> ## Documentation Index
> Fetch the complete documentation index at: https://docs.portkey.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# CIE Directory Sync

> Sync users and groups from Palo Alto Networks Cloud Identity Engine (CIE) into SCM's AI Gateway for automated workspace provisioning.

# CIE Directory Sync

CIE (Cloud Identity Engine) Directory Sync allows you to pull users and groups from your organization's identity provider directories — such as **Entra ID (Azure AD)**, **Okta**, or **On-Premises Active Directory** — into SCM via Palo Alto's Cloud Identity Engine. Once synced, you can map CIE groups to SCM's AI Gateway workspaces so that users are **automatically provisioned** into the correct workspaces.

***

## Overview

CIE Directory Sync is available for organizations running in **SCM (Strata Cloud Manager)**. It replaces the need for manual user provisioning or standalone SCIM integration by leveraging CIE as the centralized identity source.

### How It Works

1. **CIE aggregates directories** — Your organization's identity providers (Entra ID, Okta, on-prem AD) are connected to CIE via the Strata Cloud Manager. CIE syncs and caches user/group data from these directories.
2. **Admin maps groups to workspaces** — An admin selects which CIE directory to connect, then maps CIE groups to AI Gateway workspaces.
3. **Users are auto-provisioned** — Background sync periodically pulls group membership changes from CIE and provisions/deprovisions users in the mapped workspaces automatically.

### Key Concepts

| Concept                          | Description                                                                                                                                                                                                                                                                                     |
| -------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Domain (Connected Directory)** | An identity provider directory synced into CIE. Each domain represents a separate directory source.                                                                                                                                                                                             |
| **Tenant ID**                    | The CIE tenant identifier for your organization, auto-provisioned during Onboarding. You never need to enter this manually.                                                                                                                                                                     |
| **Group**                        | A directory group from CIE (e.g., a security group). Groups contain users that can be mapped to workspaces.                                                                                                                                                                                     |
| **Group-Workspace Mapping**      | A 1:1 link between a CIE group and an AI Gateway workspace. All members of the mapped group are automatically provisioned into that workspace.                                                                                                                                                  |
| **User Identity Attribute**      | The CIE user attribute used as the email address — either **UPN (User Principal Name)** or **Mail (Primary Email)**.                                                                                                                                                                            |
| **Auth Profile**                 | The authentication profile used to validate user identity during MCP inbound authentication. These profiles are synced from [Authentication Profiles](https://docs.paloaltonetworks.com/identity/cloud-identity-engine/authenticate-users-with-the-cloud-identity-engine) configured under CIE. |

***

## Prerequisites

Before configuring CIE Directory Sync in SCM's AI Gateway, ensure the following:

1. **CIE is provisioned for your organization** — Your Strata Cloud Manager tenant must have CIE activated with a Directory Sync instance. This is set up during Onboarding.
2. **At least one directory is connected in CIE** — Navigate to CIE and verify that at least one directory (Entra ID, Okta, or On-Premises) has been added and has a successful sync status.
3. **You have SCM admin access** — Only organization admins can configure Directory Sync in SCM's AI Gateway.

<Info>
  CIE Directory Sync is only available for SCM Tenants. It is not available in standalone deployments. For non-SCM deployments, use [SCIM Provisioning](/docs/product/enterprise-offering/org-management/scim/scim) instead.
</Info>

***

## Setting Up Directories in CIE

Before SCM's AI Gateway can sync from CIE, you need to connect your identity provider directories in CIE. This is done in the **Strata Cloud Manager → Cloud Identity Engine** console.

For more information about CIE, see the [Cloud Identity Engine documentation](https://docs.paloaltonetworks.com/identity/cloud-identity-engine/cloud-identity-engine-overview).

<img src="https://mintcdn.com/portkey-docs/ZIC0N2xNeGq4fc9l/images/directory-sync/cie-directories-listing.png?fit=max&auto=format&n=ZIC0N2xNeGq4fc9l&q=85&s=58f16b21168244c60869f380b4960745" alt="CIE Directories listing — showing CIE Directory, Entra ID, and Okta directories with sync status, user/group counts, and last sync times" width="1024" height="582" data-path="images/directory-sync/cie-directories-listing.png" />

### Adding a New Directory

1. In the CIE console, navigate to **Directory Sync → Directories**.
2. Click **Add New Directory**.
3. You will see the directory type options:

