This page describes the initial setup steps for performing
Identity Provisioning to PaloAltoNetworks using TrustLogin as the identity source.
Note: For detailed operating instructions for PaloAltoNetworks, please refer to the documentation provided by PaloAltoNetworks.
Item |
Details |
|
Pre-check |
|
|
Setup Flow / Manual |
Note: After connecting TrustLogin and PaloAltoNetworks using the steps on this page, |
|
Provisioning Target |
〇 |
Supports user provisioning |
〇 |
Supports group provisioning | |
SAML Authentication Setup Manual |
- | |
Notes |
|
|
Setup Steps
PaloAltoNetworks Settings
- Log in to the CIE portal (Palo Alto Networks Cloud Identity Engine), and from the menu on the left, navigate to "Directory Sync" > "Directories".
- Click the "Add New Directory" button.
- Click the "Set Up" button in the "Cloud Directory" section,
and select "SCIM" from the dropdown menu.
- Select "Others" from the "SCIM Client" dropdown.
- Enter any values of your choice in the "Directory ID" and "Directory Name" fields.
- Click the "Generate Token" button in the "Authorization Method" section
to generate a "Bearer Token".
- Click the icon to the right of the generated token,
and copy the "Bearer Token" to the clipboard. (This will be used in the TrustLogin settings.)
- Click the "Submit" button at the bottom right of the screen.
- When the "Action Required" pop-up appears, check "I have acknowledged this."
- Click "OK" to save the settings.
This completes the preparation on the PaloAltoNetworks side. Next, configure the settings on the TrustLogin side.
TrustLogin Settings
Log in to the TrustLogin Admin Page, and from the "Admin Page > Settings > Optional Features" menu,
open "Settings" next to "Identity Provisioning."
- Click "Add Service."
- Select "PaloAltoNetworks" and click the "Add" button.
- You will be redirected to the "Identity Provisioning > PaloAltoNetworks" page.
Click the "Edit" button.
-
Open "Access Settings," enter the following value for the setting item, and click "Save."
SCIM Token The "Bearer Token" you copied in PaloAltoNetworks Settings ① > Step 7 - After saving the settings, click the "Connect" button to perform the initial synchronization.
- If the button status changes to "Connected," the initial synchronization was successful.
Note: It may take some time for the status to be reflected on the PaloAltoNetworks side.
Next step: For the user synchronization settings manual, see here
Available Values for Attribute Mapping
The following values that can be specified as default functions for PaloAltoNetworks are as follows.
| Value | Description |
| Full Name | This is the full name with the last name first. |
| Full Name with First Name First | This is the full name with the first name first. |
| Username from Email | Takes the portion of the email address before the "@" and limits it to a maximum of 21 characters. |
Note: For an overview of the attribute mapping feature and how to configure it, see here.