<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Add PreLogon to Existing Portal in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/add-prelogon-to-existing-portal/m-p/560532#M4471</link>
    <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our current setup is a GlobalProtect portal that utilizes SSO via the free Okta service.&amp;nbsp; This serves our customers as well as our internal staff.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd like to switch our internal staff laptops to the prelogon method, so they automatically connect with their AD machine cert, and after they login to their laptop, it passes on their username/password to GlobalProtect.&amp;nbsp; All while not interrupting the normal SSO/Okta flow for our other users.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The only hitch is, the user workstation logins are on a different domain than the one that's connected to Okta.&amp;nbsp; So, would I make a new Client Authentication setting?&amp;nbsp; And where would I place it in the priority list?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm assuming then I could make a new agent config, using the certificate device check for the AD domain CA, and assign custom&amp;nbsp; DNS servers, etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any advice/help is greatly appreciated!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 04 Oct 2023 13:34:34 GMT</pubDate>
    <dc:creator>mwagner00</dc:creator>
    <dc:date>2023-10-04T13:34:34Z</dc:date>
    <item>
      <title>Add PreLogon to Existing Portal</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/add-prelogon-to-existing-portal/m-p/560532#M4471</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our current setup is a GlobalProtect portal that utilizes SSO via the free Okta service.&amp;nbsp; This serves our customers as well as our internal staff.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd like to switch our internal staff laptops to the prelogon method, so they automatically connect with their AD machine cert, and after they login to their laptop, it passes on their username/password to GlobalProtect.&amp;nbsp; All while not interrupting the normal SSO/Okta flow for our other users.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The only hitch is, the user workstation logins are on a different domain than the one that's connected to Okta.&amp;nbsp; So, would I make a new Client Authentication setting?&amp;nbsp; And where would I place it in the priority list?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm assuming then I could make a new agent config, using the certificate device check for the AD domain CA, and assign custom&amp;nbsp; DNS servers, etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any advice/help is greatly appreciated!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2023 13:34:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/add-prelogon-to-existing-portal/m-p/560532#M4471</guid>
      <dc:creator>mwagner00</dc:creator>
      <dc:date>2023-10-04T13:34:34Z</dc:date>
    </item>
  </channel>
</rss>

