Set Up Password Authentication
Table of Contents
Expand all | Collapse all
-
- Cloud Identity Engine Attributes
- Collect Custom Attributes with the Cloud Identity Engine
- View Directory Data
- Cloud Identity Engine User Context
- Create a Cloud Dynamic User Group
- Configure Third-Party Device-ID
- Configure an IP Tag Cloud Connection
- View Mappings and Tags
- Configure Dynamic Privilege Access in the Cloud Identity Engine
- Send Cortex XDR Risk Signals to Okta
- Configure SSF Okta Receiver as a Risk Connection
- Configure the Secrets Vault
-
- Set Up Password Authentication
-
- Configure Azure as an IdP in the Cloud Identity Engine
- Configure Okta as an IdP in the Cloud Identity Engine
- Configure PingOne as an IdP in the Cloud Identity Engine
- Configure PingFederate as an IdP in the Cloud Identity Engine
- Configure Google as an IdP in the Cloud Identity Engine
- Configure a SAML 2.0-Compliant IdP in the Cloud Identity Engine
- Set Up a Client Certificate
- Configure an OIDC Authentication Type
- Set Up an Authentication Profile
- Configure Cloud Identity Engine Authentication on the Firewall or Panorama
- Configure the Cloud Identity Engine as a Mapping Source on the Firewall or Panorama
- Configure Dynamic Privilege Access in the Cloud Identity Engine
- Get Help
Set Up Password Authentication
Find out how to configure password authentication as an authentication type for the
Cloud Identity Engine.
If you configure a CIE directory in the Cloud Identity Engine,
you also need to configure an authentication type for those users to enforce
security policy rules. Having to use a third-party identity provider (IdP) to manage
your CIE directory users can be tedious and time-consuming.
Configuring password authentication as an authentication type enables CIE directory
users to authenticate without requiring the use of an external IdP. After you
configure password authentication for your CIE directory, you can select password
authentication as an authentication type in an authentication profile. This enables CIE directory users to
authenticate using passwords, instead of having to configure an additional identity
provider.
Enabling password authentication for your CIE directory users simplifies the
authentication process for them by reducing the friction of having to use a separate
IdP to log in. It also simplifies the process for administrators, since they can add
or remove users from the CIE directory without having to configure or revoke
additional privileges.
Before you begin:
- Configure a CIE Directory.
- Add the password authentication users.
- Set up password authentication as an authentication type in the Cloud Identity Engine.
- Select AuthenticationAuthentication Types.Click Add New Authentication Type.Set Up the Password Authentication type.
Create the password authentication configuration.- Enter an Authentication Type Name.
Select a CIE Directory.
Submit the configuration.Next Steps: - You can now configure password authentication when you Set Up an Authentication Profile.
- Associate the Cloud Identity Engine with Palo Alto Networks Apps to combine the capabilities of the Cloud Identity Engine with the other Palo Alto Networks apps you use.