<img src="https://mintcdn.com/portkey-docs/ZIC0N2xNeGq4fc9l/images/directory-sync/cie-set-up-directory.png?fit=max&auto=format&n=ZIC0N2xNeGq4fc9l&q=85&s=ca26160fa2aeebc2cd166d8f2ce16446" alt="CIE &#x22;Set Up Directory&#x22; page — CIE Directory, On-Premises Directory, and Cloud Directory options" width="1024" height="697" data-path="images/directory-sync/cie-set-up-directory.png" />

For SCM's AI Gateway integration, the relevant directory types are:

| Directory Type            | Provider                          | Description                                                       |
| ------------------------- | --------------------------------- | ----------------------------------------------------------------- |
| **Cloud Directory**       | Entra ID (Azure AD), Okta, Google | Connect a cloud identity provider. This is the most common setup. |
| **On-Premises Directory** | Active Directory                  | Install a Cloud Identity agent to sync from on-prem AD.           |
| **CIE Directory**         | CIE-native                        | Create a local directory managed entirely within CIE.             |

<Note>
  SCM's AI Gateway can connect to **any** directory type that CIE supports. The "Connected Directory" dropdown will show all directories that have been successfully synced in CIE.
</Note>

***

## Configuring Directory Sync in SCM's AI Gateway

Navigate to **AI Gateway → Admin Settings → Authentication → Directory Sync** in the SCM console.

<img src="https://mintcdn.com/portkey-docs/ZIC0N2xNeGq4fc9l/images/directory-sync/portkey-directory-sync-overview.jpg?fit=max&auto=format&n=ZIC0N2xNeGq4fc9l&q=85&s=1a1cfefd67df24175ae3c5a5147e92e3" alt="SCM AI Gateway Directory Sync configuration page — Connected Directory, User Identity Attribute, Auth Profile, Sync State, and Group Mappings" width="1024" height="583" data-path="images/directory-sync/portkey-directory-sync-overview.jpg" />

The **Configure in CIE** button redirects to your CIE Directory Sync console, where you can manage directories.

### Step 1: Select a Connected Directory

The **Connected Directory** dropdown shows all available directories from CIE, along with their provider type and entity counts (groups and users).

<img src="https://mintcdn.com/portkey-docs/ZIC0N2xNeGq4fc9l/images/directory-sync/connected-directory-dropdown.png?fit=max&auto=format&n=ZIC0N2xNeGq4fc9l&q=85&s=7d864df34546312d23eaf5c6ddac7ed0" alt="Connected Directory dropdown — available domains with provider type and user/group counts" width="1024" height="354" data-path="images/directory-sync/connected-directory-dropdown.png" />

Each entry displays:

* **Domain name** — the directory domain (e.g., `corp.example.com`)
* **Provider type** — `aad` (Entra ID), `okta`, `cie_directory` (CIE-native), `ad` (on-prem)
* **Group and user counts** — number of groups and users in that directory

Select the directory you want to sync from. You can also select **None (Disconnected)** to disconnect.

<Warning>
  Currently, only **one directory** can be connected at a time.
</Warning>

### Step 2: Choose the User Identity Attribute

The **User Identity Attribute** determines which CIE attribute is used as the user's email address.

<img src="https://mintcdn.com/portkey-docs/ZIC0N2xNeGq4fc9l/images/directory-sync/user-identity-attr-dropdown.png?fit=max&auto=format&n=ZIC0N2xNeGq4fc9l&q=85&s=3ab4ca5f6a441acba5b85aca1b5aeb98" alt="User Identity Attribute dropdown — UPN (User Principal Name) and Mail (Primary Email) options" width="1024" height="223" data-path="images/directory-sync/user-identity-attr-dropdown.png" />

| Attribute                     | Description                                                                     | When to Use                                                                                                   |
| ----------------------------- | ------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------- |
| **UPN (User Principal Name)** | The `userPrincipalName` attribute from the directory (e.g., `john@contoso.com`) | Default choice. Use when UPN matches the user's email.                                                        |
| **Mail (Primary Email)**      | The `mail` attribute from the directory                                         | Use when UPN differs from email (e.g., UPN is `john@contoso.onmicrosoft.com` but email is `john@contoso.com`) |

<Warning>
  If the selected attribute is **missing** for a user in CIE, that user will be **skipped** during sync. Verify that your chosen attribute is populated for all users in your directory.
</Warning>

<Info>
  Changing the User Identity Attribute after initial setup triggers an automatic **full re-sync** to update all user email addresses. This is safe — no users are removed during this re-sync.
</Info>

### Step 3: Save Configuration

Click **Save** to persist your Connected Directory and User Identity Attribute selections.

