Configure Cloud Identity Engine Authentication (SCM)
Focus
Focus
Identity

Configure Cloud Identity Engine Authentication (SCM)

Table of Contents


Configure Cloud Identity Engine Authentication (SCM)

Learn about configuring authentication for Cloud Identity Engine in Strata Cloud Manager.
To configure Cloud Identity authentication within Strata Cloud Manager, you must leverage the Cloud Authentication Service (CAS) to broker requests between your enforcement points and your identity providers (IdPs). This workflow allows you to enforce SAML 2.0, OIDC, or Client Certificate authentication across your managed NGFWs and Prisma Access deployments.
  1. Configure an authentication profile to use the Cloud Identity Engine Authentication Service.
    1. In Strata Cloud Manager, navigate to ConfigurationNGFW and Prisma AccessIdentity ServicesAuthenticationAuthentication Profiles.
    2. Add Profile.
    3. Set the Authentication Method to Cloud Identity Engine.
    4. Give the profile a Name.
    5. Select a Cloud Identity Engine Profile or Create a new one.
    6. Specify the Maximum Clock Skew (range is 1–900 seconds; default is 60) to allow for time synchronization differences between the IdP and the cloud service.
    7. (Optional)Select Force multi-factor authentication in the cloud if your IdP is configured to require users to log in using multi-factor authentication (MFA).
    8. (Optional) Match all users or select specific users and groups synchronized from your directory.
    9. Save.
  2. (Required for authentication policy rule only) Create an Authentication Enforcement object that uses the authentication profile to redirect users to log in using their authentication type.
    1. In Strata Cloud Manager, navigate to ConfigurationNGFW and Prisma AccessIdentity ServicesAuthenticationAuthentication Rules.
    2. Add Authentication Rule.
    3. Give the rule a Name.
    4. (Optional)Give the rule a detailed Description.
    5. (Optional) Add Tags to help organize the rule.
    6. Set the Action to Authenticate.
    7. (Optional) Set the Auth Session Timeout (range is 1–1440 minutes; default is 60).
    8. (Optional) Write a Message to your users telling them how to authenticate.
    9. Select the Cloud Identity Engine Authentication Profile you created previously.
    10. Save.
  3. Push config.