<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GlobalProtect Azure/SAML MFA prompt everytime a user logs in in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-azure-saml-mfa-prompt-everytime-a-user-logs-in/m-p/586987#M5365</link>
    <description>&lt;P&gt;We have setup Globalprotect to connect to EntraID using SAML. Our goal is to have the user get prompted to enter in MFA everytime they connect to the GlobalProtect portal. How can I do this?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 16 May 2024 16:42:42 GMT</pubDate>
    <dc:creator>asiewert</dc:creator>
    <dc:date>2024-05-16T16:42:42Z</dc:date>
    <item>
      <title>GlobalProtect Azure/SAML MFA prompt everytime a user logs in</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-azure-saml-mfa-prompt-everytime-a-user-logs-in/m-p/586987#M5365</link>
      <description>&lt;P&gt;We have setup Globalprotect to connect to EntraID using SAML. Our goal is to have the user get prompted to enter in MFA everytime they connect to the GlobalProtect portal. How can I do this?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2024 16:42:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-azure-saml-mfa-prompt-everytime-a-user-logs-in/m-p/586987#M5365</guid>
      <dc:creator>asiewert</dc:creator>
      <dc:date>2024-05-16T16:42:42Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Azure/SAML MFA prompt everytime a user logs in</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-azure-saml-mfa-prompt-everytime-a-user-logs-in/m-p/587044#M5366</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/108558"&gt;@asiewert&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I believe the default authentication cookie lifetime in Entra is 90 days.&amp;nbsp; I think these are the steps to change it for your PANW GP application in Entra.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Enterprise Applications &amp;gt; open your GP app&lt;/LI&gt;
&lt;LI&gt;Protection &amp;gt; Conditional Access&lt;/LI&gt;
&lt;LI&gt;New Policy&lt;/LI&gt;
&lt;LI&gt;Access controls &amp;gt; Session&lt;/LI&gt;
&lt;LI&gt;Sign-in frequency &amp;gt; Periodic reauthentication&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/conditional-access/howto-conditional-access-session-lifetime" target="_blank" rel="noopener"&gt;https://learn.microsoft.com/en-us/entra/identity/conditional-access/howto-conditional-access-session-lifetime&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would not set it to 0 as cookie authentication is actually used by Entra (not PANW) for the gateway.&amp;nbsp; That keeps users from being prompted for MFA by the portal &lt;EM&gt;and&lt;/EM&gt; gateway.&amp;nbsp; If you want Entra to prompt them every time, 5 minutes should be good.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2024 22:50:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-azure-saml-mfa-prompt-everytime-a-user-logs-in/m-p/587044#M5366</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-05-16T22:50:20Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Azure/SAML MFA prompt everytime a user logs in</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-azure-saml-mfa-prompt-everytime-a-user-logs-in/m-p/587653#M5377</link>
      <description>&lt;P&gt;I think the session sign-in frequency is key! I believe this is working for us now. Have not tested it extensively, but every time a user logs into GlobalProtect, EntraID will prompt them for multifactor now.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="asiewert_0-1716391076287.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59988i4849DF15B9E0A81D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="asiewert_0-1716391076287.png" alt="asiewert_0-1716391076287.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2024 15:19:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-azure-saml-mfa-prompt-everytime-a-user-logs-in/m-p/587653#M5377</guid>
      <dc:creator>asiewert</dc:creator>
      <dc:date>2024-05-22T15:19:25Z</dc:date>
    </item>
  </channel>
</rss>

