From 0e4346a04cfa0aa98739a55a20a545248d681a8a Mon Sep 17 00:00:00 2001 From: whysumedh Date: Wed, 16 Sep 2026 00:43:18 +0530 Subject: [PATCH] chore: add images and make the ciee dss doc consistent in prisma airs version --- .../directory-sync/cie-directory-sync.mdx | 50 ++++++++++++++++--- 1 file changed, 43 insertions(+), 7 deletions(-) diff --git a/aigw/product/enterprise-offering/org-management/directory-sync/cie-directory-sync.mdx b/aigw/product/enterprise-offering/org-management/directory-sync/cie-directory-sync.mdx index 962b40d4..d87ac534 100644 --- a/aigw/product/enterprise-offering/org-management/directory-sync/cie-directory-sync.mdx +++ b/aigw/product/enterprise-offering/org-management/directory-sync/cie-directory-sync.mdx @@ -5,17 +5,17 @@ description: "Sync users and groups from Palo Alto Networks Cloud Identity Engin # CIE Directory Sync -CIE (Cloud Identity Engine) Directory Sync allows you to pull users and groups from your organisation's identity provider directories — such as **Entra ID (Azure AD)**, **Okta**, or **On-Premises Active Directory** — into SCM via Palo Alto's Cloud Identity Engine. Once synced, you can map CIE groups to SCM's AI Gateway workspaces so that users are **automatically provisioned** into the correct workspaces. +CIE (Cloud Identity Engine) Directory Sync allows you to pull users and groups from your organization's identity provider directories — such as **Entra ID (Azure AD)**, **Okta**, or **On-Premises Active Directory** — into SCM via Palo Alto's Cloud Identity Engine. Once synced, you can map CIE groups to SCM's AI Gateway workspaces so that users are **automatically provisioned** into the correct workspaces. --- ## Overview -CIE Directory Sync is available for organisations running in **SCM (Strata Cloud Manager)**. It replaces the need for manual user provisioning or standalone SCIM integration by leveraging CIE as the centralized identity source. +CIE Directory Sync is available for organizations running in **SCM (Strata Cloud Manager)**. It replaces the need for manual user provisioning or standalone SCIM integration by leveraging CIE as the centralized identity source. ### How It Works -1. **CIE aggregates directories** — Your organisation's identity providers (Entra ID, Okta, on-prem AD) are connected to CIE via Strata Cloud Manager. CIE syncs and caches user/group data from these directories. +1. **CIE aggregates directories** — Your organization's identity providers (Entra ID, Okta, on-prem AD) are connected to CIE via the Strata Cloud Manager. CIE syncs and caches user/group data from these directories. 2. **Admin maps groups to workspaces** — An admin selects which CIE directory to connect, then maps CIE groups to AI Gateway workspaces. 3. **Users are auto-provisioned** — Background sync periodically pulls group membership changes from CIE and provisions/deprovisions users in the mapped workspaces automatically. @@ -24,7 +24,7 @@ CIE Directory Sync is available for organisations running in **SCM (Strata Cloud | Concept | Description | |---------|-------------| | **Domain (Connected Directory)** | An identity provider directory synced into CIE. Each domain represents a separate directory source. | -| **Tenant ID** | The CIE tenant identifier for your organisation, auto-provisioned during Onboarding. You never need to enter this manually. | +| **Tenant ID** | The CIE tenant identifier for your organization, auto-provisioned during Onboarding. You never need to enter this manually. | | **Group** | A directory group from CIE (e.g., a security group). Groups contain users that can be mapped to workspaces. | | **Group-Workspace Mapping** | A 1:1 link between a CIE group and an AI Gateway workspace. All members of the mapped group are automatically provisioned into that workspace. | | **User Identity Attribute** | The CIE user attribute used as the email address — either **UPN (User Principal Name)** or **Mail (Primary Email)**. | @@ -36,9 +36,9 @@ CIE Directory Sync is available for organisations running in **SCM (Strata Cloud Before configuring CIE Directory Sync in SCM's AI Gateway, ensure the following: -1. **CIE is provisioned for your organisation** — Your Strata Cloud Manager tenant must have CIE activated with a Directory Sync instance. This is set up during Onboarding. +1. **CIE is provisioned for your organization** — Your Strata Cloud Manager tenant must have CIE activated with a Directory Sync instance. This is set up during Onboarding. 