<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global protect: separate vendors and employees in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-separate-vendors-and-employees/m-p/597184#M5784</link>
    <description>&lt;P&gt;Good day,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for the reply; vendors have AD accounts and are also setup with Duo and in a specific group to differentiate between employees and vendors.&lt;/P&gt;
&lt;P&gt;I am not adept at Entra, I would need to get an NA involved for any configuration there, but it seems you are saying there should a way to enforce device compliance for employees and then allows the vendor group to connect by making it compliant?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry if I worded that badly.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Fri, 06 Sep 2024 16:09:04 GMT</pubDate>
    <dc:creator>ChuckW</dc:creator>
    <dc:date>2024-09-06T16:09:04Z</dc:date>
    <item>
      <title>Global protect: separate vendors and employees</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-separate-vendors-and-employees/m-p/596793#M5774</link>
      <description>&lt;P&gt;Setup:&lt;/P&gt;
&lt;P&gt;We have one GP portal and one gateway currently, used by employees and vendors.&lt;/P&gt;
&lt;P&gt;All GP users are authenticated with Entra and Duo MFA.&lt;/P&gt;
&lt;P&gt;We are using a public cert. for the FQDN and a single IP in the current setup.&lt;/P&gt;
&lt;P&gt;Vendors are assigned to a different subnet than employees when connecting to GP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Change:&lt;/P&gt;
&lt;P&gt;We want to use the Entra authentication profile to force employees to only use AD-joined devices that are compliant, this feature is available as part of the Entra authentication configuration and would deny connections if the device did not meet the criteria.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If we turn this on, vendors would not be able to connect with their company's laptop or devices.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is the best way to separate out employees and vendors?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Should we stand up a new portal and gateway just for vendors and copy the current settings over and create a new Entra profile that does not limit the device?&lt;/P&gt;
&lt;P&gt;Can we assign by AD group membership, a new, different Entra profile (create a new one for vendors) and use the existing GP setup with minimal modification?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am looking for the least complicated way of allowing vendors to connect to GP and restrict employees to the Entra restrictions for devices.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2024 19:31:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-separate-vendors-and-employees/m-p/596793#M5774</guid>
      <dc:creator>ChuckW</dc:creator>
      <dc:date>2024-09-04T19:31:10Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect: separate vendors and employees</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-separate-vendors-and-employees/m-p/597183#M5783</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How are you currently identifying vendors within Entra? If you have a vendor group you should be able to add that group to the conditional access in Entra to allow them to still be "compliant".&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 15:59:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-separate-vendors-and-employees/m-p/597183#M5783</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-09-06T15:59:08Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect: separate vendors and employees</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-separate-vendors-and-employees/m-p/597184#M5784</link>
      <description>&lt;P&gt;Good day,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for the reply; vendors have AD accounts and are also setup with Duo and in a specific group to differentiate between employees and vendors.&lt;/P&gt;
&lt;P&gt;I am not adept at Entra, I would need to get an NA involved for any configuration there, but it seems you are saying there should a way to enforce device compliance for employees and then allows the vendor group to connect by making it compliant?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry if I worded that badly.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 16:09:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-separate-vendors-and-employees/m-p/597184#M5784</guid>
      <dc:creator>ChuckW</dc:creator>
      <dc:date>2024-09-06T16:09:04Z</dc:date>
    </item>
  </channel>
</rss>

