<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect on Android vs Compliance requirements from Intune in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-on-android-vs-compliance-requirements-from-intune/m-p/1224895#M6608</link>
    <description>&lt;P&gt;Ok, Lets clarify.&lt;/P&gt;
&lt;P&gt;We have some mobile based on Android. We want to use global protect client to start our internal web site.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our Global protect uses SAML profile for authentication (Office365).&lt;/P&gt;
&lt;P&gt;But we have Intune for management of devices, they are in fully management profile. In our conditional access policies (Azure Active Directory) we require that all apps must be connnected from COMPLIANT devices. All office apps and edge works fine.&lt;/P&gt;
&lt;P&gt;The problem is that Global Protect client started on Android devices cannot pass this information to Azure Active Directory).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On Windows&amp;nbsp; works fine. I think that it is limitation of global protect client on Android.&lt;/P&gt;</description>
    <pubDate>Thu, 27 Mar 2025 08:58:59 GMT</pubDate>
    <dc:creator>ITSpravia</dc:creator>
    <dc:date>2025-03-27T08:58:59Z</dc:date>
    <item>
      <title>Global Protect on Android vs Compliance requirements from Intune</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-on-android-vs-compliance-requirements-from-intune/m-p/1224642#M6600</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;We'd like to use Global Protect on Android (latest Samsung). There devices are managed by Intune in Full Management profile.&lt;/P&gt;
&lt;P&gt;For Global Protect we use SAML profile with MFA and Conditional Access.&lt;/P&gt;
&lt;P&gt;All our users have compliance requirements (by conditional access policies) to use SAML only on compliant devices.&lt;/P&gt;
&lt;P&gt;Global protect cannot bypass this info for AAD.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Of course, we can remove compliance requirements for Global Protect App in AAD, but this will create huge security hole in our security.&lt;/P&gt;
&lt;P&gt;What to do ?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Mar 2025 13:35:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-on-android-vs-compliance-requirements-from-intune/m-p/1224642#M6600</guid>
      <dc:creator>ITSpravia</dc:creator>
      <dc:date>2025-03-25T13:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect on Android vs Compliance requirements from Intune</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-on-android-vs-compliance-requirements-from-intune/m-p/1224856#M6604</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/594840627"&gt;@ITSpravia&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Can you provide more detail about what the actual issue is? I've re-read your post a couple times and I'm kind of lost on what you're actually running into and what the actual problem is in your post. &lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 21:59:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-on-android-vs-compliance-requirements-from-intune/m-p/1224856#M6604</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2025-03-26T21:59:31Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect on Android vs Compliance requirements from Intune</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-on-android-vs-compliance-requirements-from-intune/m-p/1224895#M6608</link>
      <description>&lt;P&gt;Ok, Lets clarify.&lt;/P&gt;
&lt;P&gt;We have some mobile based on Android. We want to use global protect client to start our internal web site.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our Global protect uses SAML profile for authentication (Office365).&lt;/P&gt;
&lt;P&gt;But we have Intune for management of devices, they are in fully management profile. In our conditional access policies (Azure Active Directory) we require that all apps must be connnected from COMPLIANT devices. All office apps and edge works fine.&lt;/P&gt;
&lt;P&gt;The problem is that Global Protect client started on Android devices cannot pass this information to Azure Active Directory).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On Windows&amp;nbsp; works fine. I think that it is limitation of global protect client on Android.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2025 08:58:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-on-android-vs-compliance-requirements-from-intune/m-p/1224895#M6608</guid>
      <dc:creator>ITSpravia</dc:creator>
      <dc:date>2025-03-27T08:58:59Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect on Android vs Compliance requirements from Intune</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-on-android-vs-compliance-requirements-from-intune/m-p/1225815#M6648</link>
      <description>&lt;P&gt;Official support said that the only way to enable it in our environment is to add global protect app as exception in Conditional access polisy in Azure Active Directory.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 08:32:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-on-android-vs-compliance-requirements-from-intune/m-p/1225815#M6648</guid>
      <dc:creator>ITSpravia</dc:creator>
      <dc:date>2025-04-07T08:32:05Z</dc:date>
    </item>
  </channel>
</rss>

