<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Migrate GlobalProtect users from LDAP portal to SAML portal in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/migrate-globalprotect-users-from-ldap-portal-to-saml-portal/m-p/516055#M3193</link>
    <description>&lt;P&gt;Dear community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Pleae could someone help with my GlobalProtect transition from LDAP to SAML ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The SAML side of things has been setup and tested. I would now like to move from one portal and gateway (using LDAP auth) to new ones using SAML auth but I am struggling to see how to do this transparently for all our users with minimal disruption or manual intervention from IT.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Example:&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Windows domain managed by GPOs. &lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Current portal &amp;amp; gateway IP:&amp;nbsp; 50.0.0.1 (LDAP auth)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;New portal &amp;amp; gateway IP: 60.0.0.1 (SAML auth using auth cookie)&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;I would like to push the new portal IPs to my GP clients and change the preference so the GP clients will use those new IPs automatically. As a result my users should automatically authenticate to the new SAMP portal and gateway. &amp;nbsp;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm struggling to achieve this. There is a reg key for Windows but that only defines the IP that you get when you install the GP client for for the first time. I won't change anything after the GP client has been installed. Am I missing anything?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I could push new client install from SCCM but again this will cause disruption and will only add a single IP from what I can tell.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any advice would be much appreciated. I need to do this for over a 1000 users around the world.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;Michal&lt;/P&gt;</description>
    <pubDate>Tue, 27 Sep 2022 11:37:08 GMT</pubDate>
    <dc:creator>MichalVavrinec</dc:creator>
    <dc:date>2022-09-27T11:37:08Z</dc:date>
    <item>
      <title>Migrate GlobalProtect users from LDAP portal to SAML portal</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/migrate-globalprotect-users-from-ldap-portal-to-saml-portal/m-p/516055#M3193</link>
      <description>&lt;P&gt;Dear community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Pleae could someone help with my GlobalProtect transition from LDAP to SAML ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The SAML side of things has been setup and tested. I would now like to move from one portal and gateway (using LDAP auth) to new ones using SAML auth but I am struggling to see how to do this transparently for all our users with minimal disruption or manual intervention from IT.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Example:&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Windows domain managed by GPOs. &lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Current portal &amp;amp; gateway IP:&amp;nbsp; 50.0.0.1 (LDAP auth)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;New portal &amp;amp; gateway IP: 60.0.0.1 (SAML auth using auth cookie)&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;I would like to push the new portal IPs to my GP clients and change the preference so the GP clients will use those new IPs automatically. As a result my users should automatically authenticate to the new SAMP portal and gateway. &amp;nbsp;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm struggling to achieve this. There is a reg key for Windows but that only defines the IP that you get when you install the GP client for for the first time. I won't change anything after the GP client has been installed. Am I missing anything?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I could push new client install from SCCM but again this will cause disruption and will only add a single IP from what I can tell.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any advice would be much appreciated. I need to do this for over a 1000 users around the world.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;Michal&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 11:37:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/migrate-globalprotect-users-from-ldap-portal-to-saml-portal/m-p/516055#M3193</guid>
      <dc:creator>MichalVavrinec</dc:creator>
      <dc:date>2022-09-27T11:37:08Z</dc:date>
    </item>
  </channel>
</rss>

