<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect App for Android on Managed Chromebooks Using the Google A in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-app-for-android-on-managed-chromebooks-using-the/m-p/341457#M310</link>
    <description>&lt;P&gt;commenting to review.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jul 2020 16:17:52 GMT</pubDate>
    <dc:creator>Sec101</dc:creator>
    <dc:date>2020-07-30T16:17:52Z</dc:date>
    <item>
      <title>GlobalProtect App for Android on Managed Chromebooks Using the Google Admin</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-app-for-android-on-managed-chromebooks-using-the/m-p/339385#M288</link>
      <description>&lt;P&gt;Hi we want to deploy Global-protect app for Android on managed Chromebooks using Google admin console.&lt;/P&gt;&lt;P&gt;Requirement: every device needs to be uniquely identified and then allowed. Kind of a device whitelisting for example Host id for windows.&lt;/P&gt;&lt;P&gt;Problem 1: when the GP app running in Android container on a Chromebook managed by google admin console, my firewall sees a new serial I'd everytime it connects to firewall in Hip match logs even the host id is different.&amp;nbsp; How can we make sure we use the unique mobile I'd to enforce the whitelist approach in Hip objects?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problem 2: will this setup require a third-party MDM integration to enforce hip or can palo alto detect this without third party MDM integration. (Palo Alto only supports airwatch MDM integration)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problem 3: as per the 3rd party MDM compatibility matrix we only support Global-protect app deployment for andorid on a managed Chromebook using Google admin console. Will we be able to identify Chromebook based on mobile I'd?&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/compatibility-matrix/globalprotect/what-features-do-third-party-mobile-device-management-systems-support" target="_blank"&gt;https://docs.paloaltonetworks.com/compatibility-matrix/globalprotect/what-features-do-third-party-mobile-device-management-systems-support&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problem 4: this below URL says we can enforce mobile I'd on a android running on managed Chromebook in step 5. How wever we are not able to and this contradicted above Matrix.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/mobile-endpoint-management/set-up-a-mobile-endpoint-management-system/manage-the-globalprotect-app-using-a-third-party-mdm/deploy-the-globalprotect-mobile-app/deploy-the-globalprotect-app-for-android-on-managed-chromebooks-using-the-google-admin-console.html" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/mobile-endpoint-management/set-up-a-mobile-endpoint-management-system/manage-the-globalprotect-app-using-a-third-party-mdm/deploy-the-globalprotect-mobile-app/deploy-the-globalprotect-app-for-android-on-managed-chromebooks-using-the-google-admin-console.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jul 2020 07:20:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-app-for-android-on-managed-chromebooks-using-the/m-p/339385#M288</guid>
      <dc:creator>lrangra</dc:creator>
      <dc:date>2020-07-18T07:20:58Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect App for Android on Managed Chromebooks Using the Google A</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-app-for-android-on-managed-chromebooks-using-the/m-p/341305#M304</link>
      <description>&lt;P&gt;Problem 1: Is there a setting (on Google Admin Console) where apps on the chromebook are getting uninstalled when chromebook shuts down? Can you confirm?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2020 00:42:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-app-for-android-on-managed-chromebooks-using-the/m-p/341305#M304</guid>
      <dc:creator>vathreya</dc:creator>
      <dc:date>2020-07-30T00:42:58Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect App for Android on Managed Chromebooks Using the Google A</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-app-for-android-on-managed-chromebooks-using-the/m-p/341375#M308</link>
      <description>&lt;P&gt;yes the app gets uninstalled on reboot. since the app is running in Kiosk mode. it runs in a sandbox environment on managed chormebook.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2020 08:02:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-app-for-android-on-managed-chromebooks-using-the/m-p/341375#M308</guid>
      <dc:creator>lrangra</dc:creator>
      <dc:date>2020-07-30T08:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect App for Android on Managed Chromebooks Using the Google A</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-app-for-android-on-managed-chromebooks-using-the/m-p/341457#M310</link>
      <description>&lt;P&gt;commenting to review.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2020 16:17:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-app-for-android-on-managed-chromebooks-using-the/m-p/341457#M310</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2020-07-30T16:17:52Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect App for Android on Managed Chromebooks Using the Google A</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-app-for-android-on-managed-chromebooks-using-the/m-p/351722#M441</link>
      <description>&lt;P&gt;We opened a case with TAC and the findings were:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problem 1: when the GP app running in Android container on a Chromebook managed by google admin console, my firewall sees a new serial I'd everytime it connects to firewall in Hip match logs even the host id is different.&amp;nbsp; How can we make sure we use the unique mobile I'd to enforce the whitelist approach in Hip objects?&lt;/P&gt;&lt;P&gt;Answer: Since the mode of deployment is kiosk mode for chromebook after reboot, a new container version will be created everytime. thus new serial number and host id. only the options given under Hip Object&amp;gt; General can be used. changing the mode to App mode at Google admin console will help. mobile id can only be used when we integrate with MDM.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problem 2: will this setup require a third-party MDM integration to enforce hip or can palo alto detect this without third party MDM integration. (Palo Alto only supports airwatch MDM integration)&lt;/P&gt;&lt;P&gt;if we want mdm then we have to use airwatch.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problem 3: as per the 3rd party MDM compatibility matrix we only support Global-protect app deployment for andorid on a managed Chromebook using Google admin console. Will we be able to identify Chromebook based on mobile I'd?&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/compatibility-matrix/globalprotect/what-features-do-third-party-mobile-device-management-systems-support" target="_blank" rel="nofollow noopener noreferrer"&gt;https://docs.paloaltonetworks.com/compatibility-matrix/globalprotect/what-features-do-third-party-mo...&lt;/A&gt;&lt;/P&gt;&lt;P&gt;No we will not be able to. as the documents says only thing which is support is&amp;nbsp;Global-protect app deployment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problem 4: this below URL says we can enforce mobile I'd on a android running on managed Chromebook in step 5. However we are not able to and this contradicted above Matrix.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/mobile-endpoint-management/set-up-a-mobile-endpoint-management-system/manage-the-globalprotect-app-using-a-third-party-mdm/deploy-the-globalprotect-mobile-app/deploy-the-globalprotect-app-for-android-on-managed-chromebooks-using-the-google-admin-console.html" target="_blank" rel="nofollow noopener noreferrer"&gt;https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/mobile-endpoint-management/s...&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Mobile id is only applicable when we have a MDM. currently only airwatch is supported.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2020 11:10:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-app-for-android-on-managed-chromebooks-using-the/m-p/351722#M441</guid>
      <dc:creator>lrangra</dc:creator>
      <dc:date>2020-09-24T11:10:31Z</dc:date>
    </item>
  </channel>
</rss>

