<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article GlobalProtect: User/Device Context and Compliance in GlobalProtect Articles</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-articles/globalprotect-user-device-context-and-compliance/ta-p/322235</link>
    <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="GlobalProtect: User/Device Context  and Compliance" style="width: 960px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25102i67F8777625282990/image-size/large?v=v2&amp;amp;px=999" role="button" title="GlobalProtect User Device Context  Compliance.png" alt="GlobalProtect: User/Device Context  and Compliance" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;GlobalProtect: User/Device Context  and Compliance&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN&gt;In my previous article, "&lt;/SPAN&gt;&lt;A title="GlobalProtect: Expanded Setup | LIVEcommunity | Palo Alto Networks" href="https://live.paloaltonetworks.com/t5/General-Articles/GlobalProtect-Expanded-Setup/ta-p/322234" target="_self"&gt;GlobalProtect: Expanded Setup&lt;/A&gt;&lt;SPAN&gt;," we covered the expanded setup of GlobalProtect, which included multiple authentication types, as well as the creation of an internal gateway. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN&gt;In this post, we are going to modify security policy matching based on user identity and device context provided via the GlobalProtect app. We will also enable notifications to the end user based on compliance of the endpoint. You can see a diagram of the environment&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Blogs/GlobalProtect-Overview/ba-p/322170" target="_self"&gt;here&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The value in leveraging user identity and device context in security policy along with end user notifications allow for greater visibility as well as more granular control over what users can access. This same methodology is applicable regardless of user location, and best practices dictate that they should be leveraged wherever possible. If a user is outside of what is required in order to access resources, they can be notified or mapped to a different rule to provide the minimum level of access required in order to become compliant.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;NOTE:&lt;/STRONG&gt;&amp;nbsp;&lt;SPAN&gt;This article assumes that you have already followed the previous articles in this series.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Part III - User/Device Context and Compliance&lt;/STRONG&gt;&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;Navigate to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Objects &amp;gt; GlobalProtect &amp;gt; HIP Objects &amp;gt; Add&lt;/STRONG&gt;&amp;nbsp;to create one or more test objects that are applicable to your environment&lt;/LI&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;Name the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;HIP Object&lt;/STRONG&gt;&amp;nbsp;and enable, checking for something specific to your environment. In my case, I run Cortex XDR Prevent on my workstations, and I will be also testing via an iPhone, so I will create two objects called&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;AV&lt;/I&gt;&amp;nbsp;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;iPhone&lt;/I&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HIP Object - General Tab - AV" style="width: 640px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25103i1B763A4014E755F1/image-size/large?v=v2&amp;amp;px=999" role="button" title="HIP Object - General Tab.png" alt="HIP Object - General Tab - AV" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;HIP Object - General Tab - AV&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HIP Object - Anti-Malware Tab" style="width: 640px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25104i197993EFD04BC6B1/image-size/large?v=v2&amp;amp;px=999" role="button" title="HIP Object - Anit-Malware Tab.png" alt="HIP Object - Anti-Malware Tab" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;HIP Object - Anti-Malware Tab&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HIP Object - General Tab - iPhone" style="width: 640px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25105iC632113C346AE636/image-size/large?v=v2&amp;amp;px=999" role="button" title="HIP Object - General Tab - iPhone.png" alt="HIP Object - General Tab - iPhone" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;HIP Object - General Tab - iPhone&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Navigate to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Objects &amp;gt; GlobalProtect &amp;gt; HIP Profiles &amp;gt; Add&lt;/STRONG&gt;&amp;nbsp;to create a profile that references both of the previously created objects&lt;/LI&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;&lt;STRONG&gt;NOTE:&lt;/STRONG&gt;&amp;nbsp;In