<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect SAML Azure AD Entera ID and cookies in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-saml-azure-ad-entera-id-and-cookies/m-p/576778#M4951</link>
    <description>&lt;P&gt;AFAIK this is a side effect of how windows stores identities once you have a SAML token for an account in your system. The SAML authentication is a direct connection with the IdP which retrieves your stored identities&lt;/P&gt;</description>
    <pubDate>Fri, 09 Feb 2024 09:14:19 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2024-02-09T09:14:19Z</dc:date>
    <item>
      <title>GlobalProtect SAML Azure AD Entera ID and cookies</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-saml-azure-ad-entera-id-and-cookies/m-p/576607#M4950</link>
      <description>&lt;DIV class="usertext-body may-blank-within md-container "&gt;
&lt;DIV class="md"&gt;
&lt;P&gt;Hi, we have recently implemented Azure Entera ID SAML auth on our portal/gateway on a customer. This works fine with authenticating.&lt;/P&gt;
&lt;P&gt;However there is a small quirk that is annoying. Everytime the client needs to connect, they have to choose which account to use (They have other private Office accounts as well as the business one). Even though they are logged in with their main account, it is still asking for which account to use.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See screenshots for more details: &lt;A href="https://imgur.com/a/qqQd8Kd" target="_blank"&gt;https://imgur.com/a/qqQd8Kd&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;How do you use your SAML auth to make this work okay?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Current cookie settings:&lt;/P&gt;
&lt;P&gt;Portal: Generate cookie Checked. Accept Cookie Checked. Lifetime 2 days.&lt;/P&gt;
&lt;P&gt;Gateway: Generate cookie Unchecked. Accept Cookie Checked. Lifetime 24 hours.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Thu, 08 Feb 2024 12:26:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-saml-azure-ad-entera-id-and-cookies/m-p/576607#M4950</guid>
      <dc:creator>daniel.nicklasson</dc:creator>
      <dc:date>2024-02-08T12:26:51Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect SAML Azure AD Entera ID and cookies</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-saml-azure-ad-entera-id-and-cookies/m-p/576778#M4951</link>
      <description>&lt;P&gt;AFAIK this is a side effect of how windows stores identities once you have a SAML token for an account in your system. The SAML authentication is a direct connection with the IdP which retrieves your stored identities&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2024 09:14:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-saml-azure-ad-entera-id-and-cookies/m-p/576778#M4951</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-02-09T09:14:19Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect SAML Azure AD Entera ID and cookies</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-saml-azure-ad-entera-id-and-cookies/m-p/576945#M4959</link>
      <description>&lt;P&gt;Not exactly you case, our ousers just have one Account, but to avoid tons of Auth Requests (MFA for example) we create and also accept then cookies. helps also when user changes in the office from LAN to WLAN for example.&lt;/P&gt;</description>
      <pubDate>Sun, 11 Feb 2024 19:14:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-saml-azure-ad-entera-id-and-cookies/m-p/576945#M4959</guid>
      <dc:creator>ThomasZetzsche</dc:creator>
      <dc:date>2024-02-11T19:14:36Z</dc:date>
    </item>
  </channel>
</rss>