2. **At least one directory is connected in CIE** — Navigate to CIE and verify that at least one directory (Entra ID, Okta, or On-Premises) has been added and has a successful sync status. -3. **You have SCM admin access** — Only organisation admins can configure Directory Sync in SCM's AI Gateway. +3. **You have SCM admin access** — Only organization admins can configure Directory Sync in SCM's AI Gateway. CIE Directory Sync is only available for SCM Tenants. It is not available in standalone deployments. For non-SCM deployments, use [SCIM Provisioning](/aigw/product/enterprise-offering/org-management/scim/scim) instead. @@ -52,12 +52,16 @@ Before SCM's AI Gateway can sync from CIE, you need to connect your identity pro For more information about CIE, see the [Cloud Identity Engine documentation](https://docs.paloaltonetworks.com/identity/cloud-identity-engine/cloud-identity-engine-overview). +![CIE Directories listing — showing CIE Directory, Entra ID, and Okta directories with sync status, user/group counts, and last sync times](/images/directory-sync/cie-directories-listing.png) + ### Adding a New Directory 1. In the CIE console, navigate to **Directory Sync → Directories**. 2. Click **Add New Directory**. 3. You will see the directory type options: +![CIE "Set Up Directory" page — CIE Directory, On-Premises Directory, and Cloud Directory options](/images/directory-sync/cie-set-up-directory.png) + For SCM's AI Gateway integration, the relevant directory types are: | Directory Type | Provider | Description | @@ -76,12 +80,16 @@ SCM's AI Gateway can connect to **any** directory type that CIE supports. The "C Navigate to **AI Gateway → Admin Settings → Authentication → Directory Sync** in the SCM console. +![SCM AI Gateway Directory Sync configuration page — Connected Directory, User Identity Attribute, Auth Profile, Sync State, and Group Mappings](/images/directory-sync/portkey-directory-sync-overview.jpg) + The **Configure in CIE** button redirects to your CIE Directory Sync console, where you can manage directories. ### Step 1: Select a Connected Directory The **Connected Directory** dropdown shows all available directories from CIE, along with their provider type and entity counts (groups and users). +![Connected Directory dropdown — available domains with provider type and user/group counts](/images/directory-sync/connected-directory-dropdown.png) + Each entry displays: - **Domain name** — the directory domain (e.g., `corp.example.com`) - **Provider type** — `aad` (Entra ID), `okta`, `cie_directory` (CIE-native), `ad` (on-prem) @@ -97,6 +105,8 @@ Currently, only **one directory** can be connected at a time. The **User Identity Attribute** determines which CIE attribute is used as the user's email address. +![User Identity Attribute dropdown — UPN (User Principal Name) and Mail (Primary Email) options](/images/directory-sync/user-identity-attr-dropdown.png) + | Attribute | Description | When to Use | |-----------|-------------|-------------| | **UPN (User Principal Name)** | The `userPrincipalName` attribute from the directory (e.g., `john@contoso.com`) | Default choice. Use when UPN matches the user's email. | @@ -126,6 +136,8 @@ The **Auth Profile** dropdown shows authentication profiles available for your t The **Directory Sync State** section shows the current health of the sync process. +![Directory Sync State — Status: Success, Last Updated: Sep 4, 2026, Objects Synced: 12 users · 1 groups](/images/directory-sync/sync-state-success.jpg) + | Field | Description | |-------|-------------| | **Status** | Current sync status — `Success`, `In Progress`, or `Failed` | @@ -148,10 +160,14 @@ If a sync is already in progress, the full sync will run once the current sync c The **Group Mappings** section is where you map CIE groups to workspaces. Users in a mapped group are automatically provisioned into the corresponding workspace. +![Group Mappings — "Default Directory" mapped to "Engineering_Workspace"](/images/directory-sync/group-mappings.jpg) + ### Adding a Mapping 1. Click **Add Mapping**. The **Add Group Mapping** dialog opens: +![Add Group Mapping dialog — select a CIE Group and a Workspace, then click Add](/images/directory-sync/add-group-mapping-dialog.png) + 2. Select a **CIE Group** from the dropdown. The dropdown lists all groups from your connected directory. 