<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Prisma Access/Cloud Identity Engine with Okta IDP – Issue with Group Changes in Strata Cloud Manager</title>
    <link>https://live.paloaltonetworks.com/t5/strata-cloud-manager/prisma-access-cloud-identity-engine-with-okta-idp-issue-with/m-p/1227698#M19</link>
    <description>&lt;P class="" data-start="49" data-end="138"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="" data-start="140" data-end="646"&gt;We're encountering an issue when moving users between Okta groups. In the Cloud Identity Engine (CIE), we observe that the user's group membership updates correctly. However, the firewall is not reflecting this change; the user loses access permissions associated with both the new and the old groups. Additionally, firewall logs show the source user as their email ID instead of the expected format (&lt;CODE data-start="541" data-end="566"&gt;okta\firstname.lastname&lt;/CODE&gt;). As a result, security policies based on Okta groups aren't correctly applied.&lt;/P&gt;
&lt;P class="" data-start="648" data-end="826"&gt;Could you advise on how to resolve this? Are there specific configuration settings we might have overlooked, or certain steps we must follow when reassigning user groups in Okta?&lt;/P&gt;</description>
    <pubDate>Tue, 29 Apr 2025 21:37:18 GMT</pubDate>
    <dc:creator>jaswanthwhoop</dc:creator>
    <dc:date>2025-04-29T21:37:18Z</dc:date>
    <item>
      <title>Prisma Access/Cloud Identity Engine with Okta IDP – Issue with Group Changes</title>
      <link>https://live.paloaltonetworks.com/t5/strata-cloud-manager/prisma-access-cloud-identity-engine-with-okta-idp-issue-with/m-p/1227698#M19</link>
      <description>&lt;P class="" data-start="49" data-end="138"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="" data-start="140" data-end="646"&gt;We're encountering an issue when moving users between Okta groups. In the Cloud Identity Engine (CIE), we observe that the user's group membership updates correctly. However, the firewall is not reflecting this change; the user loses access permissions associated with both the new and the old groups. Additionally, firewall logs show the source user as their email ID instead of the expected format (&lt;CODE data-start="541" data-end="566"&gt;okta\firstname.lastname&lt;/CODE&gt;). As a result, security policies based on Okta groups aren't correctly applied.&lt;/P&gt;
&lt;P class="" data-start="648" data-end="826"&gt;Could you advise on how to resolve this? Are there specific configuration settings we might have overlooked, or certain steps we must follow when reassigning user groups in Okta?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 21:37:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/strata-cloud-manager/prisma-access-cloud-identity-engine-with-okta-idp-issue-with/m-p/1227698#M19</guid>
      <dc:creator>jaswanthwhoop</dc:creator>
      <dc:date>2025-04-29T21:37:18Z</dc:date>
    </item>
  </channel>
</rss>