the screenshot below, the profile will match based on either of the previously created objects&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HIP Profile - Compliant HIP Profile" style="width: 501px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25106iE61942A6BC6E2797/image-size/large?v=v2&amp;amp;px=999" role="button" title="HIP Profile - Compliant HIP Profile.png" alt="HIP Profile - Compliant HIP Profile" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;HIP Profile - Compliant HIP Profile&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Navigate to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Network &amp;gt; GlobalProtect &amp;gt; Gateways&amp;nbsp;&amp;gt;&lt;/STRONG&gt;&amp;nbsp;open each of the existing gateways&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&amp;gt; Agent &amp;gt; HIP Notification &amp;gt; Add&lt;/STRONG&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;Select the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Host Information&lt;/STRONG&gt;&amp;nbsp;profile that was previously created&lt;/LI&gt;
&lt;LI&gt;On the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Match Message&amp;nbsp;&lt;/STRONG&gt;tab
&lt;UL class="lia-list-style-type-square"&gt;
&lt;LI&gt;Check the&amp;nbsp;&lt;STRONG&gt;Enable&lt;/STRONG&gt;&amp;nbsp;box&lt;/LI&gt;
&lt;LI&gt;Enter a message&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;On the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Not Match Message&lt;/STRONG&gt;&amp;nbsp;tab
&lt;UL class="lia-list-style-type-square"&gt;
&lt;LI&gt;Check the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Enable&lt;/STRONG&gt;&amp;nbsp;box&lt;/LI&gt;
&lt;LI&gt;Enter a message&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HIP Notification - Compliant HIP Profile - Match Message" style="width: 640px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25107iE5184DE782DDF63D/image-size/large?v=v2&amp;amp;px=999" role="button" title="HIP Notification - Compliant HIP Profile - Match Message.png" alt="HIP Notification - Compliant HIP Profile - Match Message" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;HIP Notification - Compliant HIP Profile - Match Message&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HIP Notification - Compliant HIP Profile - Not Match Message" style="width: 640px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25108iF4AF13AD5F77EB35/image-size/large?v=v2&amp;amp;px=999" role="button" title="HIP Notification - Compliant HIP Profile - Not Match Message.png" alt="HIP Notification - Compliant HIP Profile - Not Match Message" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;HIP Notification - Compliant HIP Profile - Not Match Message&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Navigate to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Policies &amp;gt; Security&lt;/STRONG&gt;&amp;nbsp;to create rules based on user group and device context&lt;/LI&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;As shown below, we are adding a user group and HIP profile as match criteria&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Security Policies - Add User Group and HIP Profile" style="width: 640px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25109i07651CBB4BAB5E42/image-size/large?v=v2&amp;amp;px=999" role="button" title="Security Policies - Add User Group and HIP Profile.png" alt="Security Policies - Add User Group and HIP Profile" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Security Policies - Add User Group and HIP Profile&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Commit&lt;/STRONG&gt;&amp;nbsp;the configuration&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV&gt;You should now be able to log into GlobalProtect and see a message similar to the following:&lt;/DIV&gt;
&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GlobalProtect - Home Internal Gateway Compliant" style="width: 329px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25110i1CF490EEC09EB21D/image-size/large?v=v2&amp;amp;px=999" role="button" title="GlobalProtect - Home Internal Gateway Compliant.png" alt="GlobalProtect - Home Internal Gateway Compliant" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;GlobalProtect - Home Internal Gateway Compliant&lt;/span&gt;&lt;/span&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;P&gt;You should also be able to see rule matches via the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Traffic&amp;nbsp;logs&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my next article, "&lt;A title="GlobalProtect: Authentication Policy with MFA | LIVEcommunity | Palo Alto Networks" href="https://live.paloaltonetworks.com/t5/General-Articles/GlobalProtect-Authentication-Policy-with-MFA/ta-p/322236" target="_self"&gt;GlobalProtect: Authentication Policy with MFA&lt;/A&gt;," we will configure authentication policy with MFA for both HTTP and non-HTTP access to sensitive resources.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
