<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Intune with IOS and Global Protect, utilizing certificate-based authentication troubles. in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/intune-with-ios-and-global-protect-utilizing-certificate-based/m-p/597197#M5790</link>
    <description>&lt;P&gt;We are deploying the app via Intune also, but the way Intune works, if it's all part of the push, but the GP agent exists, then the whole policy script fails.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I had an issue where a user could install GP from the MDM app store of approved apps. If a user installed GP before Intune ran the MDM script for VPN, the whole VPN policy script would fail and the VPN profile never got installed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I&amp;nbsp;&lt;STRONG&gt;&lt;EM&gt;believe&lt;/EM&gt;&lt;/STRONG&gt; that this is due to an Intune issue where the push script fails if the app already exists.&lt;/P&gt;</description>
    <pubDate>Fri, 06 Sep 2024 17:28:12 GMT</pubDate>
    <dc:creator>HCornwell</dc:creator>
    <dc:date>2024-09-06T17:28:12Z</dc:date>
    <item>
      <title>Intune with IOS and Global Protect, utilizing certificate-based authentication troubles.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/intune-with-ios-and-global-protect-utilizing-certificate-based/m-p/564323#M4584</link>
      <description>&lt;P&gt;We have been trying to migrate a client from Airwatch to Intune for MDM management. Part of this deployment was implementing certificate-based authentication for their Global Protect VPN client.&amp;nbsp; We have been successful with Windows, and Android. However, we have not been able to get MacOS, iPadOs, or IOS to work successfully. all the Error logs indicate that the Global Protect application does not know how to identify the certificate that is being deployed via Intune. We have validated that Root and Intermediate certificates are on the devices. I am all ears as to any help anyone can provide on this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 15:41:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/intune-with-ios-and-global-protect-utilizing-certificate-based/m-p/564323#M4584</guid>
      <dc:creator>Ben_Laney</dc:creator>
      <dc:date>2023-11-03T15:41:29Z</dc:date>
    </item>
    <item>
      <title>Re: Intune with IOS and Global Protect, utilizing certificate-based authentication troubles.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/intune-with-ios-and-global-protect-utilizing-certificate-based/m-p/584411#M5271</link>
      <description>&lt;P&gt;Hi Ben,&lt;BR /&gt;I also work on the same setup with intune and ios.&lt;/P&gt;
&lt;P&gt;It seems that we run into the same issue.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you find a solution for that?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the PANGPS log I found the errors:&lt;/P&gt;
&lt;P&gt;"Couldn't find any matching identities. Trying to continue without client cert&lt;/P&gt;
&lt;P&gt;Client cert error detail is Client cert usage check failed&lt;/P&gt;
&lt;P&gt;error detail is Client cert usage check failed"&lt;/P&gt;
&lt;P&gt;Any Idea? Is it a problem with the certificate store lookup?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;kind regards&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Torsten&lt;/P&gt;</description>
      <pubDate>Sun, 21 Apr 2024 15:37:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/intune-with-ios-and-global-protect-utilizing-certificate-based/m-p/584411#M5271</guid>
      <dc:creator>TorstenForster</dc:creator>
      <dc:date>2024-04-21T15:37:38Z</dc:date>
    </item>
    <item>
      <title>Re: Intune with IOS and Global Protect, utilizing certificate-based authentication troubles.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/intune-with-ios-and-global-protect-utilizing-certificate-based/m-p/584698#M5286</link>
      <description>&lt;P&gt;We ended up scaping the project , and going back to Airwatch. if you ever figure it out, i would be interested to know how to get around those errors.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 23:06:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/intune-with-ios-and-global-protect-utilizing-certificate-based/m-p/584698#M5286</guid>
      <dc:creator>Ben_Laney</dc:creator>
      <dc:date>2024-04-23T23:06:51Z</dc:date>
    </item>
    <item>
      <title>Re: Intune with IOS and Global Protect, utilizing certificate-based authentication troubles.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/intune-with-ios-and-global-protect-utilizing-certificate-based/m-p/585025#M5300</link>
