<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Syncing Specific Entra ID Groups to Cloud Identity Engine in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/syncing-specific-entra-id-groups-to-cloud-identity-engine/m-p/1244683#M7198</link>
    <description>&lt;P data-start="81" data-end="370"&gt;We are planning to integrate CIE with Entra ID to map and authenticate GlobalProtect users. However, after completing the configuration, we observed that all users from Entra ID were synced to the CIE side, even though a filter was configured to include only users from a specific group.&lt;/P&gt;
&lt;P data-start="377" data-end="548"&gt;Could someone please assist us in understanding why this is happening and how we can ensure that only the intended users are synced? Your help would be highly appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 26 Dec 2025 09:58:11 GMT</pubDate>
    <dc:creator>A.Rodrigo</dc:creator>
    <dc:date>2025-12-26T09:58:11Z</dc:date>
    <item>
      <title>Syncing Specific Entra ID Groups to Cloud Identity Engine</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/syncing-specific-entra-id-groups-to-cloud-identity-engine/m-p/1244683#M7198</link>
      <description>&lt;P data-start="81" data-end="370"&gt;We are planning to integrate CIE with Entra ID to map and authenticate GlobalProtect users. However, after completing the configuration, we observed that all users from Entra ID were synced to the CIE side, even though a filter was configured to include only users from a specific group.&lt;/P&gt;
&lt;P data-start="377" data-end="548"&gt;Could someone please assist us in understanding why this is happening and how we can ensure that only the intended users are synced? Your help would be highly appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Dec 2025 09:58:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/syncing-specific-entra-id-groups-to-cloud-identity-engine/m-p/1244683#M7198</guid>
      <dc:creator>A.Rodrigo</dc:creator>
      <dc:date>2025-12-26T09:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: Syncing Specific Entra ID Groups to Cloud Identity Engine</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/syncing-specific-entra-id-groups-to-cloud-identity-engine/m-p/1246047#M7226</link>
      <description>&lt;P&gt;Use Entra ID Group-Based Access Control (Recommended)&lt;BR /&gt;Create a dedicated Entra ID group for GlobalProtect users&lt;BR /&gt;Assign only intended users to this group&lt;/P&gt;
&lt;P&gt;This can only be controlled from EntraID side.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jan 2026 04:08:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/syncing-specific-entra-id-groups-to-cloud-identity-engine/m-p/1246047#M7226</guid>
      <dc:creator>arusharma</dc:creator>
      <dc:date>2026-01-21T04:08:49Z</dc:date>
    </item>
  </channel>
</rss>

