- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-15-2026 09:44 AM
Hi everyone,
I’m troubleshooting a CIE group mapping issue on a firewall and would appreciate some advice.
The setup is:
PAN-OS 11.1.13-h9
Panorama-managed firewall
CIE using Okta as the directory source
Okta receives groups from both its own directory and MS Entra
GP uses these groups in Portal Agent Config and Gateway configuration
6 existing groups from the same CIE directory work correctly. However, newly created groups are not recognized by the firewall.
I tested 2 different cases:
A group created in Entra and synchronized to Okta.
A group created directly in Okta, to eliminate the Entra-Okta sync path.
In both cases:
The group is visible in the CIE directory.
The group has members.
The group is added to the GP Portal Agent Config.
The group is addded to the Gateway configuration.
The group is also referenced in a Security Policy (suggestion of our PA support)
The pushed configuration contains the correct group name and domain separator.
I manually forced a CIE refresh.
The direct lookup fails: show user group name "cie-domain\GP-Ring1"
Result: User group 'cie-domain\GP-Ring1' does not exist or does not have members
The CIE sync status itself reports success, and 6 other groups (created on Okta or Entra) from the same directory are available on the firewall.
At this point, I’m trying to understand whether:
CIE groups are only retrieved under specific conditions
the group must be associated with an authenticated user before it appears
there is a cache or refresh issue on the firewall ??
a particular CIE or PAN-OS command is required to request the group explicitly ??
An known issue with 11.1.13
Has anyone seen this behavior with CIE and Okta, especially when Okta itself receives groups from both Entra ID and its own directory?
Thanks !!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

