If you are collecting data for the same domain from
both an on-premises Active Directory (AD) and an Azure AD, Palo Alto
Networks recommends that you create a separate Cloud Identity Engine tenant
for each directory type. If you must use the same Cloud Identity Engine
tenant and want to collect data from both an on-premises AD and an Azure AD,
you must customize the directory name for the Azure AD (for example, by
adding
.aad to
Customize Directory
Name) then reconnect or edit your Azure directory. Any
applications that you
associate with the Cloud Identity
Engine use the custom directory name.