      <description>&lt;P&gt;Yes, we found a solution right know.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Problem was that the intune vpn profile wasn't pushed to the device. My Collegues analyzed it and changed something. Now, everything is working fine with a split vpn setup. Certificate autheneticaten and user authentication is working fine.&lt;/P&gt;
&lt;P&gt;Also the tag detection on the device.&lt;/P&gt;
&lt;P&gt;The only problem we found is that intune doesn't remove the app again. Only installation is working fine&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2024 06:56:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/intune-with-ios-and-global-protect-utilizing-certificate-based/m-p/585025#M5300</guid>
      <dc:creator>TorstenForster</dc:creator>
      <dc:date>2024-04-26T06:56:07Z</dc:date>
    </item>
    <item>
      <title>Re: Intune with IOS and Global Protect, utilizing certificate-based authentication troubles.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/intune-with-ios-and-global-protect-utilizing-certificate-based/m-p/585072#M5303</link>
      <description>&lt;P&gt;If you could find out what your colleagues did to get it to work, you would be a life saver.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2024 14:55:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/intune-with-ios-and-global-protect-utilizing-certificate-based/m-p/585072#M5303</guid>
      <dc:creator>Ben_Laney</dc:creator>
      <dc:date>2024-04-26T14:55:35Z</dc:date>
    </item>
    <item>
      <title>Re: Intune with IOS and Global Protect, utilizing certificate-based authentication troubles.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/intune-with-ios-and-global-protect-utilizing-certificate-based/m-p/585663#M5327</link>
      <description>&lt;P&gt;There was a wrong userrole mapping. With the right mapping, also the VPN config will be pushed to the client. Without, only the VPN client will be pushed to the client.&lt;/P&gt;
&lt;P&gt;Its not easy to see this misconfiguration inside intune logs.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 16:13:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/intune-with-ios-and-global-protect-utilizing-certificate-based/m-p/585663#M5327</guid>
      <dc:creator>TorstenForster</dc:creator>
      <dc:date>2024-05-02T16:13:54Z</dc:date>
    </item>
    <item>
      <title>Re: Intune with IOS and Global Protect, utilizing certificate-based authentication troubles.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/intune-with-ios-and-global-protect-utilizing-certificate-based/m-p/596787#M5773</link>
      <description>&lt;P&gt;For GlobalProtect on iOS iPhone or iPad to be managed by Microsoft Intune for user certificate authentication, Intune must contain an iOS device VPN policy with:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Connection Type: Palo Alto Networks GlobalProtect&lt;BR /&gt;Connection Name: &lt;EM&gt;&amp;lt;variable free form&amp;gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;VPN server Address: &lt;EM&gt;&amp;lt;GlobalProtect Portal FQDN or IP&amp;gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Authentication method: Derived credential&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2024 17:38:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/intune-with-ios-and-global-protect-utilizing-certificate-based/m-p/596787#M5773</guid>
      <dc:creator>HCornwell</dc:creator>
      <dc:date>2024-09-04T17:38:50Z</dc:date>
    </item>
    <item>
      <title>Re: Intune with IOS and Global Protect, utilizing certificate-based authentication troubles.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/intune-with-ios-and-global-protect-utilizing-certificate-based/m-p/596988#M5779</link>
      <description>&lt;P&gt;Hcornwell, are you talking about the pre-canned VPN policy that MS offers in intune?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2024 14:43:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/intune-with-ios-and-global-protect-utilizing-certificate-based/m-p/596988#M5779</guid>
      <dc:creator>Ben_Laney</dc:creator>
      <dc:date>2024-09-05T14:43:48Z</dc:date>
    </item>
    <item>
      <title>Re: Intune with IOS and Global Protect, utilizing certificate-based authentication troubles.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/intune-with-ios-and-global-protect-utilizing-certificate-based/m-p/597190#M5786</link>
