Initial Setup Steps for Identity Provisioning with PaloAltoNetworks

This page describes the initial setup steps for performing
Identity Provisioning to PaloAltoNetworks using TrustLogin as the identity source.

Note: For detailed operating instructions for PaloAltoNetworks, please refer to the documentation provided by PaloAltoNetworks.

Item

Details

Pre-check

  • Administrator privileges in PaloAltoNetworks are required.

Setup Flow / Manual

Note: After connecting TrustLogin and PaloAltoNetworks using the steps on this page,
 proceed to the user synchronization settings.

Provisioning Target

Supports user provisioning

Supports group provisioning

SAML Authentication Setup Manual

-

Notes

  • None in particular

 

Setup Steps

PaloAltoNetworks Settings

  1. Log in to the CIE portal (Palo Alto Networks Cloud Identity Engine), and from the menu on the left, navigate to "Directory Sync" > "Directories".
    paloalto_IDProv_01.png
     
  2. Click the "Add New Directory" button.
    paloalto_IDProv_02.png
     
  3. Click the "Set Up" button in the "Cloud Directory" section,
    and select "SCIM" from the dropdown menu.
    paloalto_IDProv_03.png
     
  4. Select "Others" from the "SCIM Client" dropdown.
    paloalto_IDProv_04.png
     
  5. Enter any values of your choice in the "Directory ID" and "Directory Name" fields.
    paloalto_IDProv_05.png
     
  6. Click the "Generate Token" button in the "Authorization Method" section
    to generate a "Bearer Token". paloalto_IDProv_06.png
     
  7. Click the icon to the right of the generated token,
    and copy the "Bearer Token" to the clipboard. (This will be used in the TrustLogin settings.)
    paloalto_IDProv_07.png
     
  8. Click the "Submit" button at the bottom right of the screen.
    paloalto_IDProv_08.png
     
  9. When the "Action Required" pop-up appears, check "I have acknowledged this."
    paloalto_IDProv_09.png
     
  10. Click "OK" to save the settings.
     paloalto_IDProv_10.png

    This completes the preparation on the PaloAltoNetworks side. Next, configure the settings on the TrustLogin side.
     

TrustLogin Settings

  1. Log in to the TrustLogin Admin Page, and from the "Admin Page > Settings > Optional Features" menu,
    open "Settings" next to "Identity Provisioning."
    IDProvServiceCommon01.png
     

  2. Click "Add Service."
    IDProvServiceCommon02.png
     
  3. Select "PaloAltoNetworks" and click the "Add" button.
    paloalto_IDProv_11.png
     
  4. You will be redirected to the "Identity Provisioning > PaloAltoNetworks" page.
    Click the "Edit" button.
    paloalto_IDProv_12.png
     
  5. Open "Access Settings," enter the following value for the setting item, and click "Save."
    paloalto_IDProv_13.png

    SCIM Token The "Bearer Token" you copied in PaloAltoNetworks Settings ① > Step 7

     

  6. After saving the settings, click the "Connect" button to perform the initial synchronization.
    paloalto_IDProv_14.png 
  7. If the button status changes to "Connected," the initial synchronization was successful.
    Note: It may take some time for the status to be reflected on the PaloAltoNetworks side.
    paloalto_IDProv_15.png
     

Next step: For the user synchronization settings manual, see here

 

Available Values for Attribute Mapping

The following values that can be specified as default functions for PaloAltoNetworks are as follows.

Value Description
Full Name This is the full name with the last name first.
Full Name with First Name First This is the full name with the first name first.
Username from Email Takes the portion of the email address before the "@" and limits it to a maximum of 21 characters.

Note: For an overview of the attribute mapping feature and how to configure it, see here.

 


 

 

 

 

 

 

 

 

 

 

Initial Setup Steps for Identity Provisioning with PaloAltoNetworks

This page describes the initial setup steps for performing
Identity Provisioning to PaloAltoNetworks using TrustLogin as the identity source.

Note: For detailed operating instructions for PaloAltoNetworks, please refer to the documentation provided by PaloAltoNetworks.

Item

Details

Pre-check

  • Administrator privileges in PaloAltoNetworks are required.

Setup Flow / Manual

Note: After connecting TrustLogin and PaloAltoNetworks using the steps on this page,
 proceed to the user synchronization settings.

Provisioning Target

Supports user provisioning

Supports group provisioning

SAML Authentication Setup Manual

-

Notes

  • None in particular

 

Setup Steps

PaloAltoNetworks Settings

  1. Log in to the CIE portal (Palo Alto Networks Cloud Identity Engine), and from the menu on the left, navigate to "Directory Sync" > "Directories".
    paloalto_IDProv_01.png
     
  2. Click the "Add New Directory" button.
    paloalto_IDProv_02.png
     
  3. Click the "Set Up" button in the "Cloud Directory" section,
    and select "SCIM" from the dropdown menu.
    paloalto_IDProv_03.png
     
  4. Select "Others" from the "SCIM Client" dropdown.
    paloalto_IDProv_04.png
     
  5. Enter any values of your choice in the "Directory ID" and "Directory Name" fields.
    paloalto_IDProv_05.png
     
  6. Click the "Generate Token" button in the "Authorization Method" section
    to generate a "Bearer Token". paloalto_IDProv_06.png
     
  7. Click the icon to the right of the generated token,
    and copy the "Bearer Token" to the clipboard. (This will be used in the TrustLogin settings.)
    paloalto_IDProv_07.png
     
  8. Click the "Submit" button at the bottom right of the screen.
    paloalto_IDProv_08.png
     
  9. When the "Action Required" pop-up appears, check "I have acknowledged this."
    paloalto_IDProv_09.png
     
  10. Click "OK" to save the settings.
     paloalto_IDProv_10.png

    This completes the preparation on the PaloAltoNetworks side. Next, configure the settings on the TrustLogin side.
     

TrustLogin Settings

  1. Log in to the TrustLogin Admin Page, and from the "Admin Page > Settings > Optional Features" menu,
    open "Settings" next to "Identity Provisioning."
    IDProvServiceCommon01.png
     

  2. Click "Add Service."
    IDProvServiceCommon02.png
     
  3. Select "PaloAltoNetworks" and click the "Add" button.
    paloalto_IDProv_11.png
     
  4. You will be redirected to the "Identity Provisioning > PaloAltoNetworks" page.
    Click the "Edit" button.
    paloalto_IDProv_12.png
     
  5. Open "Access Settings," enter the following value for the setting item, and click "Save."
    paloalto_IDProv_13.png

    SCIM Token The "Bearer Token" you copied in PaloAltoNetworks Settings ① > Step 7

     

  6. After saving the settings, click the "Connect" button to perform the initial synchronization.
    paloalto_IDProv_14.png 
  7. If the button status changes to "Connected," the initial synchronization was successful.
    Note: It may take some time for the status to be reflected on the PaloAltoNetworks side.
    paloalto_IDProv_15.png
     

Next step: For the user synchronization settings manual, see here

 

Available Values for Attribute Mapping

The following values that can be specified as default functions for PaloAltoNetworks are as follows.

Value Description
Full Name This is the full name with the last name first.
Full Name with First Name First This is the full name with the first name first.
Username from Email Takes the portion of the email address before the "@" and limits it to a maximum of 21 characters.

Note: For an overview of the attribute mapping feature and how to configure it, see here.