Is the Cloud Identity Engine required for filtering by Group when using Entra without LDAP?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Is the Cloud Identity Engine required for filtering by Group when using Entra without LDAP?

L1 Bithead

I feel like I've read every document on this forum but I can't seem to find a solid answer to this question. I'm sure someone will link 4 other posts.....  🤦‍♂️

 

I am using SAML Auth to Entra for GlobalProtect.  I can auth to the Portal if I specify the user directly (using domain.com\username - username@domain.com does not work).  I can also auth to the gateway using the same setup or (the way I'm doing it) using an authentication cookie.  I can also specify Security rules using the domain.com\username (if using the cookie) or username@domain.com (if not using the cookie) .  All of that is working as expected (after many many failed attempts 😂).

 

Next up, I want to use Entra groups to filter traffic on the Portal, Gateway and Security rules.  I've tried specifying the 'group' attribute in the SAML config (and the same on the Entra side) with no luck.  

 

Looking at debug logs on gpsvc.log, I can see a message with the following:

 

"GetUsernamesAndUsergroups: vsys (vsys1); user (username@domain.com); domain ()"}

"GetUsernamesAndUsergroups: response &{Email: UserAttrs:[domain.com\\username] Groups:[] GroupReady:true}"}

 

 

 

I'm assuming this means no groups are being passed down from Entra. Since I have to request Entra updates (no permissions myself), I'm hoping someone can definitely tell me, in 2025, with PanOS v11.1.x, do I need to set up CIE to make this work or is there a way to get group info using the standard Entra connector or if I'm just misconfiguring either the Auth Profile in Palo or the groups attribute (which I can't see) in Entra?

 

I've tried a couple of options here but this is what it currently looks like:

KSaucier_0-1748887583212.png

 

 

Thanks in advance for any wisdom you can impart!

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

need the CIE to get the group mapping, sorry... 😉

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

5 REPLIES 5

Cyber Elite
Cyber Elite

need the CIE to get the group mapping, sorry... 😉

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

L1 Bithead

Not what I was hoping to hear but what I was expecting to hear.  😁  Thanks!

L1 Bithead

Follow up question on this.  Can I use CIE for both auth as well as group mapping or do I still need individual SAML connections from each of my firewalls to Entra as well as using CIE to keep a cache of user/group mappings?  Obviously, I'd rather dump the individual SAML and just use CIE.  The documentation isn't super clear so, before I make the request from our Entra group, I'd like to know exactly what I need.  Thanks!

you can use it for both. just set up a directory first and then set up auth

 

in authentication you'll also need to set up a link to entraID once, but after that each firewall can simply talk to CIE for all their auth needs

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Sounds good.  Thanks again!

  • 1 accepted solution
  • 683 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!