nerdexam
Palo_Alto_Networks

SSE-ENGINEER · Question #20

All mobile users are unable to authenticate to Prisma Access (Managed by Strata Cloud Manager) using SAML authentication through the Cloud Identity Engine. Users report that after entering their…

The correct answer is C. Verify the SAML metadata configuration in both the Cloud Identity Engine and the IdP portal to. The "400 Bad Request" error when attempting SAML authentication through the Cloud Identity Engine (CIE) suggests a misconfiguration in the SAML metadata. This typically occurs when the endpoint URLs, certificates, or entity IDs do not match between Cloud Identity Engine and the…

Troubleshooting and Diagnostics

Question

All mobile users are unable to authenticate to Prisma Access (Managed by Strata Cloud Manager) using SAML authentication through the Cloud Identity Engine. Users report that after entering their credentials on the Identity Provider (IdP) login page, they are redirected to the Prisma Access portal without successful authentication, and they receive this error message:

Error: Prisma Access Portal Authentication Failed using CIE-SAML with message "400 Bad Request" Which action will identify the root cause of this error?

Options

  • AVerify the SAML metadata configuration in both Strata Cloud Manager and the IdP portal to
  • BExamine the Security policy rules in Prisma Access to ensure that traffic from the IdP is allowed
  • CVerify the SAML metadata configuration in both the Cloud Identity Engine and the IdP portal to
  • DReview the Authentication logs in Strata Cloud Manager to check for any SAML error messages or

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    7% (2)
  • C
    79% (22)
  • D
    11% (3)

Explanation

The "400 Bad Request" error when attempting SAML authentication through the Cloud Identity Engine (CIE) suggests a misconfiguration in the SAML metadata. This typically occurs when the endpoint URLs, certificates, or entity IDs do not match between Cloud Identity Engine and the IdP portal. To resolve this, verify that: The SAML metadata uploaded to Cloud Identity Engine matches the configuration from the IdP. The ACS (Assertion Consumer Service) URL, Entity ID, and certificate are correctly set. There are no incorrect or expired certificates in the Cloud Identity Engine and IdP configuration. By ensuring the SAML metadata is properly configured in both systems, authentication should proceed without errors.

Topics

#SAML#Cloud Identity Engine#metadata configuration#authentication failure

Community Discussion

No community discussion yet for this question.

Full SSE-ENGINEER Practice