<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CIE Azure AD/Entra AD guest upn match Global Protect login user in Cloud Identity Engine Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cie-azure-ad-entra-ad-guest-upn-match-global-protect-login-user/m-p/589737#M66</link>
    <description>&lt;P&gt;I am trying to see how I can get the Cloud Identity Engine to match Global Protect SSO (Also from Azure AD/Entra) upn for the user.&amp;nbsp; I have a sister company that I have invite certain users in as external guests and added them to aad groups, which is assigned to allow them to connect to AAD enterprise app for Saml SSO.&amp;nbsp; But CIE will return different upn than what the sso returns back to the palo alto.&amp;nbsp; I honestly do not care which one of these formats it uses, as long as they consistent matches. The main issue is the CIE and the global protect logins don't match for the same user, so its not possible to tie the user to the AAD groups CIE populates.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Global protect will identify the user like &lt;A href="mailto:jwoodman@example.com" target="_blank"&gt;jwoodman@example.com&lt;/A&gt; and CIE will be jwoodman_example_com#ext#@example2.onmicrosoft.com&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;While if the user have mail setup, you could go off that.&amp;nbsp; But this being a sister company, we have some of these users already setup as contacts, and it will not allow those users to save there email address. It says there is already a proxy addresses. Instead it places there email address in the other mail property.&amp;nbsp; I'm assuming I need to go the route of setting up Azure AD/Entra SAML transformations for the nameidentifier, as I don't see a way of changing the Cloud Identity Engine behavior. Curious if anyone has done this before.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 18 Jun 2024 00:16:48 GMT</pubDate>
    <dc:creator>JustinWoodman</dc:creator>
    <dc:date>2024-06-18T00:16:48Z</dc:date>
    <item>
      <title>CIE Azure AD/Entra AD guest upn match Global Protect login user</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cie-azure-ad-entra-ad-guest-upn-match-global-protect-login-user/m-p/589737#M66</link>
      <description>&lt;P&gt;I am trying to see how I can get the Cloud Identity Engine to match Global Protect SSO (Also from Azure AD/Entra) upn for the user.&amp;nbsp; I have a sister company that I have invite certain users in as external guests and added them to aad groups, which is assigned to allow them to connect to AAD enterprise app for Saml SSO.&amp;nbsp; But CIE will return different upn than what the sso returns back to the palo alto.&amp;nbsp; I honestly do not care which one of these formats it uses, as long as they consistent matches. The main issue is the CIE and the global protect logins don't match for the same user, so its not possible to tie the user to the AAD groups CIE populates.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Global protect will identify the user like &lt;A href="mailto:jwoodman@example.com" target="_blank"&gt;jwoodman@example.com&lt;/A&gt; and CIE will be jwoodman_example_com#ext#@example2.onmicrosoft.com&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;While if the user have mail setup, you could go off that.&amp;nbsp; But this being a sister company, we have some of these users already setup as contacts, and it will not allow those users to save there email address. It says there is already a proxy addresses. Instead it places there email address in the other mail property.&amp;nbsp; I'm assuming I need to go the route of setting up Azure AD/Entra SAML transformations for the nameidentifier, as I don't see a way of changing the Cloud Identity Engine behavior. Curious if anyone has done this before.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2024 00:16:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-identity-engine/cie-azure-ad-entra-ad-guest-upn-match-global-protect-login-user/m-p/589737#M66</guid>
      <dc:creator>JustinWoodman</dc:creator>
      <dc:date>2024-06-18T00:16:48Z</dc:date>
    </item>
  </channel>
</rss>

