Cloud Identity Engine Group Mapping

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Cloud Identity Engine Group Mapping

L2 Linker

It seems like guest users arent matching any groups with Cloud Identity Engine. We have SAML (Azure) setup for our GlobalProtect authentication (not throught Cloud Identity Engine). We have CIE configured on the firewall under user identification. The Cloud Identity Engine is configured to sync the Azure directory but if I look on the firewall using show user user-ids match-user it shows no groups. We have on-prem users that sync up to Azure and those pull groups fine however the guest accounts do not, so accounta we invite into Azure and arent synced on prem dont match any groups.


If I go to CIE itself I can see the user there and the groups they are a part of but the firewall doesnt pull any of those groups, the certain groups are used for different agent configs for GlobalProtect. Is there a reason if wouldn't be pulling the groups that it should need? Do I need to use a SAML auth profile through CIE itself?


Running command "show user cloud-identity-engine statistics all" returns Failed with error code: -20001


Configure the Cloud Identity Engine as a Mapping Source on the Firewall (


Cyber Elite
Cyber Elite
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!