<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authentication Issue with Authentic ID and GlobalProtect Integration in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/authentication-issue-with-authentic-id-and-globalprotect/m-p/594507#M5652</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/934742765"&gt;@hamza_d&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Remember that under the hood GlobalProtect is performing two authentication - first authenticate and connect to GP Portal then authenticate annd connect to GP Gateway. By default GP client will try to reuse the credentials you use for portal to authenticate you to the gateway. With SAML this is not possible. &lt;BR /&gt;&lt;BR /&gt;Try search through the form there should be multiple similar questions, explaining that workaround would be to set GP Portal to create authentication cookie, valid for 1mins and set GP Gateway to accept authentication cookie. This way when user is connecting with GP client, he will be authenticated with SAML against the portal. Portal will give the client cookie, which it will use to authenticate to GP Gateway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You should still keep the SAML authentication on the portal, in case GP client skip portal connection (when using the last known good cached config)&lt;/P&gt;</description>
    <pubDate>Fri, 09 Aug 2024 15:39:47 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2024-08-09T15:39:47Z</dc:date>
    <item>
      <title>Authentication Issue with Authentic ID and GlobalProtect Integration</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/authentication-issue-with-authentic-id-and-globalprotect/m-p/594156#M5636</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have integrated Authentic ID with GlobalProtect as the Identity Provider (IDP), but the username and password fields are not appearing for authentication. Have you encountered a similar issue, or do you have any suggestions on how to resolve it?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="hamza_d_1-1722957486264.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61361iF0BE5725BE4FAA9C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="hamza_d_1-1722957486264.png" alt="hamza_d_1-1722957486264.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Thanks in advance.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2024 15:20:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/authentication-issue-with-authentic-id-and-globalprotect/m-p/594156#M5636</guid>
      <dc:creator>hamza_d</dc:creator>
      <dc:date>2024-08-06T15:20:19Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Issue with Authentic ID and GlobalProtect Integration</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/authentication-issue-with-authentic-id-and-globalprotect/m-p/594180#M5638</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/934742765"&gt;@hamza_d&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What version of GlobalProtect are you using?&lt;/P&gt;
&lt;P&gt;When using SAML authentication, the username and password login form is provided by the IdP. The GlobalProtect just act as simple web browser that visualize the content provided by the IdP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As described here GlobalProtect embedded browser was recently upgraded to use newer framework - &lt;A href="https://docs.paloaltonetworks.com/globalprotect/6-2/globalprotect-app-release-notes/features-introduced-in-gp-app" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/6-2/globalprotect-app-release-notes/features-introduced-in-gp-app&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am wondering if the IdP is having issues with the framework used by the GlobalProtect.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As workaround you may try to switch to "default browser". This will tell GlobalProtect to use the web browser that is set as default for the OS.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2024 19:25:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/authentication-issue-with-authentic-id-and-globalprotect/m-p/594180#M5638</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2024-08-06T19:25:33Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Issue with Authentic ID and GlobalProtect Integration</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/authentication-issue-with-authentic-id-and-globalprotect/m-p/594233#M5645</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What version of GlobalProtect are you using?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;--&amp;gt;6.1.1-5&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 13:30:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/authentication-issue-with-authentic-id-and-globalprotect/m-p/594233#M5645</guid>
      <dc:creator>hamza_d</dc:creator>
      <dc:date>2024-08-07T13:30:10Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Issue with Authentic ID and GlobalProtect Integration</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/authentication-issue-with-authentic-id-and-globalprotect/m-p/594251#M5646</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;After restarting the GlobalProtect service on my Windows machine, GlobalProtect started redirecting to the default browser for authentication via IDP. However, I am now experiencing authentication failures, even though the IDP logs show successful authentication.&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 15:30:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/authentication-issue-with-authentic-id-and-globalprotect/m-p/594251#M5646</guid>
      <dc:creator>hamza_d</dc:creator>
      <dc:date>2024-08-07T15:30:27Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Issue with Authentic ID and GlobalProtect Integration</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/authentication-issue-with-authentic-id-and-globalprotect/m-p/594507#M5652</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/934742765"&gt;@hamza_d&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Remember that under the hood GlobalProtect is performing two authentication - first authenticate and connect to GP Portal then authenticate annd connect to GP Gateway. By default GP client will try to reuse the credentials you use for portal to authenticate you to the gateway. With SAML this is not possible. &lt;BR /&gt;&lt;BR /&gt;Try search through the form there should be multiple similar questions, explaining that workaround would be to set GP Portal to create authentication cookie, valid for 1mins and set GP Gateway to accept authentication cookie. This way when user is connecting with GP client, he will be authenticated with SAML against the portal. Portal will give the client cookie, which it will use to authenticate to GP Gateway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You should still keep the SAML authentication on the portal, in case GP client skip portal connection (when using the last known good cached config)&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2024 15:39:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/authentication-issue-with-authentic-id-and-globalprotect/m-p/594507#M5652</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2024-08-09T15:39:47Z</dc:date>
    </item>
  </channel>
</rss>

