Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -5,17 +5,17 @@ description: "Sync users and groups from Palo Alto Networks Cloud Identity Engin

# CIE Directory Sync

CIE (Cloud Identity Engine) Directory Sync allows you to pull users and groups from your organisation's identity provider directories — such as **Entra ID (Azure AD)**, **Okta**, or **On-Premises Active Directory** — into SCM via Palo Alto's Cloud Identity Engine. Once synced, you can map CIE groups to SCM's AI Gateway workspaces so that users are **automatically provisioned** into the correct workspaces.
CIE (Cloud Identity Engine) Directory Sync allows you to pull users and groups from your organization's identity provider directories — such as **Entra ID (Azure AD)**, **Okta**, or **On-Premises Active Directory** — into SCM via Palo Alto's Cloud Identity Engine. Once synced, you can map CIE groups to SCM's AI Gateway workspaces so that users are **automatically provisioned** into the correct workspaces.

---

## Overview

CIE Directory Sync is available for organisations running in **SCM (Strata Cloud Manager)**. It replaces the need for manual user provisioning or standalone SCIM integration by leveraging CIE as the centralized identity source.
CIE Directory Sync is available for organizations running in **SCM (Strata Cloud Manager)**. It replaces the need for manual user provisioning or standalone SCIM integration by leveraging CIE as the centralized identity source.

### How It Works

1. **CIE aggregates directories** — Your organisation's identity providers (Entra ID, Okta, on-prem AD) are connected to CIE via Strata Cloud Manager. CIE syncs and caches user/group data from these directories.
1. **CIE aggregates directories** — Your organization's identity providers (Entra ID, Okta, on-prem AD) are connected to CIE via the Strata Cloud Manager. CIE syncs and caches user/group data from these directories.
2. **Admin maps groups to workspaces** — An admin selects which CIE directory to connect, then maps CIE groups to AI Gateway workspaces.
3. **Users are auto-provisioned** — Background sync periodically pulls group membership changes from CIE and provisions/deprovisions users in the mapped workspaces automatically.

Expand All @@ -24,7 +24,7 @@ CIE Directory Sync is available for organisations running in **SCM (Strata Cloud
| Concept | Description |
|---------|-------------|
| **Domain (Connected Directory)** | An identity provider directory synced into CIE. Each domain represents a separate directory source. |
| **Tenant ID** | The CIE tenant identifier for your organisation, auto-provisioned during Onboarding. You never need to enter this manually. |
| **Tenant ID** | The CIE tenant identifier for your organization, auto-provisioned during Onboarding. You never need to enter this manually. |
| **Group** | A directory group from CIE (e.g., a security group). Groups contain users that can be mapped to workspaces. |
| **Group-Workspace Mapping** | A 1:1 link between a CIE group and an AI Gateway workspace. All members of the mapped group are automatically provisioned into that workspace. |
| **User Identity Attribute** | The CIE user attribute used as the email address — either **UPN (User Principal Name)** or **Mail (Primary Email)**. |
Expand All @@ -36,9 +36,9 @@ CIE Directory Sync is available for organisations running in **SCM (Strata Cloud

Before configuring CIE Directory Sync in SCM's AI Gateway, ensure the following:

1. **CIE is provisioned for your organisation** — Your Strata Cloud Manager tenant must have CIE activated with a Directory Sync instance. This is set up during Onboarding.
1. **CIE is provisioned for your organization** — Your Strata Cloud Manager tenant must have CIE activated with a Directory Sync instance. This is set up during Onboarding.
2. **At least one directory is connected in CIE** — Navigate to CIE and verify that at least one directory (Entra ID, Okta, or On-Premises) has been added and has a successful sync status.
3. **You have SCM admin access** — Only organisation admins can configure Directory Sync in SCM's AI Gateway.
3. **You have SCM admin access** — Only organization admins can configure Directory Sync in SCM's AI Gateway.

<Info>
CIE Directory Sync is only available for SCM Tenants. It is not available in standalone deployments. For non-SCM deployments, use [SCIM Provisioning](/aigw/product/enterprise-offering/org-management/scim/scim) instead.
Expand All @@ -52,12 +52,16 @@ Before SCM's AI Gateway can sync from CIE, you need to connect your identity pro

For more information about CIE, see the [Cloud Identity Engine documentation](https://docs.paloaltonetworks.com/identity/cloud-identity-engine/cloud-identity-engine-overview).

![CIE Directories listing — showing CIE Directory, Entra ID, and Okta directories with sync status, user/group counts, and last sync times](/images/directory-sync/cie-directories-listing.png)

### Adding a New Directory

1. In the CIE console, navigate to **Directory Sync → Directories**.
2. Click **Add New Directory**.
3. You will see the directory type options:

![CIE "Set Up Directory" page — CIE Directory, On-Premises Directory, and Cloud Directory options](/images/directory-sync/cie-set-up-directory.png)

For SCM's AI Gateway integration, the relevant directory types are:

| Directory Type | Provider | Description |
Expand All @@ -76,12 +80,16 @@ SCM's AI Gateway can connect to **any** directory type that CIE supports. The "C

Navigate to **AI Gateway → Admin Settings → Authentication → Directory Sync** in the SCM console.

![SCM AI Gateway Directory Sync configuration page — Connected Directory, User Identity Attribute, Auth Profile, Sync State, and Group Mappings](/images/directory-sync/portkey-directory-sync-overview.jpg)

The **Configure in CIE** button redirects to your CIE Directory Sync console, where you can manage directories.

