<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Agent Client Settings user name match when SAML in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/agent-client-settings-user-name-match-when-saml/m-p/517572#M3248</link>
    <description>&lt;P data-unlink="true"&gt;Usernames are "&lt;A href="mailto:user@domain.com&amp;quot;" target="_blank"&gt;user@domain.com"&lt;/A&gt;&amp;nbsp;on both logs and configuration.&lt;/P&gt;</description>
    <pubDate>Wed, 12 Oct 2022 07:33:17 GMT</pubDate>
    <dc:creator>Anbjorn</dc:creator>
    <dc:date>2022-10-12T07:33:17Z</dc:date>
    <item>
      <title>Agent Client Settings user name match when SAML</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/agent-client-settings-user-name-match-when-saml/m-p/515803#M3191</link>
      <description>&lt;P&gt;I have a SAML setup where I want to match a specific user name to an agent config in the gateway:&lt;/P&gt;
&lt;P&gt;Gateway -&amp;gt; Agent -&amp;gt; Client settings -&amp;gt;&lt;/P&gt;
&lt;P&gt;Source User : &amp;lt;username&amp;gt;&lt;/P&gt;
&lt;P&gt;OS: Any&lt;/P&gt;
&lt;P&gt;Region/IP address: empty&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the SAML authentication profile the username is listed in the Allow List and is authenticated correctly. However, the client errors with "Client config not found". If I set Source User in Agent Client settings to Any, it works and user name show up in both traffic and GP logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Documentation says "You must configure group mapping (&lt;SPAN class="uicontrol"&gt;Device&lt;/SPAN&gt; &amp;gt; &lt;SPAN class="uicontrol"&gt;User Identification&lt;/SPAN&gt; &amp;gt; &lt;SPAN class="uicontrol"&gt;Group Mapping Settings&lt;/SPAN&gt;) before you can select users and groups.", but this is only for AD group mapping. How can I match the username in the SAML login in the Agent client setting?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2022 12:14:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/agent-client-settings-user-name-match-when-saml/m-p/515803#M3191</guid>
      <dc:creator>Anbjorn</dc:creator>
      <dc:date>2022-09-23T12:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: Agent Client Settings user name match when SAML</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/agent-client-settings-user-name-match-when-saml/m-p/517312#M3239</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/118374"&gt;@Anbjorn&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;How do you configure the username for the client settings? Are you using "user@domain.com" or "domain\user" format?&lt;/P&gt;
&lt;P&gt;If you set source username as any and clients connect and get settings successfully, what format you see for the username in the GlobalProtect logs?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2022 14:24:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/agent-client-settings-user-name-match-when-saml/m-p/517312#M3239</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-10-10T14:24:23Z</dc:date>
    </item>
    <item>
      <title>Re: Agent Client Settings user name match when SAML</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/agent-client-settings-user-name-match-when-saml/m-p/517572#M3248</link>
      <description>&lt;P data-unlink="true"&gt;Usernames are "&lt;A href="mailto:user@domain.com&amp;quot;" target="_blank"&gt;user@domain.com"&lt;/A&gt;&amp;nbsp;on both logs and configuration.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 07:33:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/agent-client-settings-user-name-match-when-saml/m-p/517572#M3248</guid>
      <dc:creator>Anbjorn</dc:creator>
      <dc:date>2022-10-12T07:33:17Z</dc:date>
    </item>
    <item>
      <title>Re: Agent Client Settings user name match when SAML</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/agent-client-settings-user-name-match-when-saml/m-p/532491#M3732</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/118374"&gt;@Anbjorn&lt;/a&gt; - did you ever figure this out?&amp;nbsp; I am having a similar issue.&amp;nbsp; I am using SAML and I have an "any" user config which works fine.&amp;nbsp; But I am trying to add a more restrictive config above that one, which contains specific users or groups, and cannot get it to work. All users keep matching the "any" rule.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 17:09:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/agent-client-settings-user-name-match-when-saml/m-p/532491#M3732</guid>
      <dc:creator>tamerfahmy</dc:creator>
      <dc:date>2023-02-28T17:09:39Z</dc:date>
    </item>
    <item>
      <title>Re: Agent Client Settings user name match when SAML</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/agent-client-settings-user-name-match-when-saml/m-p/573085#M4831</link>
      <description>&lt;P&gt;Same here&lt;/P&gt;
&lt;P&gt;We are able to supply configuration to SAML groups using cloud identity engine to pull user to group membership.&lt;/P&gt;
&lt;P&gt;But we can not supply configuration directly to saml users&lt;/P&gt;
&lt;P&gt;Did anyone figure this out ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We do not have any AD or LDAP for user group matching&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2024 16:04:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/agent-client-settings-user-name-match-when-saml/m-p/573085#M4831</guid>
      <dc:creator>gudmundur</dc:creator>
      <dc:date>2024-01-15T16:04:56Z</dc:date>
    </item>
  </channel>
</rss>

