Cloud Identity Engine Group Mapping

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Cloud Identity Engine Group Mapping

Cyber Elite
Cyber Elite

It seems like guest users arent matching any groups with Cloud Identity Engine. We have SAML (Azure) setup for our GlobalProtect authentication (not throught Cloud Identity Engine). We have CIE configured on the firewall under user identification. The Cloud Identity Engine is configured to sync the Azure directory but if I look on the firewall using show user user-ids match-user it shows no groups. We have on-prem users that sync up to Azure and those pull groups fine however the guest accounts do not, so accounta we invite into Azure and arent synced on prem dont match any groups.

 

If I go to CIE itself I can see the user there and the groups they are a part of but the firewall doesnt pull any of those groups, the certain groups are used for different agent configs for GlobalProtect. Is there a reason if wouldn't be pulling the groups that it should need? Do I need to use a SAML auth profile through CIE itself?

 

Running command "show user cloud-identity-engine statistics all" returns Failed with error code: -20001

 

Configure the Cloud Identity Engine as a Mapping Source on the Firewall (paloaltonetworks.com)

4 REPLIES 4

L6 Presenter

L0 Member

i'm having exactly the same issue. did you end up solving this?

Opened a TAC case on it and ours ended up being an error/bug with the user-id service on the firewall side. We restarted the service and it fixed the issue. 

 

Commands ran: 

>debug software restart process user-id-agent
>debug user-id refresh group-mapping all

 

The error we were getting was shown in the dscd.log file. Cli command for that: less mp-log dscd.log

dscd is the process for the cloud identity engine connection from the firewall, so this explains the workaround.

 

 

Edit: Also you could automate the process restart each night till you upgrade to a stable version following article:

 

https://live.paloaltonetworks.com/t5/general-articles/automating-the-palo-alto-ngfw-s-process-deamon...

  • 5296 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!