    <pubDate>Mon, 11 Jul 2022 15:30:34 GMT</pubDate>
    <dc:creator>SpencerMitchell</dc:creator>
    <dc:date>2022-07-11T15:30:34Z</dc:date>
    <item>
      <title>GlobalProtect: User/Device Context and Compliance</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-articles/globalprotect-user-device-context-and-compliance/ta-p/322235</link>
      <description>&lt;P&gt;&lt;SPAN&gt;See how to modify security policy matching based on user identity and device context provided via the GlobalProtect app.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jul 2022 15:30:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-articles/globalprotect-user-device-context-and-compliance/ta-p/322235</guid>
      <dc:creator>SpencerMitchell</dc:creator>
      <dc:date>2022-07-11T15:30:34Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect: User/Device Context and Compliance</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-articles/globalprotect-user-device-context-and-compliance/tac-p/1232819#M154</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;Struggling to find any documentation related to user based policy configuration. Yours is the closest I could find.&lt;BR /&gt;&lt;BR /&gt;I managed to setup auth for user following documentation here :&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000008U48CAE" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000008U48CAE&lt;/A&gt;&lt;BR /&gt;but there is no mention of how we can add a user authenticated with SAML profile on security policies there.&lt;BR /&gt;&lt;BR /&gt;How do we manage to add an azure saml authenticated user to security policy?&lt;/P&gt;&lt;P&gt;Is it via Cloud Identity engine + User ID?&lt;BR /&gt;&lt;BR /&gt;Kindly help&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jun 2025 22:15:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-articles/globalprotect-user-device-context-and-compliance/tac-p/1232819#M154</guid>
      <dc:creator>Proton951</dc:creator>
      <dc:date>2025-06-29T22:15:44Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect: User/Device Context and Compliance</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-articles/globalprotect-user-device-context-and-compliance/tac-p/1232905#M155</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I like to think of User-ID as synonymous with all things identity. With this in mind, there are two different aspects of User-ID that we need to configure as it relates to traditional GlobalProtect or Prisma Access: authentication and authorization. Think of authentication as what grants the initial login. A user logs in (is authenticated). Think of authorization as what resources are accessible by a user once they are connected (what they are authorized to access).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;In the case of Azure, it can be used both for authentication and authorization. You would configure Azure as an iDP for authentication&amp;nbsp;(see &lt;A href="https://docs.paloaltonetworks.com/cloud-identity/cloud-identity-engine-getting-started/authenticate-users-with-the-cloud-identity-engine" target="_self"&gt;here&lt;/A&gt;), and use Azure AD for authorization&amp;nbsp;(see &lt;A href="https://docs.paloaltonetworks.com/cloud-identity/cloud-identity-engine-getting-started/choose-directory-type/configure-a-cloud-based-directory/set-up-azure" target="_self"&gt;here&lt;/A&gt;). If you just set up SAML auth, this is not enough to be able to leverage user/group information in security policy. You also have to setup Azure AD in CIE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jun 2025 16:00:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-articles/globalprotect-user-device-context-and-compliance/tac-p/1232905#M155</guid>
      <dc:creator>SpencerMitchell</dc:creator>
      <dc:date>2025-06-30T16:00:53Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect: User/Device Context and Compliance</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-articles/globalprotect-user-device-context-and-compliance/tac-p/1234335#M157</link>
      <description>&lt;P&gt;Thanks Mitchel,&lt;BR /&gt;&lt;BR /&gt;I have figured it out.&lt;BR /&gt;Was able to setup a CIE with Azure Entra then use it as the user accounts on Policies with users authenticated using SAML prepared as in the 1st link I sent.&lt;BR /&gt;I will probable come up with a combined doc of it and share its link here aswell so someone that stumbles into it later could save some time&lt;BR /&gt;&lt;BR /&gt;Regards&lt;/P&gt;</description>
      <pubDate>Sun, 20 Jul 2025 17:50:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-articles/globalprotect-user-device-context-and-compliance/tac-p/1234335#M157</guid>
      <dc:creator>Proton951</dc:creator>
      <dc:date>2025-07-20T17:50:23Z</dc:date>
    </item>
  </channel>
</rss>

