<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global Protect and Azure SAML in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-and-azure-saml/m-p/568230#M4700</link>
    <description>&lt;P&gt;Hi All&lt;/P&gt;
&lt;P&gt;PA-VM running 11.0.02&lt;/P&gt;
&lt;P&gt;Global Protect 6.2.0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After some advise/suggestions&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are rolling out Global Protect for the first time and getting some strange results&lt;/P&gt;
&lt;P&gt;Portal and Gateway Configured to use Azure SAML in addition to this I have followed this article to try and make the whole process simple for users&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HBMdCAO&amp;amp;lang=en_US%E2%80%A9" target="_blank"&gt;Seamless SAML Authentication with default-browser for GlobalPro... - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Both our Azure MFA Sign-in Frequency and Authentication Override cookies are set to 1 hour.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On first login everything seems to work ok and if we attempt to disconnect and reconnect VPN within an hour everything seems to work fine and users can connect without needing to authenticate, however after that hour has passed (I assume the Azure cookie timestamps)&amp;nbsp; then the problems start and users get a mixture of issues - the most common one is Finding Best Gateway just sits there and you might get a second browser open (presumably from the Gateway) advising that authentication is successful and to "click here" to launch global protect but this works intermittently but most times Find Best Gateway just sits there...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone setup Global Protect in this way or have any pointers appreciated&lt;/P&gt;</description>
    <pubDate>Mon, 04 Dec 2023 15:30:09 GMT</pubDate>
    <dc:creator>PBassett</dc:creator>
    <dc:date>2023-12-04T15:30:09Z</dc:date>
    <item>
      <title>Global Protect and Azure SAML</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-and-azure-saml/m-p/568230#M4700</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;
&lt;P&gt;PA-VM running 11.0.02&lt;/P&gt;
&lt;P&gt;Global Protect 6.2.0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After some advise/suggestions&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are rolling out Global Protect for the first time and getting some strange results&lt;/P&gt;
&lt;P&gt;Portal and Gateway Configured to use Azure SAML in addition to this I have followed this article to try and make the whole process simple for users&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HBMdCAO&amp;amp;lang=en_US%E2%80%A9" target="_blank"&gt;Seamless SAML Authentication with default-browser for GlobalPro... - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Both our Azure MFA Sign-in Frequency and Authentication Override cookies are set to 1 hour.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On first login everything seems to work ok and if we attempt to disconnect and reconnect VPN within an hour everything seems to work fine and users can connect without needing to authenticate, however after that hour has passed (I assume the Azure cookie timestamps)&amp;nbsp; then the problems start and users get a mixture of issues - the most common one is Finding Best Gateway just sits there and you might get a second browser open (presumably from the Gateway) advising that authentication is successful and to "click here" to launch global protect but this works intermittently but most times Find Best Gateway just sits there...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone setup Global Protect in this way or have any pointers appreciated&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 15:30:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-and-azure-saml/m-p/568230#M4700</guid>
      <dc:creator>PBassett</dc:creator>
      <dc:date>2023-12-04T15:30:09Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect and Azure SAML</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-and-azure-saml/m-p/589331#M5450</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was wondering if you had the issue resolved.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 23:11:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-and-azure-saml/m-p/589331#M5450</guid>
      <dc:creator>Wowrack-Support</dc:creator>
      <dc:date>2024-06-11T23:11:30Z</dc:date>
    </item>
  </channel>
</rss>

