<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Clientless VPN portal and SAML SSO and Application SSO in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/clientless-vpn-portal-and-saml-sso-and-application-sso/m-p/583370#M5243</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you find working solution for this kind of integration with SAML. I was able to create SAML for for Global Protect Portal and Clientless VPN. And now I want to create something similar with internal published application Guacamole with SAML, but is this possible at all, from the perspective of first SAML session of the login to GP Portal, then further use for internal published application?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Matjaž&lt;/P&gt;</description>
    <pubDate>Thu, 11 Apr 2024 12:27:30 GMT</pubDate>
    <dc:creator>matjazp</dc:creator>
    <dc:date>2024-04-11T12:27:30Z</dc:date>
    <item>
      <title>Clientless VPN portal and SAML SSO and Application SSO</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/clientless-vpn-portal-and-saml-sso-and-application-sso/m-p/573319#M4837</link>
      <description>&lt;P&gt;Hi there, I wanted to check that possibly what I'm trying isn't actually going to work. Had a look around at people with simular issues on LDAP, but I thought using SAML would solve this ... but not!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What I'm trying to achieve here is SSO into the VPN portal and then into any applications that use the same SSO method (the method we are using is SAML via Microsoft Entra (365).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have SAML SSO working as an auth profile for the Global Protect Portal... works perfectly. I have Applications (Guacamole, One Drive) that can be accessed via the VPN portal.. but the first time I access one of these I'm prompted again for My Microsoft sign in. If I then use any other Microsoft SSO app I'm not prompted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this expected as there is no link between the outside "session" and the sessions inside the portal?.. Is this possible to achieve (no double login)?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 11:57:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/clientless-vpn-portal-and-saml-sso-and-application-sso/m-p/573319#M4837</guid>
      <dc:creator>DTGHelp</dc:creator>
      <dc:date>2024-01-17T11:57:36Z</dc:date>
    </item>
    <item>
      <title>Re: Clientless VPN portal and SAML SSO and Application SSO</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/clientless-vpn-portal-and-saml-sso-and-application-sso/m-p/573356#M4838</link>
      <description>&lt;P&gt;It depends on&amp;nbsp;Microsoft Entra settings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In DUO SAML for example it is possible to configure if every application needs to be accepted with 2FA or any of them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Raido_Rattameister_0-1705517453954.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56586iED053F9D9EA8B2CA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Raido_Rattameister_0-1705517453954.png" alt="Raido_Rattameister_0-1705517453954.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 18:52:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/clientless-vpn-portal-and-saml-sso-and-application-sso/m-p/573356#M4838</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2024-01-17T18:52:34Z</dc:date>
    </item>
    <item>
      <title>Re: Clientless VPN portal and SAML SSO and Application SSO</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/clientless-vpn-portal-and-saml-sso-and-application-sso/m-p/583370#M5243</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you find working solution for this kind of integration with SAML. I was able to create SAML for for Global Protect Portal and Clientless VPN. And now I want to create something similar with internal published application Guacamole with SAML, but is this possible at all, from the perspective of first SAML session of the login to GP Portal, then further use for internal published application?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Matjaž&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2024 12:27:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/clientless-vpn-portal-and-saml-sso-and-application-sso/m-p/583370#M5243</guid>
      <dc:creator>matjazp</dc:creator>
      <dc:date>2024-04-11T12:27:30Z</dc:date>
    </item>
  </channel>
</rss>

