<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Prisma Access CIE and User-ID mapping not working for groups in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-cie-and-user-id-mapping-not-working-for-groups/m-p/1245340#M1258</link>
    <description>&lt;P&gt;the first thing you should check in this case is the user attribute mapping:&lt;/P&gt;
&lt;P&gt;in the prisma access (or global) configuration scope, go to Identity Services &amp;gt; Cloud Identity Engine&lt;/P&gt;
&lt;P&gt;verify what the primary username is set to and compare that to the usernames you are seeing from the user-id agent&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if the userid agent sends you domain\user, set the CIE primary to SAM Account Name, if the format is &lt;A href="mailto:user@domain," target="_blank" rel="noopener"&gt;user@domain,&lt;/A&gt;&amp;nbsp;set the primary to User Principal Name&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this can happen if you instruct CIE to fetch one type of username format while receiving a different format from the uidagent i.e. your groups come loaded with username references that don't match the actual usernames&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="reaper_0-1768212465770.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70317i63914E9344BBD6DF/image-size/large?v=v2&amp;amp;px=999" role="button" title="reaper_0-1768212465770.png" alt="reaper_0-1768212465770.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 12 Jan 2026 10:08:52 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2026-01-12T10:08:52Z</dc:date>
    <item>
      <title>Prisma Access CIE and User-ID mapping not working for groups</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-cie-and-user-id-mapping-not-working-for-groups/m-p/1245308#M1257</link>
      <description>&lt;P&gt;Hi, all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks in advance for any help about an issue we are facing with User-ID agent on on-prem and EntraID with CIE integration.Let me explain our topology a bit deeper:&lt;/P&gt;
&lt;P&gt;On the one hand, we have a Remote Network with some Windows servers without GP or Prisma Access agent. We use User-ID agent for username-to-IP mapping. This is sent to local NGFW, and from there to Prisma Access. It runs fine, coz on UserID logs in Prisma I can see the users there.&lt;/P&gt;
&lt;P&gt;On the other hand, AD is federated with EntraID and CIE collects certain test users and groups. I can see that a particular test user is on EntraID and also in CIE inside a certain group. On Prisma Access CIE configuration I can see that a number of groups and users are there.&lt;/P&gt;
&lt;P&gt;So, if we create a rule on Prisma Access (with Strata Cloud Manager), we can select both the groups and the users as source. If we choose user (brought by CIE), the username-to-IP mapping works, and the rule matches. But if we use the group in the rule, the username-to-IP mapping seems to be avoided and the rule doesn't match.&lt;/P&gt;
&lt;P&gt;Did anyone faced this before? I think it should work. Group rules are not only for agent based workstations, right?&lt;/P&gt;
&lt;P&gt;Many thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jan 2026 15:54:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-cie-and-user-id-mapping-not-working-for-groups/m-p/1245308#M1257</guid>
      <dc:creator>IvanBermejo</dc:creator>
      <dc:date>2026-01-09T15:54:00Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Access CIE and User-ID mapping not working for groups</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-cie-and-user-id-mapping-not-working-for-groups/m-p/1245340#M1258</link>
      <description>&lt;P&gt;the first thing you should check in this case is the user attribute mapping:&lt;/P&gt;
&lt;P&gt;in the prisma access (or global) configuration scope, go to Identity Services &amp;gt; Cloud Identity Engine&lt;/P&gt;
&lt;P&gt;verify what the primary username is set to and compare that to the usernames you are seeing from the user-id agent&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if the userid agent sends you domain\user, set the CIE primary to SAM Account Name, if the format is &lt;A href="mailto:user@domain," target="_blank" rel="noopener"&gt;user@domain,&lt;/A&gt;&amp;nbsp;set the primary to User Principal Name&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this can happen if you instruct CIE to fetch one type of username format while receiving a different format from the uidagent i.e. your groups come loaded with username references that don't match the actual usernames&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="reaper_0-1768212465770.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70317i63914E9344BBD6DF/image-size/large?v=v2&amp;amp;px=999" role="button" title="reaper_0-1768212465770.png" alt="reaper_0-1768212465770.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2026 10:08:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-cie-and-user-id-mapping-not-working-for-groups/m-p/1245340#M1258</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2026-01-12T10:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Access CIE and User-ID mapping not working for groups</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-cie-and-user-id-mapping-not-working-for-groups/m-p/1245560#M1260</link>
      <description>&lt;P&gt;Thanks for your answer, Reaper. I checked the configuration and seems to be right, since we are receiving our users from User-ID in a domain\username format.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IvanBermejo_0-1768405884124.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70350i08A0D1D65154CE17/image-size/medium?v=v2&amp;amp;px=400" role="button" title="IvanBermejo_0-1768405884124.png" alt="IvanBermejo_0-1768405884124.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;In fact, as I said, if we use the username in the rule, it matches. The group in CIE is synchronizing (I filtered to one name, and I can see the group and the user in CIE), and the numbers in Prisma Access are the same. The group is selectable in the rule, but the user in the group doesn't match the rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any way to check the group-to-user mapping in Prisma Access? Any other ideas?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jan 2026 16:01:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-cie-and-user-id-mapping-not-working-for-groups/m-p/1245560#M1260</guid>
      <dc:creator>IvanBermejo</dc:creator>
      <dc:date>2026-01-14T16:01:36Z</dc:date>
    </item>
  </channel>
</rss>

