Cortex Cloud: Why does Cortex Cloud creates a new identity domain when running the onboarding script in OCI

Cortex Cloud: Why does Cortex Cloud creates a new identity domain when running the onboarding script in OCI

291
Created On 01/09/26 20:17 PM - Last Modified 06/12/26 17:21 PM


Symptom


Cortex Cloud Onboarding scripts create a new identity domain in OCI



Environment


**Product_versions**
Cortex Cloud 2.1

Cortex Cloud license on Cortex XSIAM and Cortex XDR



Cause


An OCI limitation restricts one trust policy per IdP per domain. The Cortex XSIAM WIF implementation relies on "accounts.google.com". When multiple Cortex tenants are linked to a single OCI tenancy or another tool already uses Google as an IdP in the same domain, attempting to add a second trust policy results in a 409 Conflict, necessitating the creation of a new identity domain.



Resolution


**REMEDIATION_PLAN**
Creating a separate identity domain during OCI integration to ensure clean and conflict-free onboarding for Cortex XSIAM.

**PREVENTIVE_MEASURES**
Creating a separate identity domain during OCI integration to prevent 409 Conflict errors caused by OCI's trust policy limitation.



Additional Information


This change will help us in the future when we implement Compartment-level onboarding from the same OCI tenancy.



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA1Ki000000wkGaKAI&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail