engine Directory Sync</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cloud-identity-engine-directory-sync/m-p/470626#M10</link>
      <description>&lt;P&gt;I was able to get Cloud Identity Engine working on the firewall. I changed the service interface for "Palo Alto Network Services" to use the outside interface instead of the default management interface. This didn't work at first until I removed the Cloud Identity Engine config on the firewall and re-added it.&lt;BR /&gt;&lt;BR /&gt;With that being said, my new issue is that the CIE group doesn't seem to work for GlobalProtect portal config for agent match criteria. I am able to configure it, but it doesn't seem to work for matching the user even though I see the user and group information on the firewall through CLI which looks correct.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2022 20:57:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cloud-identity-engine-directory-sync/m-p/470626#M10</guid>
      <dc:creator>CCIE11129</dc:creator>
      <dc:date>2022-03-04T20:57:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cloud Identity Engine Directory Sync</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cloud-identity-engine-directory-sync/m-p/471447#M11</link>
      <description>&lt;P&gt;Is there an error? maybe in agent log file? I finally got mine working with users and groups in my policies.&amp;nbsp; I haven't tried GlobalProtect yet.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 18:34:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cloud-identity-engine-directory-sync/m-p/471447#M11</guid>
      <dc:creator>Housing1</dc:creator>
      <dc:date>2022-03-08T18:34:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cloud Identity Engine Directory Sync</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cloud-identity-engine-directory-sync/m-p/471473#M12</link>
      <description>&lt;P&gt;Thanks for the reply. The error I see is that the user didn't match a policy in the portal.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have two users in the Azure group that is seen on the firewall via CIE. One user synced from on-prem has the email as the UPN and the other user is a guest in Azure and has a guestuser_email.com#EXT#@xxxxxx.onmicrosoft.com UPN. The users have to log in with email address format to Azure via SAML which works for both users. The on-prem user can map to a portal policy, but guest user cannot. The on-prem user appears in the group with email (same as login), but the guest user shows as UPN which isn't the same as the email login format.&lt;BR /&gt;&lt;BR /&gt;Even though the guest user shows as UPN in the group, the email address used for login is an alternative user id and therefore should be able to map the user to the group referenced in the portal policy. I believe that should be the case.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 19:01:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cloud-identity-engine-directory-sync/m-p/471473#M12</guid>
      <dc:creator>CCIE11129</dc:creator>
      <dc:date>2022-03-08T19:01:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cloud Identity Engine Directory Sync</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cloud-identity-engine-directory-sync/m-p/520616#M31</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am having an issue whereby we have activated CIE on Panorama however no groups or users are coming through.the command s&lt;SPAN&gt;how user cloud-identity-engine client stat" shows 0 for everything. Any ideas?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 07:49:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cloud-identity-engine-directory-sync/m-p/520616#M31</guid>
      <dc:creator>Nisha_Bharadia</dc:creator>
      <dc:date>2022-11-08T07:49:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cloud Identity Engine Directory Sync</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cloud-identity-engine-directory-sync/m-p/520727#M32</link>
      <description>&lt;P&gt;I had 0s for everything until I changed Palo Alto Network Services to use the outside interface instead of the management interface.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 19:14:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cloud-identity-engine-directory-sync/m-p/520727#M32</guid>
      <dc:creator>CCIE11129</dc:creator>
      <dc:date>2022-11-09T19:14:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cloud Identity Engine Directory Sync</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cloud-identity-engine-directory-sync/m-p/522010#M34</link>
      <description>&lt;P&gt;Have the exact same issue, can't get guest user to select configuration and the user is listed under "Unmapped Groups" when running &lt;EM&gt;show user cloud-identity-engine client statistics.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you get any further?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 10:56:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cloud-identity-engine-directory-sync/m-p/522010#M34</guid>
      <dc:creator>Johande</dc:creator>
      <dc:date>2022-11-22T10:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cloud Identity Engine Directory Sync</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cloud-identity-engine-directory-sync/m-p/527775#M35</link>
      <description>&lt;P&gt;PanOS 10.2.3-h2&lt;/P&gt;
&lt;P&gt;I've configured CIE in Panorama; it shows Enabled. All behavior I see is exactly like all others in this thread. Via CLI, I have zeros on everything relating to CIE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the same config elements on a firewall (also connected/managed by panorama FWIW), I have configured in the same way. CLI shows zeros just like with panorama.&amp;nbsp;&lt;EM&gt;But...&lt;/EM&gt; creating a security policy on the firewall and browsing groups shows all groups synched from azureAD. It's there. I haven't found documentation about the CLI commands, nor any relating to CIE and group-mapping beyond "here is a section where you can pick what attributes a group is in your cloud environment."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I double checked this on Panorama by way of creating a sample security rule and browsing for source groups and I got nothing on that end.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 21:00:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cloud-identity-engine-directory-sync/m-p/527775#M35</guid>
      <dc:creator>BenKnorr2</dc:creator>
      <dc:date>2023-01-19T21:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cloud Identity Engine Directory Sync</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cloud-identity-engine-directory-sync/m-p/527781#M36</link>
      <description>&lt;P&gt;Before I changed the CIE to use outside interface to get it to work, I was seeing the 0 stats and never run under CLI commands. During the period where it showed this, I would select groups in security policies and then see them listed, but could never see a user mapped to it. I think it actually showed in "unmapped" section of the CLI. I put a user in a security policy and then could see the user in CLI but still not mapped to a group. I swore that I could see users and groups in the CLI. Changed to use outside interface to communicate to CIE and everything started working then I could see that previously I wasn't actually seeing info pulled from CIE.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 21:17:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cloud-identity-engine-directory-sync/m-p/527781#M36</guid>
      <dc:creator>CCIE11129</dc:creator>
      <dc:date>2023-01-19T21:17:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cloud Identity Engine Directory Sync</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cloud-identity-engine-directory-sync/m-p/587891#M65</link>
      <description>&lt;P&gt;This sounds like you had a security policy in your way, and you bypassed it by using an 'untrust' to 'untrust' route instead.&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2024 14:06:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cloud-identity-engine-directory-sync/m-p/587891#M65</guid>
      <dc:creator>PaulArcellx</dc:creator>
      <dc:date>2024-05-24T14:06:42Z</dc:date>
    </item>
  </channel>
</rss>

