Unable to fetch instances for cloud authentication service under the authentication profile

Unable to fetch instances for cloud authentication service under the authentication profile

7315
Created On 10/05/22 15:24 PM - Last Modified 10/12/23 21:30 PM


Symptom


CIE-1.png

  • Checking the cloud-auth-service-profiles from the CLI fails to fetch instance with the message "No profile is provisioned for Tenant" 
> show cloud-auth-service-profiles tenant_id 2085763612689333248 region_id in
No profile is provisioned for Tenant "2085763612689333248" in Region "in"

Note: "Tenant_ID" is displayed under Directories on the Cloud Identity Engine web page.
CIE-2-tenant-id-ee.png



Environment




Resolution


  1. Go to the Cloud Identity Engine >Authentication Profile and click Add Authentication Profile

CIE-3-add-auth.png

  1. Set up Authentication Profile
  • Entre Profile name
  • Choose the Authentication mode
  • Select the Authentication type and click submit

CIE-4-creat-AP.png

  1. Go to the Directories and click on Full Sync and wait for 5 mins to complete the database sync

CIE-full-sync.png

 

  1. Now run the below command to check the Authentication profile details created on CIE
> show cloud-auth-service-profiles tenant_id <XXXXXXXXXXXXXX> region_id <id>

mfa_enforceable (false)  0a082186-3231-44fa-a03a-e7c28c758b82  Authentication-CIE
client_cert_exists (false)  0a082186-3231-44fa-a03a-e7c28c758b82  Authentication-CIE
  1. Go to the Firewall Authentication profile, and you can see the instance name and authentication profile created on CIE

CIE-Auth-choose-created-in-CIE.png



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000sZPOCA2&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail