Unable to fetch instances for cloud authentication service under the authentication profile
7325
Created On 10/05/22 15:24 PM - Last Modified 10/12/23 21:30 PM
Symptom
- Setting up Cloud Identity Engine for Authentication
- When trying to select the instance, unable to select the same in the drop-down
- Checking the cloud-auth-service-profiles from the CLI fails to fetch instance with the message "No profile is provisioned for Tenant"
> show cloud-auth-service-profiles tenant_id 2085763612689333248 region_id in
No profile is provisioned for Tenant "2085763612689333248" in Region "in"
Note: "Tenant_ID" is displayed under Directories on the Cloud Identity Engine web page.
Environment
- Palo Alto Firewall
- PAN-OS 10.1 and above
- Cloud Identity Engine (CIE)
Resolution
- Go to the Cloud Identity Engine >Authentication Profile and click Add Authentication Profile
- Set up Authentication Profile
- Entre Profile name
- Choose the Authentication mode
- Select the Authentication type and click submit
- Go to the Directories and click on Full Sync and wait for 5 mins to complete the database sync
- Now run the below command to check the Authentication profile details created on CIE
> show cloud-auth-service-profiles tenant_id <XXXXXXXXXXXXXX> region_id <id>
mfa_enforceable (false) 0a082186-3231-44fa-a03a-e7c28c758b82 Authentication-CIE
client_cert_exists (false) 0a082186-3231-44fa-a03a-e7c28c758b82 Authentication-CIE
- Go to the Firewall Authentication profile, and you can see the instance name and authentication profile created on CIE