Activate the Cloud Identity Engine
Focus
Focus
Identity

Activate the Cloud Identity Engine

Table of Contents

Activate the Cloud Identity Engine

Activate the Cloud Identity Engine in the hub to create your first tenant.
Where Can I Use This?What Do I Need?
  • The Activation Console
  • Commercial deployments
  • Customer Support Portal account
Activating the Cloud Identity Engine is the foundational step in establishing a centralized, cloud-native source of truth for user identities across your security infrastructure. This process is performed within the Palo Alto Networks Hub and initializes the tenant that will aggregate and normalize user, group, and device data from your disparate directory sources. Unlike traditional hardware deployments, activation focuses on provisioning the cloud service, enabling you to prepare your environment for identity synchronization without the need for immediate physical appliance installation.
The activation workflow is designed to accommodate various organizational structures, ranging from Single Customer Support Portal (CSP) Accounts to complex environments managing Multiple CSP Accounts or child tenants. While the service is often included as a free integration requiring no standalone authorization code, the activation process allows you to claim licenses and link the engine to your existing support accounts. Once activation is complete, the system automatically creates your primary tenant, allowing you to immediately begin associating firewalls and configuring your on-premises or cloud-based directories.
To activate the Cloud Identity Engine, refer to the documentation for the type of account you have and how you want to configure the Cloud Identity Engine:

First time Cloud Identity Engine Activation - One Customer Support Portal Account

Learn how to activate your Cloud Identity Engine(CIE) application for the first time if you have only one Customer Support Portal account.
Where Can I Use This?What Do I Need?
  • The Activation Console
  • Commercial deployments
  • Customer Support Portal account
If you have only one Customer Support Portal account, follow these steps for first time Cloud Identity Engine (CIE) activation.
  1. From the Activation Console, select Activate.
  2. Because you have only one Customer Support Portal account associated with your username, the Customer Support Account is prepopulated.
  3. Allocate the product to the Recipient of your choice.
    1. The name provided matches your Customer Support Portal account for convenience. You can use the name provided or change it.
  4. Select a Region where you want to deploy your product.
  5. Agree to the terms and conditions, and Activate.
    A single default tenant is autocreated behind the scenes, and the product is activated in the tenant.
    This tenant, and any others created by this Customer Support Portal account, will have the Superuser role.
  6. (Optional) Manage your product from Strata Cloud Manager.

First time Cloud Identity Engine Activation - Multiple Customer Support Portal Account

Learn how to activate your Cloud Identity Engine(CIE) application for the first time if you have multiple Customer Support Portal accounts.
Where Can I Use This?What Do I Need?
  • The Activation Console
  • Commercial deployments
  • Customer Support Portal account
If you have multiple Customer Support Portal accounts, follow these steps for first time Cloud Identity Engine (CIE) activation.
  1. From the Activation Console, select Activate.
  2. If you have multiple Customer Support Portal accounts, choose the Customer Support Account number that you want to use.
  3. Allocate the product to the Recipient of your choice.
    You can allocate your entire license to one recipient or you can share it with multiple recipients in a tenant hierarchy. What is a tenant?
    1. If you need just one tenant, use or rename the tenant provided. The name provided matches your Customer Support Portal account for convenience.
    2. (Optional) This step applies if you are a managed security service provider (MSSP), a distributed enterprise customer, or need multiple tenants. After you create the first tenant, you can Allocate to subtenant and use or rename the tenant provided.
      A subscription gets allocated on a tenant or a sub-tenant. This step is for choosing a tenant where you want to allocate a license, not for building a complete tenant hierarchy. You can create only a tenant and subtenant here, and you can choose to allocate a license to that subtenant.
      After activation, you can build out your tenant hierarchy as needed through tenant management. You can create your tenant hierarchy to reflect your existing organizational structure. You can also consider identity and access inheritance when creating the hierarchy, in addition to tenant hierarchy.
      After you create a tenant hierarchy, you can share a license.
    3. Select Done.
  4. Select a Region where you want to deploy your product.
  5. Agree to the terms and conditions, and Activate.
    This tenant, and any others created by this Customer Support Portal account, will have the Superuser role.
  6. (Optional) Manage your product from Strata Cloud Manager.

Return Visit Cloud Identity Engine Activation

Learn how to activate your Cloud Identity Engine for repeat visits.
Where Can I Use This?What Do I Need?
  • The Activation Console
  • Commercial deployments
  • Customer Support Portal account
Follow these steps if you have already completed first time activation, you have already created your tenant hierarchy through Identity & AccessTenants or tenant management, and you are returning to activate another product in your existing hierarchy.
  1. From the Activation Console, select Activate.
  2. Choose the Customer Support Account number that you want to use to activate.
  3. Allocate the subscription to the Recipient tenant of your choice.
    You can hover over each tenant to see which apps you already activated.
  4. Select a Region where you want to deploy your product.
  5. Agree to the terms and conditions, and Activate.
  6. (Optional) Manage your product from Strata Cloud Manager.

Share Cloud Identity Engine

Learn how to share Cloud Identity Engine (CIE) on tenants through Common Services.
Where Can I Use This?What Do I Need?
  • The Activation Console
  • Commercial deployments
  • Customer Support Portal account
After you activate Cloud Identity Engine on a tenant and add child tenants, you can share (CIE) with the child tenants in your hierarchy.
Regardless if you activate a new CIE instance on an existing tenant with existing Prisma Access or you activate a new CIE instance on a new tenant, you can share CIE under the following circumstances:
  • Share CIE from a parent tenant during a new Prisma Access activation
  • Share CIE from a parent tenant during the Prisma Access edit operation
  • Share CIE to a child tenant that is not already running CIE
  • Share CIE to a child tenant that is in the same region as the parent
If you don't have access to a parent tenant, the sharing option is not displayed. The parent can control which child can have access to see CIE sharing through Identity & Access Management Roles.
  1. Use one of the various ways to access Tenant Management.
  2. Search or scroll to find the parent tenant where CIE is activated, and select Actions > Manage Sharing.
  3. Select which tenants to share CIE:
    • All — share CIE with all the child tenants.
    • Share — individually select the check box for each child tenant to share CIE.
  4. Save.