<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IOS + User logon (Always On) + SAML is not working... in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ios-user-logon-always-on-saml-is-not-working/m-p/519633#M3386</link>
    <description>&lt;P&gt;SAML is only supported for iOS with On-Demand.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/compatibility-matrix/globalprotect/what-features-does-globalprotect-support" target="_blank"&gt;What Features Does GlobalProtect Support? (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 30 Oct 2022 20:23:14 GMT</pubDate>
    <dc:creator>dmifsud</dc:creator>
    <dc:date>2022-10-30T20:23:14Z</dc:date>
    <item>
      <title>IOS + User logon (Always On) + SAML is not working...</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ios-user-logon-always-on-saml-is-not-working/m-p/474189#M2600</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&amp;gt;Founf this in the release note: GPC-6663 &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The GlobalProtect app for iOS does not support SAML authentication when you configure GlobalProtect with the User-logon (Always On) Connect Method (NetworkGlobalProtectPortals&amp;lt;portal-config&amp;gt;Agent&amp;lt;agent-config&amp;gt;App). This limitation is due to the Apple Network Extension framework, which blocks network connections from the GlobalProtect app (where users are authenticated to their organization’s SAML identity provider) until the VPN tunnel is created. #&lt;/SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/4-1/globalprotect-app-release-notes/gp-app-release-information/limitations.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/globalprotect/4-1/globalprotect-app-release-notes/gp-app-release-information/limitations.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt;&lt;SPAN&gt;In the newer versions 5.1,5.2,5.3 and 6.0 I didn't see information that this issue got fixed, (since it's due to the Apple Network Extension framework, probably it can not be fixed on our side alone?).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt;Work around found here in this article, please follow the resolution to configure On-demand as Connect Method for IOS devices. &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PMfYCAW" target="_blank" rel="noopener"&gt;#https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PMfYCAW&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt;Is there any solution to this?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2022 01:35:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ios-user-logon-always-on-saml-is-not-working/m-p/474189#M2600</guid>
      <dc:creator>rxie</dc:creator>
      <dc:date>2022-03-18T01:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: IOS + User logon (Always On) + SAML is not working...</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ios-user-logon-always-on-saml-is-not-working/m-p/519591#M3385</link>
      <description>&lt;P&gt;We're experiencing the same issue. Appreciate the insight. After applying your linked work around I'm unable to get the iOS agent config selection criteria to apply despite being having the iOS os specific profile above the any OS profile. Used no login banner in the iOS profile to distinguish between the 2 profiles. I still see the login banner and get the app notification "Always on mode is enabled. Please login to continue". Regardless submitted PA-TAC ticket and will post how we resolve.&lt;/P&gt;</description>
      <pubDate>Sat, 29 Oct 2022 01:55:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ios-user-logon-always-on-saml-is-not-working/m-p/519591#M3385</guid>
      <dc:creator>Joseph.Johnson</dc:creator>
      <dc:date>2022-10-29T01:55:12Z</dc:date>
    </item>
    <item>
      <title>Re: IOS + User logon (Always On) + SAML is not working...</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ios-user-logon-always-on-saml-is-not-working/m-p/519633#M3386</link>
      <description>&lt;P&gt;SAML is only supported for iOS with On-Demand.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/compatibility-matrix/globalprotect/what-features-does-globalprotect-support" target="_blank"&gt;What Features Does GlobalProtect Support? (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 30 Oct 2022 20:23:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ios-user-logon-always-on-saml-is-not-working/m-p/519633#M3386</guid>
      <dc:creator>dmifsud</dc:creator>
      <dc:date>2022-10-30T20:23:14Z</dc:date>
    </item>
  </channel>
</rss>

