<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo Alto with Azure SAML issue in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/palo-alto-with-azure-saml-issue/m-p/582942#M5232</link>
    <description>&lt;P&gt;I am using FQDN for my GP url and for my identifier in azure . Not sure why the error is showing the IP Address instead.&lt;/P&gt;</description>
    <pubDate>Mon, 08 Apr 2024 14:43:24 GMT</pubDate>
    <dc:creator>Kevin-Ng</dc:creator>
    <dc:date>2024-04-08T14:43:24Z</dc:date>
    <item>
      <title>Palo Alto with Azure SAML issue</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/palo-alto-with-azure-saml-issue/m-p/580048#M5112</link>
      <description>&lt;P&gt;Hi all, I have configured all the required basic SAML configurations in Azure, and assigned a few test AD users to GlobalProtect enterprise application. Also configured those required settings on the Palo Alto end where I import the XML cert, create an authentication profile, and assign the profile to both my gateway and portal. You can refer to my screenshots of those configurations.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what issue i faced, once i redirect to the Microsoft portal login, and after login in, i got the below error message,&lt;/P&gt;
&lt;P&gt;Anyone can help me find the root cause of this?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KevinNg_3-1710232179173.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58242i6FFA20B23A618E82/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="KevinNg_3-1710232179173.png" alt="KevinNg_3-1710232179173.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Below are my configuration:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KevinNg_0-1710231902791.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58239i46E6E566CA1436A9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="KevinNg_0-1710231902791.png" alt="KevinNg_0-1710231902791.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KevinNg_1-1710232073112.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58240iC9C7A6BC0BEED6D6/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="KevinNg_1-1710232073112.png" alt="KevinNg_1-1710232073112.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KevinNg_2-1710232093067.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58241i1AAB30AF234F9A78/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="KevinNg_2-1710232093067.png" alt="KevinNg_2-1710232093067.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="GlobalProtect" id="GlobalProtect"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp; &lt;LI-PRODUCT title="Azure" id="Azure"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2024 08:32:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/palo-alto-with-azure-saml-issue/m-p/580048#M5112</guid>
      <dc:creator>Kevin-Ng</dc:creator>
      <dc:date>2024-03-12T08:32:07Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto with Azure SAML issue</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/palo-alto-with-azure-saml-issue/m-p/580078#M5116</link>
      <description>&lt;P&gt;Hi Kevin,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you checked the authd.log? I would say this could be related to problems with the SAML request/response.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;less mp-log authd.log&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2024 15:22:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/palo-alto-with-azure-saml-issue/m-p/580078#M5116</guid>
      <dc:creator>Anderson_D</dc:creator>
      <dc:date>2024-03-12T15:22:59Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto with Azure SAML issue</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/palo-alto-with-azure-saml-issue/m-p/581340#M5170</link>
      <description>&lt;P&gt;Hi, this is the error i getting . not sure what is it about? do you know?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2024 12:45:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/palo-alto-with-azure-saml-issue/m-p/581340#M5170</guid>
      <dc:creator>Kevin-Ng</dc:creator>
      <dc:date>2024-03-22T12:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto with Azure SAML issue</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/palo-alto-with-azure-saml-issue/m-p/581346#M5171</link>
      <description>&lt;P&gt;It seems your time is not synchronized between the firewall and the IdP (Azure), thus the firewall will reject the SAML response.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is also explained here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PM4rCAG" target="_blank"&gt;Authentication error due to timestamp in SAML message from IdP - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2024 13:05:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/palo-alto-with-azure-saml-issue/m-p/581346#M5171</guid>
      <dc:creator>Anderson_D</dc:creator>
      <dc:date>2024-03-22T13:05:17Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto with Azure SAML issue</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/palo-alto-with-azure-saml-issue/m-p/581449#M5176</link>
      <description>&lt;P&gt;My Palo alto have already configured with sg.pool.ntp.org. But do you happen to know where i can configure NTP/timezone for my Azure IdP?&lt;/P&gt;</description>
      <pubDate>Sat, 23 Mar 2024 07:46:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/palo-alto-with-azure-saml-issue/m-p/581449#M5176</guid>
      <dc:creator>Kevin-Ng</dc:creator>
      <dc:date>2024-03-23T07:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto with Azure SAML issue</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/palo-alto-with-azure-saml-issue/m-p/581615#M5184</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't know, I've been configuring Azure SAML for multiple regions in different timezones without issues.&lt;/P&gt;
&lt;P&gt;Is the firewall configured in the correct timezone besides the NTP server (Device &amp;gt; Setup &amp;gt; Management &amp;gt; Time Zone)? I'm asking this because all SAML messages are in UTC format, maybe your problem is the firewall not being in the correct time zone and the converted time to UTC is not matching Azure's.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2024 21:50:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/palo-alto-with-azure-saml-issue/m-p/581615#M5184</guid>
      <dc:creator>Anderson_D</dc:creator>
      <dc:date>2024-03-25T21:50:42Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto with Azure SAML issue</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/palo-alto-with-azure-saml-issue/m-p/582920#M5230</link>
      <description>&lt;P&gt;thanks &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206601"&gt;@Anderson_D&lt;/a&gt;&amp;nbsp;! i managed to resolve this error.&lt;/P&gt;
&lt;P&gt;Now I have a new error where I now able to login from the browser. But when I tried to log in from the GlobalProtect App itself. i got the error from the attached image "121". Do you know what is the setting i miss out?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 10:09:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/palo-alto-with-azure-saml-issue/m-p/582920#M5230</guid>
      <dc:creator>Kevin-Ng</dc:creator>
      <dc:date>2024-04-08T10:09:02Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto with Azure SAML issue</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/palo-alto-with-azure-saml-issue/m-p/582938#M5231</link>
      <description>&lt;P&gt;Make sure your Global Protect URL matches the URL identifier configured in Azure, otherwise the request will be denied.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 14:10:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/palo-alto-with-azure-saml-issue/m-p/582938#M5231</guid>
      <dc:creator>Anderson_D</dc:creator>
      <dc:date>2024-04-08T14:10:11Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto with Azure SAML issue</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/palo-alto-with-azure-saml-issue/m-p/582942#M5232</link>
      <description>&lt;P&gt;I am using FQDN for my GP url and for my identifier in azure . Not sure why the error is showing the IP Address instead.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 14:43:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/palo-alto-with-azure-saml-issue/m-p/582942#M5232</guid>
      <dc:creator>Kevin-Ng</dc:creator>
      <dc:date>2024-04-08T14:43:24Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto with Azure SAML issue</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/palo-alto-with-azure-saml-issue/m-p/582948#M5233</link>
      <description>&lt;P&gt;But even under GlobalProtect &amp;gt; Portals &amp;gt; Agent &amp;gt; External Gateways?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 15:16:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/palo-alto-with-azure-saml-issue/m-p/582948#M5233</guid>
      <dc:creator>Anderson_D</dc:creator>
      <dc:date>2024-04-08T15:16:24Z</dc:date>
    </item>
  </channel>
</rss>

