Add or Delete an Identity Federation Owner Through Common Services
Table of Contents
Expand all | Collapse all
- Get Started with Common Services: Identity & Access
-
- Add an Identity Federation
- Manually Configure a SAML Identity Provider
- Upload SAML Identity Provider Metadata
- Get the URL of a SAML Identity Provider
- Clone SAML Identity Provider Configuration
- Add or Delete an Identity Federation Owner
- Configure Palo Alto Networks as a Service Provider
- Delete an Identity Federation
- Map a Tenant for Authorization
- Update Tenant Mapping for Authorization
- PAN Resource Name Mapping Properties
- Manage Single Tenant Transition to Multitenant
- Release Updates
Add or Delete an Identity Federation Owner Through Common Services
Learn how to add or delete an identity federation owner through the Common Services.
After you add an identity federation, you
can add additional owners to manage the domain and the identity federation. After
you add owners, you can also delete identity federation owners who don't
need to manage the domain anymore.
Add an Identity Federation Owner
- Use one of the various ways to access Common ServicesIdentity & Access.Select Identity & Access/Access ManagementIdentity Federations.Scroll to your identity federation of choice and Add Owner.Enter email addresses of the new owners and Add Owners.The additional owners who are added by the original owner are of the “Owner Grant” type and they are automatically verified. They do not have to be verified by TXT record like the original owner.
Delete an Identity Federation Owner
- Use one of the various ways to access Common ServicesIdentity & Access.Select Identity & Access/Access ManagementIdentity Federations.Scroll to your Owner Grant identity federation owner of choice and Delete the owner.Confirm that you want to delete the owner.To delete a DNS Verification owner, you must first go to your domain provider’s console and delete the owner. Otherwise the txt record is still being verified from when you originally added an identity federation, so the delete request will be canceled.