Once saved, the sync configuration becomes **active** and the background sync scheduler begins monitoring for changes.

### Step 4: Select an Auth Profile

The **Auth Profile** dropdown shows authentication profiles available for your tenant. These profiles are synced from [Authentication Profiles](https://docs.paloaltonetworks.com/identity/cloud-identity-engine/authenticate-users-with-the-cloud-identity-engine) configured under CIE. The selected profile is used to validate user identity during MCP inbound authentication flows.

***

## Directory Sync State

The **Directory Sync State** section shows the current health of the sync process.

<img src="https://mintcdn.com/portkey-docs/ZIC0N2xNeGq4fc9l/images/directory-sync/sync-state-success.jpg?fit=max&auto=format&n=ZIC0N2xNeGq4fc9l&q=85&s=70289441d32c0f3f9142a2deb089f4bf" alt="Directory Sync State — Status: Success, Last Updated: Sep 4, 2026, Objects Synced: 12 users · 1 groups" width="1024" height="1013" data-path="images/directory-sync/sync-state-success.jpg" />

| Field              | Description                                                 |
| ------------------ | ----------------------------------------------------------- |
| **Status**         | Current sync status — `Success`, `In Progress`, or `Failed` |
| **Last Updated**   | Timestamp of the last sync run (success or failed)          |
| **Objects Synced** | Count of users and groups currently mapped to workspaces    |

### Full Sync Button

Delta sync with CIE for group-membership updates happens every 15 minutes. So any update can take up to 15 minutes to reflect in AI Gateway. If CIE rebuilds its cache (approximately every week), AI Gateway does a full sync automatically.

But in case there is some issue or mismatch noted and you don't want to wait for the full sync period, you can click **Full Sync** which will do a forceful full sync of data from CIE.

<Info>
  If a sync is already in progress, the full sync will run once the current sync completes.
</Info>

***

## Group Mappings

The **Group Mappings** section is where you map CIE groups to workspaces. Users in a mapped group are automatically provisioned into the corresponding workspace.

<img src="https://mintcdn.com/portkey-docs/ZIC0N2xNeGq4fc9l/images/directory-sync/group-mappings.jpg?fit=max&auto=format&n=ZIC0N2xNeGq4fc9l&q=85&s=606e88dd4455b4ed5c0a8c2a786ac704" alt="Group Mappings — &#x22;Default Directory&#x22; mapped to &#x22;Engineering_Workspace&#x22;" width="1024" height="748" data-path="images/directory-sync/group-mappings.jpg" />

### Adding a Mapping

1. Click **Add Mapping**. The **Add Group Mapping** dialog opens:

<img src="https://mintcdn.com/portkey-docs/ZIC0N2xNeGq4fc9l/images/directory-sync/add-group-mapping-dialog.png?fit=max&auto=format&n=ZIC0N2xNeGq4fc9l&q=85&s=8e9f54f24e7f7ddc3a26c4aaa4068579" alt="Add Group Mapping dialog — select a CIE Group and a Workspace, then click Add" width="966" height="604" data-path="images/directory-sync/add-group-mapping-dialog.png" />

2. Select a **CIE Group** from the dropdown. The dropdown lists all groups from your connected directory.
3. Select a **Workspace** to map the group to.
4. Click **Add**.

### Mapping Rules

* **1:1 mapping** — Each group can only be mapped to one workspace, and each workspace can only have one group mapped to it
* **Workspace must exist** — The target workspace must already exist. Directory Sync does not create workspaces.

### Removing a Mapping

Click the **delete** (trash) icon next to a mapping to remove it. Users provisioned by this mapping will be **immediately removed** from that workspace.

<Warning>
  Deleting a mapping immediately removes users from the workspace. This action cannot be undone — you would need to re-create the mapping and wait for a sync to re-provision users.
</Warning>

***

## Viewing Directory-Provisioned Members

Once Directory Sync is configured and group mappings are in place, users from CIE are automatically provisioned into the mapped workspaces. You can view these members through the Workspace Control page.

### Viewing Workspaces

Navigate to **AI Gateway → Workspace Control** to see all workspaces in your organization.

