<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cloud Identity Engine Azure AD as a service in Cloud Identity Engine Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cloud-identity-engine-azure-ad-as-a-service/m-p/512897#M25</link>
    <description>&lt;P&gt;I am confused about Cloud Identity,, on how and what to use for Azure AD as a service to map IP's to username when users login to Azure AD from their surface device.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 24 Aug 2022 19:50:34 GMT</pubDate>
    <dc:creator>markk96</dc:creator>
    <dc:date>2022-08-24T19:50:34Z</dc:date>
    <item>
      <title>Cloud Identity Engine Azure AD as a service</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cloud-identity-engine-azure-ad-as-a-service/m-p/512897#M25</link>
      <description>&lt;P&gt;I am confused about Cloud Identity,, on how and what to use for Azure AD as a service to map IP's to username when users login to Azure AD from their surface device.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2022 19:50:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cloud-identity-engine-azure-ad-as-a-service/m-p/512897#M25</guid>
      <dc:creator>markk96</dc:creator>
      <dc:date>2022-08-24T19:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cloud Identity Engine Azure AD as a service</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cloud-identity-engine-azure-ad-as-a-service/m-p/520761#M33</link>
      <description>&lt;P&gt;Basically you are using SAML IdP that is the Azure AD and the cloud identity engine is the SAML SP and it gets the Azure data like user and ad group , email address etc. from the Azure AD after the user authenticates on it like SAML assertions that are insterted in the User browser request after the Azure AD authenticates the user and returns them to Prisma Acccess &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cloud-identity/cloud-identity-engine-getting-started/authenticate-users-with-the-cloud-identity-engine/configure-an-identity-provider-in-the-cloud-identity-engine/configure-azure-as-an-idp-in-the-cloud-identity-engine" target="_blank"&gt;https://docs.paloaltonetworks.com/cloud-identity/cloud-identity-engine-getting-started/authenticate-users-with-the-cloud-identity-engine/configure-an-identity-provider-in-the-cloud-identity-engine/configure-azure-as-an-idp-in-the-cloud-identity-engine&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After you have registered the Application that will be used for SAML in the Azure AD portal you can even select what data will be returned to Prisma Access:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nikoolayy1_0-1667987683652.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/45226iDCFCB775E82118CF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="nikoolayy1_0-1667987683652.png" alt="nikoolayy1_0-1667987683652.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also you can add as a bonus SCIM for extra sync between Azure AD and CIE as SAML is too static and if you block a user on Azure AD it will take time before he is blocked on the Prisma Access but SCIM solves this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cloud-identity/cloud-identity-engine-getting-started/choose-directory-type/configure-a-cloud-based-directory/configure-scim-connector-for-the-cloud-identity-engine" target="_blank"&gt;https://docs.paloaltonetworks.com/cloud-identity/cloud-identity-engine-getting-started/choose-directory-type/configure-a-cloud-based-directory/configure-scim-connector-for-the-cloud-identity-engine&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 09:55:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cloud-identity-engine-azure-ad-as-a-service/m-p/520761#M33</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2022-11-09T09:55:13Z</dc:date>
    </item>
  </channel>
</rss>

