<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global Protect Azure AD MFA in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-azure-ad-mfa/m-p/506764#M2937</link>
    <description>&lt;P&gt;I've recently setup and succesfully tested a new portal and gateway with Azure AD MFA and the global protect app.&amp;nbsp; Currently i can log into my iphone app and I receive the portal auth, (LDAP) and then get prompted for the Microsoft sign in followed by the MFA (SAML), in my case I'm utilizing the MS authenticator app.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All is good with this setup and configuration.&amp;nbsp; The problem I'm seeing now is I cannot authenticate with the portal address via the Web using the url for the portal or from the global protect app on my windows laptop.&amp;nbsp; Testing took place with the Global Protect iOS app.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;GP logs are not showing me enough to break down what is occuring, AUTH failed, portal config is null, portal status is user authentication failed.&amp;nbsp; Monitor shows failed login, with "other" for auth method.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me know what you would like to see from my logs to troubleshoot.&amp;nbsp; I'm not seeing why this isnt working.&amp;nbsp; Perhaps some conditional access settings on the MS side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;LI-PRODUCT title="GlobalProtect" id="GlobalProtect"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Jun 2022 14:59:49 GMT</pubDate>
    <dc:creator>danoman2</dc:creator>
    <dc:date>2022-06-28T14:59:49Z</dc:date>
    <item>
      <title>Global Protect Azure AD MFA</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-azure-ad-mfa/m-p/506764#M2937</link>
      <description>&lt;P&gt;I've recently setup and succesfully tested a new portal and gateway with Azure AD MFA and the global protect app.&amp;nbsp; Currently i can log into my iphone app and I receive the portal auth, (LDAP) and then get prompted for the Microsoft sign in followed by the MFA (SAML), in my case I'm utilizing the MS authenticator app.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All is good with this setup and configuration.&amp;nbsp; The problem I'm seeing now is I cannot authenticate with the portal address via the Web using the url for the portal or from the global protect app on my windows laptop.&amp;nbsp; Testing took place with the Global Protect iOS app.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;GP logs are not showing me enough to break down what is occuring, AUTH failed, portal config is null, portal status is user authentication failed.&amp;nbsp; Monitor shows failed login, with "other" for auth method.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me know what you would like to see from my logs to troubleshoot.&amp;nbsp; I'm not seeing why this isnt working.&amp;nbsp; Perhaps some conditional access settings on the MS side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;LI-PRODUCT title="GlobalProtect" id="GlobalProtect"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2022 14:59:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-azure-ad-mfa/m-p/506764#M2937</guid>
      <dc:creator>danoman2</dc:creator>
      <dc:date>2022-06-28T14:59:49Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Azure AD MFA</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-azure-ad-mfa/m-p/508583#M2978</link>
      <description>&lt;P&gt;I made some progress on this.&amp;nbsp; First off, I made a mistake on the portal config.&amp;nbsp; I had it set to iOS only and have since switched to "any" OS.&amp;nbsp; Upon the commit I can now log into the portal via the web address.&amp;nbsp; Confirming my ability to authenticate with the portal via another method other than the iOS app.&amp;nbsp; I then moved on to the windows applicaiton.&amp;nbsp; It however is still giving me an error.&amp;nbsp; Currently getting error "failed to get client configuration".&amp;nbsp; Any thoughts?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 17:42:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-azure-ad-mfa/m-p/508583#M2978</guid>
      <dc:creator>danoman2</dc:creator>
      <dc:date>2022-07-12T17:42:29Z</dc:date>
    </item>
  </channel>
</rss>

