<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Group Login condition Azure Groups in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/group-login-condition-azure-groups/m-p/558274#M4388</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;We are using our on prem LDAP to fetch groups on the Palo. For GP authentication as well, we are using group in&lt;/P&gt;
&lt;P&gt;1) GP Portal &amp;gt; Agent &amp;gt; Config Selection Criteria &amp;gt; User/User Group&lt;/P&gt;
&lt;P&gt;2) GP Gateway &amp;gt; Agent &amp;gt; Client Settings &amp;gt;&amp;nbsp;Config Selection Criteria&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This works well with on prem LDAP. Now we are trialling out SAML with Azure. The Authentication on the SAML succeeds but GP fails to connect because the firewall cannot find the proper group for the user. After looking at logs, it looks like, when we use LDAP the user is identified as domain\username and firewall can lookup LDAP group. When using SAML authentication, the user is identified as &lt;A href="mailto:firstname.lastname@companyname.com" target="_blank"&gt;firstname.lastname@companyname.com&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any idea how to resolve this?&lt;/P&gt;</description>
    <pubDate>Mon, 18 Sep 2023 04:48:43 GMT</pubDate>
    <dc:creator>rjdahav163</dc:creator>
    <dc:date>2023-09-18T04:48:43Z</dc:date>
    <item>
      <title>Group Login condition Azure Groups</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/group-login-condition-azure-groups/m-p/558274#M4388</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;We are using our on prem LDAP to fetch groups on the Palo. For GP authentication as well, we are using group in&lt;/P&gt;
&lt;P&gt;1) GP Portal &amp;gt; Agent &amp;gt; Config Selection Criteria &amp;gt; User/User Group&lt;/P&gt;
&lt;P&gt;2) GP Gateway &amp;gt; Agent &amp;gt; Client Settings &amp;gt;&amp;nbsp;Config Selection Criteria&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This works well with on prem LDAP. Now we are trialling out SAML with Azure. The Authentication on the SAML succeeds but GP fails to connect because the firewall cannot find the proper group for the user. After looking at logs, it looks like, when we use LDAP the user is identified as domain\username and firewall can lookup LDAP group. When using SAML authentication, the user is identified as &lt;A href="mailto:firstname.lastname@companyname.com" target="_blank"&gt;firstname.lastname@companyname.com&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any idea how to resolve this?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 04:48:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/group-login-condition-azure-groups/m-p/558274#M4388</guid>
      <dc:creator>rjdahav163</dc:creator>
      <dc:date>2023-09-18T04:48:43Z</dc:date>
    </item>
  </channel>
</rss>