<img src="https://mintcdn.com/portkey-docs/ZIC0N2xNeGq4fc9l/images/directory-sync/workspace-control-list.jpg?fit=max&auto=format&n=ZIC0N2xNeGq4fc9l&q=85&s=bdd7346ec0389c1ceec4b378eef5efc7" alt="Workspace Control — list of all workspaces in the organization" width="1024" height="578" data-path="images/directory-sync/workspace-control-list.jpg" />

This page shows all workspaces along with their slug, creation date, and last update time. Workspaces that have CIE groups mapped to them will have directory-provisioned members automatically added.

### Viewing Workspace Members

Click on a workspace to open its settings, then navigate to the **Members** tab to see all members provisioned into that workspace.

<img src="https://mintcdn.com/portkey-docs/ZIC0N2xNeGq4fc9l/images/directory-sync/workspace-members.jpg?fit=max&auto=format&n=ZIC0N2xNeGq4fc9l&q=85&s=d2fc3640fff70115f88ff9484ed395e0" alt="Workspace Members — showing directory-provisioned users in Engineering_Workspace" width="1024" height="581" data-path="images/directory-sync/workspace-members.jpg" />

Each member entry shows:

* **Name** — the user's display name, derived from CIE's `Common-Name` attribute
* **Email** — the user's email, based on the User Identity Attribute you selected (UPN or Mail)
* **Created At** — when the user was provisioned into the workspace
* **Last Update** — when the user's membership was last updated by a sync

<Info>
  Members listed here are automatically managed by Directory Sync. When a user is added to or removed from the mapped CIE group, the workspace membership is updated accordingly during the next sync cycle (within 15 minutes).
</Info>

***

## Creating User API Keys for Directory-Provisioned Members

Once users are provisioned into workspaces via Directory Sync, you can create **User API Keys** scoped to individual directory-provisioned members. This allows each user to have their own key for accessing AI Gateway services within their workspace.

### Navigating to Security Keys

1. Select a workspace from the **Workspace** dropdown at the top of the page.
2. Navigate to **AI Gateway → Security Keys**.

You will see the **Gateway API Keys** page with two tabs — **Service** and **User**.

<img src="https://mintcdn.com/portkey-docs/ZIC0N2xNeGq4fc9l/images/directory-sync/security-keys-service-tab.jpg?fit=max&auto=format&n=ZIC0N2xNeGq4fc9l&q=85&s=f1782ee6506125bb452010ea35fb6351" alt="Security Keys page — Service tab showing existing service API keys" width="1024" height="583" data-path="images/directory-sync/security-keys-service-tab.jpg" />

* **Service** keys are shared keys not tied to a specific user.
* **User** keys are tied to a specific directory-provisioned member.

Switch to the **User** tab to view existing user API keys.

<img src="https://mintcdn.com/portkey-docs/ZIC0N2xNeGq4fc9l/images/directory-sync/security-keys-user-tab.jpg?fit=max&auto=format&n=ZIC0N2xNeGq4fc9l&q=85&s=24d3fed741c3002a9cda62a85f5e50e1" alt="Security Keys — User tab showing user API keys with their owners" width="1024" height="327" data-path="images/directory-sync/security-keys-user-tab.jpg" />

### Creating a User API Key

1. Click **+ Create New**. The **Create New Gateway API Key** form opens.

2. Under **API Key Type**, select **User**.

<img src="https://mintcdn.com/portkey-docs/ZIC0N2xNeGq4fc9l/images/directory-sync/create-api-key-details.jpg?fit=max&auto=format&n=ZIC0N2xNeGq4fc9l&q=85&s=570a38902d39245502b14065a4f6e9f7" alt="Create API Key — Step 1: Configure API Key Details with User type selected" width="1024" height="700" data-path="images/directory-sync/create-api-key-details.jpg" />

3. Under **Select User**, choose a directory-provisioned member from the dropdown. Only users who have been synced into this workspace via Directory Sync will appear here.

<img src="https://mintcdn.com/portkey-docs/ZIC0N2xNeGq4fc9l/images/directory-sync/create-api-key-select-user.png?fit=max&auto=format&n=ZIC0N2xNeGq4fc9l&q=85&s=ebae8c9da8cc1285d74d2502dd955f61" alt="Select User dropdown — showing directory-provisioned users" width="1024" height="242" data-path="images/directory-sync/create-api-key-select-user.png" />

4. Enter an **API Key Name** — this is required and helps identify the key later.

5. Optionally fill in a **Short Description**, **Configuration**, and **Metadata**.

<img src="https://mintcdn.com/portkey-docs/ZIC0N2xNeGq4fc9l/images/directory-sync/create-api-key-filled.jpg?fit=max&auto=format&n=ZIC0N2xNeGq4fc9l&q=85&s=6811627cb5da9767b0371093ae4fd9f1" alt="Filled form — User1 AIGW selected with key name &#x22;test-doc&#x22;" width="1024" height="837" data-path="images/directory-sync/create-api-key-filled.jpg" />

6. Click **Next: Set Permissions**.

7. On the **Permissions** step, configure which permissions this key should have. Permissions are organized by resource (Agents, Completions, Logs, Mcp, Prompts) and action (Invoke, Write, Render).

