Prisma Access CIE and User-ID mapping not working for groups

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Prisma Access CIE and User-ID mapping not working for groups

L0 Member

Hi, all,

 

thanks in advance for any help about an issue we are facing with User-ID agent on on-prem and EntraID with CIE integration.Let me explain our topology a bit deeper:

On the one hand, we have a Remote Network with some Windows servers without GP or Prisma Access agent. We use User-ID agent for username-to-IP mapping. This is sent to local NGFW, and from there to Prisma Access. It runs fine, coz on UserID logs in Prisma I can see the users there.

On the other hand, AD is federated with EntraID and CIE collects certain test users and groups. I can see that a particular test user is on EntraID and also in CIE inside a certain group. On Prisma Access CIE configuration I can see that a number of groups and users are there.

So, if we create a rule on Prisma Access (with Strata Cloud Manager), we can select both the groups and the users as source. If we choose user (brought by CIE), the username-to-IP mapping works, and the rule matches. But if we use the group in the rule, the username-to-IP mapping seems to be avoided and the rule doesn't match.

Did anyone faced this before? I think it should work. Group rules are not only for agent based workstations, right?

Many thanks!

1 REPLY 1

Cyber Elite

the first thing you should check in this case is the user attribute mapping:

in the prisma access (or global) configuration scope, go to Identity Services > Cloud Identity Engine

verify what the primary username is set to and compare that to the usernames you are seeing from the user-id agent

 

if the userid agent sends you domain\user, set the CIE primary to SAM Account Name, if the format is user@domain, set the primary to User Principal Name

 

this can happen if you instruct CIE to fetch one type of username format while receiving a different format from the uidagent i.e. your groups come loaded with username references that don't match the actual usernames

 

 

reaper_0-1768212465770.png

 

Tom Piens
PANgurus - Strata & Prisma Access specialist
  • 1204 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!