<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article 如何使用GlobalProtect设置Azure SAML认证 in 配置和实施</title>
    <link>https://live.paloaltonetworks.com/t5/%E9%85%8D%E7%BD%AE%E5%92%8C%E5%AE%9E%E6%96%BD/%E5%A6%82%E4%BD%95%E4%BD%BF%E7%94%A8globalprotect%E8%AE%BE%E7%BD%AEazure-saml%E8%AE%A4%E8%AF%81/ta-p/531019</link>
    <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;H2 id="toc-hId-1732525362"&gt;&lt;FONT color="#FF6600"&gt;目标&lt;/FONT&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN&gt;逐步说明如何为&lt;/SPAN&gt;&lt;SPAN&gt;GlobalProtect&lt;/SPAN&gt;&lt;SPAN&gt;门户和网关设置&lt;/SPAN&gt;&lt;SPAN&gt;Azure SAML&lt;/SPAN&gt;&lt;SPAN&gt;认证。&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2 id="toc-hId--819631623"&gt;&lt;FONT color="#FF6600"&gt;环境&lt;/FONT&gt;&lt;/H2&gt;
&lt;P style="margin: 0in; font-size: 11.0pt;" lang="zh-CN"&gt;&lt;SPAN&gt;使用&lt;/SPAN&gt;&lt;SPAN&gt;Azure SAML&lt;/SPAN&gt;&lt;SPAN&gt;的&lt;/SPAN&gt;&lt;SPAN&gt;GlobalProtect&lt;/SPAN&gt;&lt;SPAN&gt;认证&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="lia-message-template-symptoms-zone"&gt;
&lt;H2 id="toc-hId-1732525338"&gt;&lt;FONT color="#FF6600"&gt;&lt;SPAN&gt;步骤&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/H2&gt;
&lt;P style="margin: 0in; font-size: 11.0pt;" lang="zh-CN"&gt;&lt;SPAN&gt;第&lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;步. 登录&lt;/SPAN&gt;&lt;A title="Azure门户" href="https://login.microsoftonline.com/organizations/oauth2/v2.0/authorize?redirect_uri=https%3A%2F%2Fportal.azure.com%2Fsignin%2Findex%2F&amp;amp;response_type=code%20id_token&amp;amp;scope=https%3A%2F%2Fmanagement.core.windows.net%2F%2Fuser_impersonation%20openid%20email%20profile&amp;amp;state=OpenIdConnect.AuthenticationProperties%3DF3x9Fz6EfMaukFugOm5eQhoeKcSjUSkYaBg1tXlOtWXa15fL_y_N-1g2_7xzd9vHooKG1bT2uK8NKE6lJidBwa52uD7WTh_YFXVHwIadQNILHYFl1-ih6jaIgyz63pV39UAPb4YzRVZ5dfLdOjQEJ1XSJ9s4ZyL3B4xQ-bov24K9NagckYPzADKqApiPFsdR_I7fIAVtp8LTk_VfglxxoFHfAY6YWbNzaLjkqb-WdTi5NhYBjkgQZ9H-R6eqpWIQh4LHeNC603lVvIGWoNJqmFE9v24ZeJyZ8pBJ3cUs5BMxXjp6xqldOrXrJwEbJZ2xdAzyq3iijoODmpLdiSwsiY6YUVL2W-qGITd9cpNomNNKxyO1nzro26SF4Isyq_aA2QqUsg-dxE0ne-zdVuy_OmUKZzjG9bJ20QMnmO5he0seG1OQoVXjJS8pHaHZZML_e_LlWYmrFAF6bwGL519pdFOZPIuBB7Oaaxz1IHKHe3Q&amp;amp;response_mode=form_post&amp;amp;nonce=638119538586570728.MTU2OTQ1YjUtYTE3Zi00N2QzLWFiNDgtZWU5NDEwYTI4Yjc2ZjNkYzRlNGEtOTExMi00MTg2LTllMWQtNWNiN2NjM2NjZjQz&amp;amp;client_id=c44b4083-3bb0-49c1-b47d-974e53cbdf3c&amp;amp;site_id=501430&amp;amp;client-request-id=0ff31631-fecf-4e77-8f8d-dfdf7363ec00&amp;amp;x-client-SKU=ID_NET472&amp;amp;x-client-ver=6.22.1.0&amp;amp;sso_reload=true" target="_self"&gt;&lt;SPAN&gt;Azure&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&lt;A