<img src="https://mintcdn.com/portkey-docs/ZIC0N2xNeGq4fc9l/images/directory-sync/create-api-key-permissions.jpg?fit=max&auto=format&n=ZIC0N2xNeGq4fc9l&q=85&s=d67c1135a67189d35ca9070b1b5ac78d" alt="Set up Permissions — permission matrix for the API key" width="1024" height="863" data-path="images/directory-sync/create-api-key-permissions.jpg" />

8. Click **Create Gateway API Key**.

9. The generated API key is displayed. **Copy it now** — you will not be able to view it again.

<img src="https://mintcdn.com/portkey-docs/ZIC0N2xNeGq4fc9l/images/directory-sync/create-api-key-save.png?fit=max&auto=format&n=ZIC0N2xNeGq4fc9l&q=85&s=e0fa0364ca77320699691fe72df24407" alt="Save your Gateway API Key — copy the key before closing" width="1024" height="296" data-path="images/directory-sync/create-api-key-save.png" />

10. Click **Copy and Close**. The new key will appear in the **User** tab of Security Keys.

<img src="https://mintcdn.com/portkey-docs/ZIC0N2xNeGq4fc9l/images/directory-sync/security-keys-user-created.jpg?fit=max&auto=format&n=ZIC0N2xNeGq4fc9l&q=85&s=2d0c98b36cf095ddae24052a61378b14" alt="Security Keys User tab — newly created key attributed to User1 AIGW" width="1024" height="332" data-path="images/directory-sync/security-keys-user-created.jpg" />

<Warning>
  You cannot create a User API key without selecting a user and providing a key name. Both fields are required.
</Warning>

<Info>
  User API keys are scoped to the selected workspace. Each key is attributed to a specific directory-provisioned member and tracks who created it and who owns it.
</Info>

***

## Disabling Directory Sync

To disable Directory Sync entirely:

1. Navigate to **Admin Settings → Authentication → Directory Sync**
2. Select **None (Disconnected)** from the Connected Directory dropdown

**What happens when you disable sync:**

1. All CIE-synced users are **removed from their mapped workspaces**
2. All group-workspace mappings are removed
3. All group and sync status records are removed
4. The sync configuration is deactivated

<Warning>
  Disabling Directory Sync immediately removes all CIE-provisioned users from their workspaces. This is a destructive action. Users can be re-provisioned by re-enabling sync and re-creating group mappings.
</Warning>

To **re-enable** sync after disabling:

1. Select a Connected Directory again and save
2. Group mappings do **not** carry over — you must re-create them explicitly
3. A full sync will run to provision users into the newly mapped workspaces

***

## Troubleshooting

### Common Issues

| Issue                                                | Cause                                                            | Resolution                                                                                                                           |
| ---------------------------------------------------- | ---------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------ |
| **No domains shown** in Connected Directory dropdown | CIE not provisioned for this org, or no directories added in CIE | Ensure CIE is activated for your SCM tenant. Add directories in CIE.                                                                 |
| **Users not provisioned** after mapping              | Selected User Identity Attribute is missing for those users      | Check CIE to confirm users have the UPN or Mail attribute populated. Switch attribute if needed.                                     |
| **Users not removed** after deleting mapping         | User belongs to another group also mapped to the same workspace  | This is by design — users who have access through another mapping are not removed.                                                   |
| **Delta sync falling back to full**                  | CIE cache was rebuilt, or cursor expired                         | This is expected behavior. CIE periodically rebuilds its cache, which triggers a full resync. This acts as a self-healing mechanism. |

***

## Support

If you encounter issues with CIE Directory Sync, contact your support team.

***

<Card title="Portkey is now PRISMA AIRS AI Gateway. See it in action." href="https://www.paloaltonetworks.in/ai-security/ai-gateway?utm_source=portkey&utm_medium=referral&utm_campaign=prisma_airs&utm_content=docs_nav#contact" icon="arrow-up-right-from-square">
  Contact Us
</Card>
