CIE Group Mappings Not Populating in Security Policies for Specific Device Groups
Symptom
-
Group names retrieved via Cloud Identity Engine (CIE) populate in
Mobile_User_Device_Grouppolicy dropdowns. -
Group names fail to populate (list appears empty or incomplete) for other device groups in Panorama policies (e.g.,
Remote_Network_Device_Groupor custom on-premises device groups).
Environment
-
Panorama
-
Cloud Identity Engine (CIE)
-
Prisma Access
Cause
This behavior occurs because Panorama retrieves and populates group names on a per-device-group basis. Even if CIE is globally configured, it must be explicitly associated with each individual device group to enable the metadata sync required for the Panorama UI to display those groups in policy dropdowns.
Prisma Access automatically associates the CIE profile with the default mobile user group during the initial onboarding, but for other device groups, this association must be performed manually.
Resolution
To resolve this, you must attach the Cloud Identity Engine profile to the affected device group and commit the changes.
1. Verify the CIE Profile Configuration
Ensure you have a functioning CIE profile defined in Panorama:
-
Navigate to Panorama > User Identification > Cloud Identity Engine.
-
Verify that your profile is Enabled and the status shows as connected.
2. Attach CIE to the Affected Device Group
-
Navigate to Panorama > Cloud Services > Configuration.
-
Select the tab corresponding to the affected deployment (e.g., Remote Networks or Mobile Users—Explicit Proxy).
-
Click the gear icon to open the Settings.
-
Go to the Group Mapping Settings (or Cloud Identity Engine) tab.
-
Check the box for Enable Directory Sync Integration.
-
Select your Cloud Identity Engine Profile from the dropdown menu.
-
Click OK.
3. Verify association in Device Groups
-
Navigate to Panorama > Device Groups.
-
Select the specific Device Group that was missing the group names.
-
Ensure the Cloud Identity Engine profile is listed as the source for user/group information.
4. Commit and Push Changes
-
Select Commit > Commit to Panorama.
-
Once the Panorama commit is successful, select Push to Devices and select the relevant Prisma Access or firewall push.
-
After the push, refresh the Panorama web interface and attempt to add a group to a policy rule within that device group. The dropdown should now be populated.