<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: On-Prem Firewall &amp;amp; Cloud Identity Engine for SAML GP in Cloud Identity Engine Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cloud-identity-engine/on-prem-firewall-amp-cloud-identity-engine-for-saml-gp/m-p/1259880#M98</link>
    <description>&lt;P&gt;CIE acts like a middle man so yes it will work with Microsoft Entra ID . CIE needs to also be connected to Entra ID as to then collect user groups for authorization purposes as not only the user to be allowed but to have rules to allow specific AD groups.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/identity/cloud-identity-engine/authenticate-users-with-the-cloud-identity-engine/set-up-a-saml-2-0-authentication-type" target="_blank"&gt;Set Up a SAML 2.0 Authentication Type&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/identity/cloud-identity-engine/identify-users-and-devices-with-cie/choose-directory-type/configure-a-cloud-based-directory/set-up-azure-directory" target="_blank"&gt;Set Up an Entra ID Directory&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/identity/cloud-identity-engine/authenticate-users-with-the-cloud-identity-engine" target="_blank"&gt;Authenticate Users with the Cloud Identity Engine&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/identity/cloud-identity-engine/identify-users-and-devices-with-cie/redistribute-identification-information-from-ngfws-to-the-cloud/configure-the-cloud-identity-engine-as-a-mapping-source" target="_blank"&gt;Configure the Cloud Identity Engine as a Mapping Source&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 24 Jul 2026 07:34:12 GMT</pubDate>
    <dc:creator>nikoolayy1</dc:creator>
    <dc:date>2026-07-24T07:34:12Z</dc:date>
    <item>
      <title>On-Prem Firewall &amp; Cloud Identity Engine for SAML GP</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-identity-engine/on-prem-firewall-amp-cloud-identity-engine-for-saml-gp/m-p/1257236#M96</link>
      <description>&lt;P&gt;Hi folks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a question regarding GlobalProtect authentication using SAML and Cloud Identity Engine (CIE).&lt;/P&gt;
&lt;P&gt;Current setup:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Users authenticate to Prisma Access using SAML.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;The Identity Provider is Microsoft Entra ID.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Cloud Identity Engine (CIE) is already integrated with Entra ID and working successfully for Prisma Access users.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;What I would like to achieve:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Deploy GlobalProtect on an on-premises Palo Alto firewall.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Reuse the existing CIE tenant and Entra ID integration rather than creating a separate SAML integration directly between the firewall and Entra ID.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;I came across the following documentation:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/identity/cloud-identity-engine/identify-users-and-devices-with-cie/redistribute-identification-information-from-ngfws-to-the-cloud/configure-the-cloud-identity-engine-as-a-mapping-source/configure-the-cloud-identity-engine-as-a-mapping-source-on-the-firewall" target="_blank"&gt;https://docs.paloaltonetworks.com/identity/cloud-identity-engine/identify-users-and-devices-with-cie/redistribute-identification-information-from-ngfws-to-the-cloud/configure-the-cloud-identity-engine-as-a-mapping-source/configure-the-cloud-identity-engine-as-a-mapping-source-on-the-firewall&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;My understanding is that CIE is already acting as the identity source and authentication for Prisma users is currently occurring through Entra ID via SAML. Therefore, if I integrate my on-prem firewall with the same CIE tenant and use the corresponding authentication profile for GlobalProtect, would the firewall be able to leverage the existing SAML authentication flow through CIE?&lt;/P&gt;
&lt;P&gt;Or is a separate SAML application/integration between the on-prem firewall and Entra ID still required for GlobalProtect authentication?&lt;/P&gt;
&lt;P&gt;Has anyone implemented a similar design or can clarify whether this architecture is supported?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2026 09:48:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-identity-engine/on-prem-firewall-amp-cloud-identity-engine-for-saml-gp/m-p/1257236#M96</guid>
      <dc:creator>krishna.c</dc:creator>
      <dc:date>2026-06-24T09:48:24Z</dc:date>
    </item>
    <item>
      <title>Re: On-Prem Firewall &amp; Cloud Identity Engine for SAML GP</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-identity-engine/on-prem-firewall-amp-cloud-identity-engine-for-saml-gp/m-p/1259880#M98</link>
      <description>&lt;P&gt;CIE acts like a middle man so yes it will work with Microsoft Entra ID . CIE needs to also be connected to Entra ID as to then collect user groups for authorization purposes as not only the user to be allowed but to have rules to allow specific AD groups.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/identity/cloud-identity-engine/authenticate-users-with-the-cloud-identity-engine/set-up-a-saml-2-0-authentication-type" target="_blank"&gt;Set Up a SAML 2.0 Authentication Type&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/identity/cloud-identity-engine/identify-users-and-devices-with-cie/choose-directory-type/configure-a-cloud-based-directory/set-up-azure-directory" target="_blank"&gt;Set Up an Entra ID Directory&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/identity/cloud-identity-engine/authenticate-users-with-the-cloud-identity-engine" target="_blank"&gt;Authenticate Users with the Cloud Identity Engine&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/identity/cloud-identity-engine/identify-users-and-devices-with-cie/redistribute-identification-information-from-ngfws-to-the-cloud/configure-the-cloud-identity-engine-as-a-mapping-source" target="_blank"&gt;Configure the Cloud Identity Engine as a Mapping Source&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jul 2026 07:34:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-identity-engine/on-prem-firewall-amp-cloud-identity-engine-for-saml-gp/m-p/1259880#M98</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2026-07-24T07:34:12Z</dc:date>
    </item>
  </channel>
</rss>

