<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SAML Authentication - Users not prompted for password or MFA in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/saml-authentication-users-not-prompted-for-password-or-mfa/m-p/565200#M4611</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;We've setup SAML / SSO and all works OK , however, when GlobalProtect starts, it automatically connects without asking for any creds. I'm assuming this is a result of the machine being joined to the same domain so the password is not needed. However, I'd like to configure it so that at least an MFA prompt occurs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Connecting on a non joined machine does exhibit this behavior.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 10 Nov 2023 18:43:08 GMT</pubDate>
    <dc:creator>SethEfrat</dc:creator>
    <dc:date>2023-11-10T18:43:08Z</dc:date>
    <item>
      <title>SAML Authentication - Users not prompted for password or MFA</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/saml-authentication-users-not-prompted-for-password-or-mfa/m-p/565200#M4611</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;We've setup SAML / SSO and all works OK , however, when GlobalProtect starts, it automatically connects without asking for any creds. I'm assuming this is a result of the machine being joined to the same domain so the password is not needed. However, I'd like to configure it so that at least an MFA prompt occurs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Connecting on a non joined machine does exhibit this behavior.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2023 18:43:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/saml-authentication-users-not-prompted-for-password-or-mfa/m-p/565200#M4611</guid>
      <dc:creator>SethEfrat</dc:creator>
      <dc:date>2023-11-10T18:43:08Z</dc:date>
    </item>
    <item>
      <title>Re: SAML Authentication - Users not prompted for password or MFA</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/saml-authentication-users-not-prompted-for-password-or-mfa/m-p/565271#M4617</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/331192"&gt;@SethEfrat&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When SAML/SSO does not prompt for creds or MFA, it is almost always an authentication cookie.&amp;nbsp; Check you IdP authentication cookie settings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 00:40:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/saml-authentication-users-not-prompted-for-password-or-mfa/m-p/565271#M4617</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-11-13T00:40:01Z</dc:date>
    </item>
    <item>
      <title>Re: SAML Authentication - Users not prompted for password or MFA</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/saml-authentication-users-not-prompted-for-password-or-mfa/m-p/569706#M4731</link>
      <description>&lt;P&gt;This might be a known issue that is being addressed on PANOS 10.2.5 where a&lt;SPAN&gt;ddressed a situation where the firewall failed to appropriately initiate Single Log-out (SLO) towards the client, leading to the client's inability to trigger the SLO request towards the identity provider (IdP). Consequently, this led to the IdP not executing the SLO callback to the firewall for user removal.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I&lt;/SPAN&gt;ssue ID:&amp;nbsp;PAN-213296&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can be found on PANOS 10.2.5 release notes:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-release-notes/pan-os-10-2-5-known-and-addressed-issues/pan-os-10-2-5-addressed-issues" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-release-notes/pan-os-10-2-5-known-and-addressed-issues/pan-os-10-2-5-addressed-issues&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 13:43:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/saml-authentication-users-not-prompted-for-password-or-mfa/m-p/569706#M4731</guid>
      <dc:creator>jfernandez1</dc:creator>
      <dc:date>2023-12-13T13:43:04Z</dc:date>
    </item>
  </channel>
</rss>

