Incorrect UPN (User Principal Name) fetched in CIE (Cloud Identity Engine) from Azure AD (AAD) even when the UPN on AAD is correct.

Incorrect UPN (User Principal Name) fetched in CIE (Cloud Identity Engine) from Azure AD (AAD) even when the UPN on AAD is correct.

5257
Created On 10/17/24 03:48 AM - Last Modified 12/03/24 19:51 PM


Symptom




Environment


  • Palo Alto Cloud Identify Engine for User and group mapping. (CIE)


Cause


  • This is an issue due to inconsistent response of UPN field from the Azure side. 
  • When the collect user risk information is checked, CIE queries the Azure AD via 2 different methods and in one of them (for user risk info), the incorrect value for UPN is returned hence CIE shows incorrect value for this attribute.

 



Resolution


  1. Validate that the UPN value is correct on the Azure AD side as needed.
  2. It has been observed that Mail Nick name (which is not expected to impact UPN ideally) also impacts the AAD response and to change the mail nick name to be same as UPN so the AAD might return the correct value.
  3. If not using Cloud dynamic user groups, Uncheck the Collect user risk information from Azure AD Identity Protection from AAD integration in the CIE followed by full sync in CIE to reflect the correct value.
  4. If the problem is still not fixed by unchecking the Collect user risk information from Azure AD Identity Protection, Reach out to Palo Alto Support with a screenshot of CIE info and the attribute details configured on the AAD side.

 



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000PQigCAG&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language