      <description>&lt;P&gt;Here is the Intune SS for my reference.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There must also be an install of GP, be it pushed via MDM or user download. Once the Intune policy exists on the iPhone, then the GP client can be installed.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 16:39:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/intune-with-ios-and-global-protect-utilizing-certificate-based/m-p/597190#M5786</guid>
      <dc:creator>HCornwell</dc:creator>
      <dc:date>2024-09-06T16:39:43Z</dc:date>
    </item>
    <item>
      <title>Re: Intune with IOS and Global Protect, utilizing certificate-based authentication troubles.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/intune-with-ios-and-global-protect-utilizing-certificate-based/m-p/597192#M5787</link>
      <description>&lt;P&gt;So the Policy has to be deployed prior to the Install being pushed?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 16:58:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/intune-with-ios-and-global-protect-utilizing-certificate-based/m-p/597192#M5787</guid>
      <dc:creator>Ben_Laney</dc:creator>
      <dc:date>2024-09-06T16:58:45Z</dc:date>
    </item>
    <item>
      <title>Re: Intune with IOS and Global Protect, utilizing certificate-based authentication troubles.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/intune-with-ios-and-global-protect-utilizing-certificate-based/m-p/597193#M5788</link>
      <description>&lt;P&gt;That is only in my environment due to app controls in Intune. It is entirely dependent on your Intune MDM controls and deployment. This is not a GP consideration.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 17:02:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/intune-with-ios-and-global-protect-utilizing-certificate-based/m-p/597193#M5788</guid>
      <dc:creator>HCornwell</dc:creator>
      <dc:date>2024-09-06T17:02:04Z</dc:date>
    </item>
    <item>
      <title>Re: Intune with IOS and Global Protect, utilizing certificate-based authentication troubles.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/intune-with-ios-and-global-protect-utilizing-certificate-based/m-p/597194#M5789</link>
      <description>&lt;P&gt;Got it, so you are deploying the app , not through intune . only the policy? correct.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 17:08:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/intune-with-ios-and-global-protect-utilizing-certificate-based/m-p/597194#M5789</guid>
      <dc:creator>Ben_Laney</dc:creator>
      <dc:date>2024-09-06T17:08:06Z</dc:date>
    </item>
    <item>
      <title>Re: Intune with IOS and Global Protect, utilizing certificate-based authentication troubles.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/intune-with-ios-and-global-protect-utilizing-certificate-based/m-p/597197#M5790</link>
      <description>&lt;P&gt;We are deploying the app via Intune also, but the way Intune works, if it's all part of the push, but the GP agent exists, then the whole policy script fails.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I had an issue where a user could install GP from the MDM app store of approved apps. If a user installed GP before Intune ran the MDM script for VPN, the whole VPN policy script would fail and the VPN profile never got installed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I&amp;nbsp;&lt;STRONG&gt;&lt;EM&gt;believe&lt;/EM&gt;&lt;/STRONG&gt; that this is due to an Intune issue where the push script fails if the app already exists.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 17:28:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/intune-with-ios-and-global-protect-utilizing-certificate-based/m-p/597197#M5790</guid>
      <dc:creator>HCornwell</dc:creator>
      <dc:date>2024-09-06T17:28:12Z</dc:date>
    </item>
    <item>
      <title>Re: Intune with IOS and Global Protect, utilizing certificate-based authentication troubles.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/intune-with-ios-and-global-protect-utilizing-certificate-based/m-p/597219#M5792</link>
      <description>&lt;P&gt;Ok, this makes sense. Did you have a way of logging those policy's not working, I mean did you see them in the intune logs?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 20:56:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/intune-with-ios-and-global-protect-utilizing-certificate-based/m-p/597219#M5792</guid>
      <dc:creator>Ben_Laney</dc:creator>
      <dc:date>2024-09-06T20:56:37Z</dc:date>
    </item>
  </channel>
</rss>

