Activate the Cloud Identity Engine
Table of Contents
Expand all | Collapse all
-
- Cloud Identity Engine Attributes
- Collect Custom Attributes with the Cloud Identity Engine
- View Directory Data
- Cloud Identity Engine User Context
- Create a Cloud Dynamic User Group
- Configure Third-Party Device-ID
- Configure an IP Tag Cloud Connection
- Configure Dynamic Privilege Access in the Cloud Identity Engine
- Configure Security Risk for the Cloud Identity Engine
-
-
- Configure Azure as an IdP in the Cloud Identity Engine
- Configure Okta as an IdP in the Cloud Identity Engine
- Configure PingOne as an IdP in the Cloud Identity Engine
- Configure PingFederate as an IdP in the Cloud Identity Engine
- Configure Google as an IdP in the Cloud Identity Engine
- Configure a SAML 2.0-Compliant IdP in the Cloud Identity Engine
- Configure a Client Certificate
- Configure an OIDC Authentication Type
- Set Up an Authentication Profile
- Configure Cloud Identity Engine Authentication on the Firewall or Panorama
- Configure the Cloud Identity Engine as a Mapping Source on the Firewall or Panorama
- Configure Dynamic Privilege Access in the Cloud Identity Engine
-
- Get Help
Activate the Cloud Identity Engine
Activate the Cloud Identity Engine in the hub to create your first tenant.
If you use Common Services: Tenant and Subscription
management, refer to the Common Services: Tenant and Subscription
management documentation to activate the Cloud Identity Engine or
share it with other tenants.
- Log in to the hub.If you don’t see the Cloud Identity Engine, verify that you are using the tenant view then clickExplore Apps from Palo Alto Networks.
- Activatethe Cloud Identity Engine.If theActivatebutton is not available, ensure your role has the necessary privileges. For more information about Cloud Identity Engine roles, refer to Manage Cloud Identity Engine App Roles.The Cloud Identity Engine supports alphanumeric characters, underscores (_), hyphens (-), and periods (.) for the tenant name.
- Select the information for your Cloud Identity Engine tenant.
- Select theCustomer Support Accountfor the tenant.
- Select theRegionwhere the tenant is located.If you want to configure an on-premises Active Directory for the Cloud Identity Engine, the region you select must match the region info you enter for theCloud Identity Enginein the Cloud Identity Configuration when you Configure the Cloud Identity Agent.
- After youAgree to the Terms and Conditions, clickActivate Nowto activate your Cloud Identity Engine tenant.
- Openthe Cloud Identity Engine app to begin configuring your Cloud Identity Engine app.Depending on whether you want to use the Cloud Identity Engine for user identification, user authentication, or both, complete the following initial configuration tasks to begin using the Cloud Identity Engine for user visibility and policy enforcement. For more information, refer to Set Up the Cloud Identity Engine.
- Choose Your Directory Type—Set up a directory to allow the Cloud Identity Engine to collect information for user visibility and policy enforcement.
- Authenticate Users with the Cloud Identity Engine—Configure an authentication method to support user authentication with the Cloud Identity Engine.