<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GlobalProtect with Azure MFA setup in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-with-azure-mfa-setup/m-p/367764#M666</link>
    <description>&lt;P&gt;Good Morning Everyone,&lt;/P&gt;&lt;P&gt;Has anyone had any luck setting up MFA on the Palo Alto with Global Protect with Microsoft Azure MFA (Hybrid) I tried opening a ticket with the support team and they said they had no clue how to setup but could support it if broken and told me a "Sales" Engineer would reach out to me sometime that day. That was 4 business days ago.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been reading articles but have not had luck with them. Anyone have an Idiots guide to setting up Microsoft Azure MFA with Global protect?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA Version: 8.1.15&lt;/P&gt;&lt;P&gt;Global Protect Client: 5.1.1&lt;/P&gt;</description>
    <pubDate>Tue, 08 Dec 2020 13:39:25 GMT</pubDate>
    <dc:creator>CharlesHanley</dc:creator>
    <dc:date>2020-12-08T13:39:25Z</dc:date>
    <item>
      <title>GlobalProtect with Azure MFA setup</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-with-azure-mfa-setup/m-p/367764#M666</link>
      <description>&lt;P&gt;Good Morning Everyone,&lt;/P&gt;&lt;P&gt;Has anyone had any luck setting up MFA on the Palo Alto with Global Protect with Microsoft Azure MFA (Hybrid) I tried opening a ticket with the support team and they said they had no clue how to setup but could support it if broken and told me a "Sales" Engineer would reach out to me sometime that day. That was 4 business days ago.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been reading articles but have not had luck with them. Anyone have an Idiots guide to setting up Microsoft Azure MFA with Global protect?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA Version: 8.1.15&lt;/P&gt;&lt;P&gt;Global Protect Client: 5.1.1&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 13:39:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-with-azure-mfa-setup/m-p/367764#M666</guid>
      <dc:creator>CharlesHanley</dc:creator>
      <dc:date>2020-12-08T13:39:25Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect with Azure MFA setup</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-with-azure-mfa-setup/m-p/373430#M670</link>
      <description>&lt;P&gt;we have global protect deployed with azure mfa authentication. its not fool proof as occasionally the firewall does not even try to send the auth requests out via the specified interface, for that we have to modify our authentication server profile, commit the change, and then magically the firewall starts sending the authentication requests out again. we setup a job with octopus that makes api calls to see if we have a certain number of unique login failures in a specified amount of time to do this programmatically.&lt;BR /&gt;&lt;BR /&gt;that all being said, just setup a new RADIUS server profile and use that as your authentication source for the 3rd party mfa to work.&lt;BR /&gt;&lt;BR /&gt;edit- apparently they have a KB article for this now as well for your step by step: &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClkkCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClkkCAC&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 00:45:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-with-azure-mfa-setup/m-p/373430#M670</guid>
      <dc:creator>JasonMatherly</dc:creator>
      <dc:date>2020-12-10T00:45:54Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect with Azure MFA setup</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-with-azure-mfa-setup/m-p/373506#M673</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/14544"&gt;@JasonMatherly&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I thought about that however As of July 1, 2019, Microsoft no longer offers MFA Server for new deployments.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfaserver-dir-radius" target="_blank" rel="noopener"&gt;https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfaserver-dir-radius&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did talk to one of the local Sales engineers and they recommended the following &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000008U48CAE" target="_blank" rel="noopener noreferrer"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000008U48CAE&lt;/A&gt;&lt;/P&gt;&lt;P&gt;This is a good solution to bring us online and meet the short requirements I have for deployment however because we are in a hybrid Azure it does rely on the Windows Authentication Passthrough servers to be 100% functional. If they go down we cant sign in. fun times. I am still working on the radius part but at least now i have a backup plan to bring us online.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 13:18:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-with-azure-mfa-setup/m-p/373506#M673</guid>
      <dc:creator>CharlesHanley</dc:creator>
      <dc:date>2020-12-10T13:18:38Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect with Azure MFA setup</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-with-azure-mfa-setup/m-p/374427#M697</link>
      <description>&lt;P&gt;In case you are deploying this setup for Linux clients, you might want to consider upgrading to the Global Protect 5.1.6 version.&amp;nbsp;GPC-11090 Fixed an issue where, when the GlobalProtect app was installed on Linux, users were not able to authenticate through SAML authentication when Microsoft Azure was used as the identity provider (ldP).&lt;/P&gt;</description>
      <pubDate>Tue, 15 Dec 2020 04:57:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-with-azure-mfa-setup/m-p/374427#M697</guid>
      <dc:creator>saraya</dc:creator>
      <dc:date>2020-12-15T04:57:30Z</dc:date>
    </item>
  </channel>
</rss>

