<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Always on and user MFA in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/always-on-and-user-mfa/m-p/1262207#M7493</link>
    <description>&lt;P&gt;Trying to configure Global Protect on new firewalls and update the MFA&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Current configuration:&lt;BR /&gt;Clients configured w/always connected. Portal is configured w/pre-login device certificates from internal PKI. GW is configured w/LDAP and RADUIS. When a user tunnel is established, user must push yubikey to complete the config.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;New Configuration:&lt;/P&gt;
&lt;P&gt;We are trying to eliminate the 3rd party RADIUS provider but still have the Yubikey functionality.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In addition, I have configured&amp;nbsp; Entra ID SSO and plan to use that going forward. What is the preferred way to enable the Yubikey? Do I need to configure a different RADIUS provider?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Lastly, when I go to the portal web page, I am prompted to need a valid certificate (see above). Will I need to import the local machine certificate into the browser for that to work or can I configure the portal differently?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;TIA&lt;/P&gt;</description>
    <pubDate>Tue, 18 Aug 2026 22:09:28 GMT</pubDate>
    <dc:creator>C.Meisch</dc:creator>
    <dc:date>2026-08-18T22:09:28Z</dc:date>
    <item>
      <title>Always on and user MFA</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/always-on-and-user-mfa/m-p/1262207#M7493</link>
      <description>&lt;P&gt;Trying to configure Global Protect on new firewalls and update the MFA&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Current configuration:&lt;BR /&gt;Clients configured w/always connected. Portal is configured w/pre-login device certificates from internal PKI. GW is configured w/LDAP and RADUIS. When a user tunnel is established, user must push yubikey to complete the config.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;New Configuration:&lt;/P&gt;
&lt;P&gt;We are trying to eliminate the 3rd party RADIUS provider but still have the Yubikey functionality.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In addition, I have configured&amp;nbsp; Entra ID SSO and plan to use that going forward. What is the preferred way to enable the Yubikey? Do I need to configure a different RADIUS provider?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Lastly, when I go to the portal web page, I am prompted to need a valid certificate (see above). Will I need to import the local machine certificate into the browser for that to work or can I configure the portal differently?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;TIA&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2026 22:09:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/always-on-and-user-mfa/m-p/1262207#M7493</guid>
      <dc:creator>C.Meisch</dc:creator>
      <dc:date>2026-08-18T22:09:28Z</dc:date>
    </item>
  </channel>
</rss>

