<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect VPN  Enforcing Password Changes and Google Authenticator MFA in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-vpn-enforcing-password-changes-and-google/m-p/998677#M6257</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1568460073"&gt;@GWong4&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Changing your password upon first logon while connecting to GP and using local user database auth is not natively supported, but you can enforce it using other auth methods like ldap, radius, and saml. For example, user signs into GP that initiates a saml auth request to your IdP of choice. An embedded browser pops-up to sign into your sso service url and your IdP forces users to change their password.&amp;nbsp;Once completed, the IdP sends a saml response back to GP, allowing access. **This can work with radius/ldap server as well. You can also throw in&amp;nbsp;&lt;SPAN&gt;Google Authenticator into the mix through radius or saml.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Are you looking to deploy GlobalProtect for the first time? Do you have an idea of how you want to handle authentication?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Happy to help!&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 17 Dec 2024 21:02:53 GMT</pubDate>
    <dc:creator>JayGolf</dc:creator>
    <dc:date>2024-12-17T21:02:53Z</dc:date>
    <item>
      <title>GlobalProtect VPN  Enforcing Password Changes and Google Authenticator MFA</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-vpn-enforcing-password-changes-and-google/m-p/998366#M6248</link>
      <description>&lt;P data-sourcepos="3:1-3:50"&gt;I have two inquiries regarding GlobalProtect VPN:&lt;/P&gt;
&lt;OL data-sourcepos="5:1-8:0"&gt;
&lt;LI data-sourcepos="5:1-6:0"&gt;
&lt;P data-sourcepos="5:4-5:132"&gt;&lt;STRONG&gt;Password Change:&lt;/STRONG&gt; Is there a feature that mandates users to change their GlobalProtect VPN password after their initial login?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-sourcepos="7:1-8:0"&gt;
&lt;P data-sourcepos="7:4-7:113"&gt;&lt;STRONG&gt;MFA Support:&lt;/STRONG&gt; Does GlobalProtect VPN support Multi-Factor Authentication (MFA) using Google Authenticator?"&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Best Regards&lt;/P&gt;
&lt;P data-sourcepos="9:1-9:21"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 14 Dec 2024 09:13:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-vpn-enforcing-password-changes-and-google/m-p/998366#M6248</guid>
      <dc:creator>GWong4</dc:creator>
      <dc:date>2024-12-14T09:13:37Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect VPN  Enforcing Password Changes and Google Authenticator MFA</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-vpn-enforcing-password-changes-and-google/m-p/998677#M6257</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1568460073"&gt;@GWong4&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Changing your password upon first logon while connecting to GP and using local user database auth is not natively supported, but you can enforce it using other auth methods like ldap, radius, and saml. For example, user signs into GP that initiates a saml auth request to your IdP of choice. An embedded browser pops-up to sign into your sso service url and your IdP forces users to change their password.&amp;nbsp;Once completed, the IdP sends a saml response back to GP, allowing access. **This can work with radius/ldap server as well. You can also throw in&amp;nbsp;&lt;SPAN&gt;Google Authenticator into the mix through radius or saml.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Are you looking to deploy GlobalProtect for the first time? Do you have an idea of how you want to handle authentication?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Happy to help!&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 21:02:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-vpn-enforcing-password-changes-and-google/m-p/998677#M6257</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2024-12-17T21:02:53Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect VPN  Enforcing Password Changes and Google Authenticator MFA</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-vpn-enforcing-password-changes-and-google/m-p/998710#M6264</link>
      <description>&lt;P&gt;Hi jayGolf,&lt;/P&gt;
&lt;P&gt;Thanks for the explanation is because the GP is mainly for external vendor use. Hence I think it is better isolated the external vendor login via firewall features itself.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyway thanks for the explanation&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 02:49:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-vpn-enforcing-password-changes-and-google/m-p/998710#M6264</guid>
      <dc:creator>GWong4</dc:creator>
      <dc:date>2024-12-18T02:49:28Z</dc:date>
    </item>
  </channel>
</rss>

