<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN SSO with MFA every time in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-sso-with-mfa-every-time/m-p/521883#M3443</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have recently purchased a Palo Alto firewall and connect to the VPN using GlobalProtect.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For Teams/Sharepoint etc. We use Azure MFA where a push notification comes through to the authenticator app and to get this working on GlobalProtect we had to set up a radius server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The reason we can't use Azure MFA with GlobalProtect is that we want someone to be prompted for MFA &lt;U&gt;every time&lt;/U&gt; they connect to the VPN.&amp;nbsp; This works with radius but with Azure MFA you only get prompted once per hour.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem we have is that now we can't use single sign on for Global Protect as this doesn't work with Radius.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any way around this - so we can have single sign on and be prompted for MFA on the microsoft authenticator app every time?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Mon, 21 Nov 2022 15:41:25 GMT</pubDate>
    <dc:creator>edmozley</dc:creator>
    <dc:date>2022-11-21T15:41:25Z</dc:date>
    <item>
      <title>VPN SSO with MFA every time</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-sso-with-mfa-every-time/m-p/521883#M3443</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have recently purchased a Palo Alto firewall and connect to the VPN using GlobalProtect.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For Teams/Sharepoint etc. We use Azure MFA where a push notification comes through to the authenticator app and to get this working on GlobalProtect we had to set up a radius server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The reason we can't use Azure MFA with GlobalProtect is that we want someone to be prompted for MFA &lt;U&gt;every time&lt;/U&gt; they connect to the VPN.&amp;nbsp; This works with radius but with Azure MFA you only get prompted once per hour.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem we have is that now we can't use single sign on for Global Protect as this doesn't work with Radius.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any way around this - so we can have single sign on and be prompted for MFA on the microsoft authenticator app every time?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 21 Nov 2022 15:41:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-sso-with-mfa-every-time/m-p/521883#M3443</guid>
      <dc:creator>edmozley</dc:creator>
      <dc:date>2022-11-21T15:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SSO with MFA every time</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-sso-with-mfa-every-time/m-p/522497#M3458</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/258035"&gt;@edmozley&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I am not sure if I understand your question, so let me know if I got it wrong.&lt;/P&gt;
&lt;P&gt;If you want GlobalProtect to prompt user only once every hour, the simple way is to use &lt;A href="https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/authentication/about-globalprotect-user-authentication/how-does-the-app-know-what-credentials-to-supply/cookie-authentication-on-the-portal-or-gateway" target="_blank"&gt;Cookie Authentication on the Portal or Gateway (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Basically when user have authenticated successfully, FW will generate a cookie which will be sent to the GP client (you can configure the lifetime duration of the cookie, aka how long after its creations is considered valid). Upon next connection GP client will first send it cookie (if such exist on the machine), FW will check its validity and if it valid will authenticate the user without prompting the user for credentials.&lt;/P&gt;</description>
      <pubDate>Sun, 27 Nov 2022 17:07:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-sso-with-mfa-every-time/m-p/522497#M3458</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-11-27T17:07:24Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SSO with MFA every time</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-sso-with-mfa-every-time/m-p/583432#M5244</link>
      <description>&lt;P&gt;Hello, where you able to find a way to prompt a user for MFA each time they sign on using Microsoft Authentication and SAML?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2024 20:17:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-sso-with-mfa-every-time/m-p/583432#M5244</guid>
      <dc:creator>cdamore</dc:creator>
      <dc:date>2024-04-11T20:17:20Z</dc:date>
    </item>
  </channel>
</rss>