3. Select a **Workspace** to map the group to. 4. Click **Add**. @@ -177,7 +193,9 @@ Once Directory Sync is configured and group mappings are in place, users from CI ### Viewing Workspaces -Navigate to **AI Gateway → Workspace Control** to see all workspaces in your organisation. +Navigate to **AI Gateway → Workspace Control** to see all workspaces in your organization. + +![Workspace Control — list of all workspaces in the organization](/images/directory-sync/workspace-control-list.jpg) This page shows all workspaces along with their slug, creation date, and last update time. Workspaces that have CIE groups mapped to them will have directory-provisioned members automatically added. @@ -185,6 +203,8 @@ This page shows all workspaces along with their slug, creation date, and last up Click on a workspace to open its settings, then navigate to the **Members** tab to see all members provisioned into that workspace. +![Workspace Members — showing directory-provisioned users in Engineering_Workspace](/images/directory-sync/workspace-members.jpg) + Each member entry shows: - **Name** — the user's display name, derived from CIE's `Common-Name` attribute - **Email** — the user's email, based on the User Identity Attribute you selected (UPN or Mail) @@ -208,33 +228,49 @@ Once users are provisioned into workspaces via Directory Sync, you can create ** You will see the **Gateway API Keys** page with two tabs — **Service** and **User**. +![Security Keys page — Service tab showing existing service API keys](/images/directory-sync/security-keys-service-tab.jpg) + - **Service** keys are shared keys not tied to a specific user. - **User** keys are tied to a specific directory-provisioned member. Switch to the **User** tab to view existing user API keys. +![Security Keys — User tab showing user API keys with their owners](/images/directory-sync/security-keys-user-tab.jpg) + ### Creating a User API Key 1. Click **+ Create New**. The **Create New Gateway API Key** form opens. 2. Under **API Key Type**, select **User**. +![Create API Key — Step 1: Configure API Key Details with User type selected](/images/directory-sync/create-api-key-details.jpg) + 3. Under **Select User**, choose a directory-provisioned member from the dropdown. Only users who have been synced into this workspace via Directory Sync will appear here. +![Select User dropdown — showing directory-provisioned users](/images/directory-sync/create-api-key-select-user.png) + 4. Enter an **API Key Name** — this is required and helps identify the key later. 5. Optionally fill in a **Short Description**, **Configuration**, and **Metadata**. +![Filled form — User1 AIGW selected with key name "test-doc"](/images/directory-sync/create-api-key-filled.jpg) + 6. Click **Next: Set Permissions**. 7. On the **Permissions** step, configure which permissions this key should have. Permissions are organized by resource (Agents, Completions, Logs, Mcp, Prompts) and action (Invoke, Write, Render). +![Set up Permissions — permission matrix for the API key](/images/directory-sync/create-api-key-permissions.jpg) + 8. Click **Create Gateway API Key**. 9. The generated API key is displayed. **Copy it now** — you will not be able to view it again. +![Save your Gateway API Key — copy the key before closing](/images/directory-sync/create-api-key-save.png) + 10. Click **Copy and Close**. The new key will appear in the **User** tab of Security Keys. +![Security Keys User tab — newly created key attributed to User1 AIGW](/images/directory-sync/security-keys-user-created.jpg) + You cannot create a User API key without selecting a user and providing a key name. Both fields are required.