<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global Protect with SAML authentication from Azure on multiple Portals in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-with-saml-authentication-from-azure-on-multiple/m-p/383898#M882</link>
    <description>&lt;P&gt;Hi Everyone!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im not sure if this is more a Global Protect or Pan-OS topic, but here goes:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our setup: I have implemented SAML authentication with our PanOS devices to be used on Global Protect. It works great,&lt;/P&gt;&lt;P&gt;our corporate laptops authenticate with certificate + SAML, but now I want to have the same SAML authentication on another&lt;/P&gt;&lt;P&gt;portal that is intended to be used for BYOD devices. That portal is configured to allow only one type of auth, in this case - SAML.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem: With the default/documentation SAML setup, after authenticating on Azure SSO, the redirect goes to the first portal,&lt;/P&gt;&lt;P&gt;the one meant for corporate laptops, that has certificate + SAML, and obviously that fails for BYOD devices with the missing certificate error. Is there a way to configure it so, that multiple reply URLs can be used? So it redirects to the correct portal?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know Azure SSO supports idp-initiated sso, but how to use it with Pan-OS?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas are appreciated&lt;/P&gt;</description>
    <pubDate>Thu, 04 Feb 2021 16:25:22 GMT</pubDate>
    <dc:creator>mdsgn1</dc:creator>
    <dc:date>2021-02-04T16:25:22Z</dc:date>
    <item>
      <title>Global Protect with SAML authentication from Azure on multiple Portals</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-with-saml-authentication-from-azure-on-multiple/m-p/383898#M882</link>
      <description>&lt;P&gt;Hi Everyone!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im not sure if this is more a Global Protect or Pan-OS topic, but here goes:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our setup: I have implemented SAML authentication with our PanOS devices to be used on Global Protect. It works great,&lt;/P&gt;&lt;P&gt;our corporate laptops authenticate with certificate + SAML, but now I want to have the same SAML authentication on another&lt;/P&gt;&lt;P&gt;portal that is intended to be used for BYOD devices. That portal is configured to allow only one type of auth, in this case - SAML.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem: With the default/documentation SAML setup, after authenticating on Azure SSO, the redirect goes to the first portal,&lt;/P&gt;&lt;P&gt;the one meant for corporate laptops, that has certificate + SAML, and obviously that fails for BYOD devices with the missing certificate error. Is there a way to configure it so, that multiple reply URLs can be used? So it redirects to the correct portal?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know Azure SSO supports idp-initiated sso, but how to use it with Pan-OS?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas are appreciated&lt;/P&gt;</description>
      <pubDate>Thu, 04 Feb 2021 16:25:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-with-saml-authentication-from-azure-on-multiple/m-p/383898#M882</guid>
      <dc:creator>mdsgn1</dc:creator>
      <dc:date>2021-02-04T16:25:22Z</dc:date>
    </item>
  </channel>
</rss>