### Step 1: Select a Connected Directory

The **Connected Directory** dropdown shows all available directories from CIE, along with their provider type and entity counts (groups and users).

![Connected Directory dropdown — available domains with provider type and user/group counts](/images/directory-sync/connected-directory-dropdown.png)

Each entry displays:
- **Domain name** — the directory domain (e.g., `corp.example.com`)
- **Provider type** — `aad` (Entra ID), `okta`, `cie_directory` (CIE-native), `ad` (on-prem)
Expand All @@ -97,6 +105,8 @@ Currently, only **one directory** can be connected at a time.

The **User Identity Attribute** determines which CIE attribute is used as the user's email address.

![User Identity Attribute dropdown — UPN (User Principal Name) and Mail (Primary Email) options](/images/directory-sync/user-identity-attr-dropdown.png)

| Attribute | Description | When to Use |
|-----------|-------------|-------------|
| **UPN (User Principal Name)** | The `userPrincipalName` attribute from the directory (e.g., `john@contoso.com`) | Default choice. Use when UPN matches the user's email. |
Expand Down Expand Up @@ -126,6 +136,8 @@ The **Auth Profile** dropdown shows authentication profiles available for your t

The **Directory Sync State** section shows the current health of the sync process.

![Directory Sync State — Status: Success, Last Updated: Sep 4, 2026, Objects Synced: 12 users · 1 groups](/images/directory-sync/sync-state-success.jpg)

| Field | Description |
|-------|-------------|
| **Status** | Current sync status — `Success`, `In Progress`, or `Failed` |
Expand All @@ -148,10 +160,14 @@ If a sync is already in progress, the full sync will run once the current sync c

The **Group Mappings** section is where you map CIE groups to workspaces. Users in a mapped group are automatically provisioned into the corresponding workspace.

![Group Mappings — "Default Directory" mapped to "Engineering_Workspace"](/images/directory-sync/group-mappings.jpg)

### Adding a Mapping

1. Click **Add Mapping**. The **Add Group Mapping** dialog opens:

![Add Group Mapping dialog — select a CIE Group and a Workspace, then click Add](/images/directory-sync/add-group-mapping-dialog.png)

2. Select a **CIE Group** from the dropdown. The dropdown lists all groups from your connected directory.
3. Select a **Workspace** to map the group to.
4. Click **Add**.
Expand All @@ -177,14 +193,18 @@ Once Directory Sync is configured and group mappings are in place, users from CI

### Viewing Workspaces

Navigate to **AI Gateway → Workspace Control** to see all workspaces in your organisation.
Navigate to **AI Gateway → Workspace Control** to see all workspaces in your organization.

![Workspace Control — list of all workspaces in the organization](/images/directory-sync/workspace-control-list.jpg)

This page shows all workspaces along with their slug, creation date, and last update time. Workspaces that have CIE groups mapped to them will have directory-provisioned members automatically added.

### Viewing Workspace Members

Click on a workspace to open its settings, then navigate to the **Members** tab to see all members provisioned into that workspace.

![Workspace Members — showing directory-provisioned users in Engineering_Workspace](/images/directory-sync/workspace-members.jpg)

Each member entry shows:
- **Name** — the user's display name, derived from CIE's `Common-Name` attribute
- **Email** — the user's email, based on the User Identity Attribute you selected (UPN or Mail)
Expand All @@ -208,33 +228,49 @@ Once users are provisioned into workspaces via Directory Sync, you can create **

You will see the **Gateway API Keys** page with two tabs — **Service** and **User**.

![Security Keys page — Service tab showing existing service API keys](/images/directory-sync/security-keys-service-tab.jpg)

- **Service** keys are shared keys not tied to a specific user.
- **User** keys are tied to a specific directory-provisioned member.

Switch to the **User** tab to view existing user API keys.

![Security Keys — User tab showing user API keys with their owners](/images/directory-sync/security-keys-user-tab.jpg)

### Creating a User API Key

1. Click **+ Create New**. The **Create New Gateway API Key** form opens.

2. Under **API Key Type**, select **User**.

![Create API Key — Step 1: Configure API Key Details with User type selected](/images/directory-sync/create-api-key-details.jpg)

3. Under **Select User**, choose a directory-provisioned member from the dropdown. Only users who have been synced into this workspace via Directory Sync will appear here.

![Select User dropdown — showing directory-provisioned users](/images/directory-sync/create-api-key-select-user.png)

4. Enter an **API Key Name** — this is required and helps identify the key later.

5. Optionally fill in a **Short Description**, **Configuration**, and **Metadata**.

![Filled form — User1 AIGW selected with key name "test-doc"](/images/directory-sync/create-api-key-filled.jpg)

6. Click **Next: Set Permissions**.

7. On the **Permissions** step, configure which permissions this key should have. Permissions are organized by resource (Agents, Completions, Logs, Mcp, Prompts) and action (Invoke, Write, Render).

![Set up Permissions — permission matrix for the API key](/images/directory-sync/create-api-key-permissions.jpg)

8. Click **Create Gateway API Key**.

9. The generated API key is displayed. **Copy it now** — you will not be able to view it again.

![Save your Gateway API Key — copy the key before closing](/images/directory-sync/create-api-key-save.png)

10. Click **Copy and Close**. The new key will appear in the **User** tab of Security Keys.

![Security Keys User tab — newly created key attributed to User1 AIGW](/images/directory-sync/security-keys-user-created.jpg)

<Warning>
You cannot create a User API key without selecting a user and providing a key name. Both fields are required.
</Warning>
Expand Down
Loading