title="Azure门户" href="https://login.microsoftonline.com/organizations/oauth2/v2.0/authorize?redirect_uri=https%3A%2F%2Fportal.azure.com%2Fsignin%2Findex%2F&amp;amp;response_type=code%20id_token&amp;amp;scope=https%3A%2F%2Fmanagement.core.windows.net%2F%2Fuser_impersonation%20openid%20email%20profile&amp;amp;state=OpenIdConnect.AuthenticationProperties%3DF3x9Fz6EfMaukFugOm5eQhoeKcSjUSkYaBg1tXlOtWXa15fL_y_N-1g2_7xzd9vHooKG1bT2uK8NKE6lJidBwa52uD7WTh_YFXVHwIadQNILHYFl1-ih6jaIgyz63pV39UAPb4YzRVZ5dfLdOjQEJ1XSJ9s4ZyL3B4xQ-bov24K9NagckYPzADKqApiPFsdR_I7fIAVtp8LTk_VfglxxoFHfAY6YWbNzaLjkqb-WdTi5NhYBjkgQZ9H-R6eqpWIQh4LHeNC603lVvIGWoNJqmFE9v24ZeJyZ8pBJ3cUs5BMxXjp6xqldOrXrJwEbJZ2xdAzyq3iijoODmpLdiSwsiY6YUVL2W-qGITd9cpNomNNKxyO1nzro26SF4Isyq_aA2QqUsg-dxE0ne-zdVuy_OmUKZzjG9bJ20QMnmO5he0seG1OQoVXjJS8pHaHZZML_e_LlWYmrFAF6bwGL519pdFOZPIuBB7Oaaxz1IHKHe3Q&amp;amp;response_mode=form_post&amp;amp;nonce=638119538586570728.MTU2OTQ1YjUtYTE3Zi00N2QzLWFiNDgtZWU5NDEwYTI4Yjc2ZjNkYzRlNGEtOTExMi00MTg2LTllMWQtNWNiN2NjM2NjZjQz&amp;amp;client_id=c44b4083-3bb0-49c1-b47d-974e53cbdf3c&amp;amp;site_id=501430&amp;amp;client-request-id=0ff31631-fecf-4e77-8f8d-dfdf7363ec00&amp;amp;x-client-SKU=ID_NET472&amp;amp;x-client-ver=6.22.1.0&amp;amp;sso_reload=true" target="_self"&gt;门户&lt;/A&gt;，在所有服务下浏览企业应用程序&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 942px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47890iECE474241483EA06/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;"&gt;&lt;SPAN&gt;第2步. &lt;/SPAN&gt;&lt;SPAN&gt;搜索Palo Alto并选择Palo Alto Global Protect&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 691px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47893i8DAB946AB9345072/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;"&gt;&lt;SPAN&gt;第3步&lt;/SPAN&gt;&lt;SPAN&gt;. &lt;/SPAN&gt;&lt;SPAN&gt;点击 "添加"来添加应用程序。&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.png" style="width: 334px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47895i5AA5998D85719C00/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-size: 11.0pt;"&gt;&lt;SPAN&gt;第&lt;/SPAN&gt;&lt;SPAN&gt;4&lt;/SPAN&gt;&lt;SPAN&gt;步&lt;/SPAN&gt;&lt;SPAN&gt;. &lt;/SPAN&gt;&lt;SPAN&gt;在应用程序成功添加后&amp;gt;点击单点登录&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="4.png" style="width: 282px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47896iB2A6EFEB9CC8C8CF/image-size/large?v=v2&amp;amp;px=999" role="button" title="4.png" alt="4.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;"&gt;&lt;SPAN&gt;第5步&lt;/SPAN&gt;&lt;SPAN&gt;. &lt;/SPAN&gt;&lt;SPAN&gt;选择SAML选项。&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="5.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47897i42DE783EDCE7D1D7/image-size/large?v=v2&amp;amp;px=999" role="button" title="5.png" alt="5.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;"&gt;&lt;SPAN&gt;第6步&lt;/SPAN&gt;&lt;SPAN&gt;. &lt;/SPAN&gt;&lt;SPAN&gt;通过点击编辑按钮编辑基本SAML配置&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="6.png" style="width: 860px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47898iED646F1FAD3C082C/image-size/large?v=v2&amp;amp;px=999" role="button" title="6.png" alt="6.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;SPAN&gt;第7步&lt;/SPAN&gt;&lt;SPAN&gt;. &lt;/SPAN&gt;&lt;SPAN&gt;填写登录URL、标识符（实体ID）和回复URL（主张消费者服务URL），如下所示&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&amp;nbsp; &amp;nbsp; GlobalProtect门户的FQDN/IP地址可以通过登录防火墙，在网络&amp;gt;门户&amp;gt;选择门户&amp;gt;代理&amp;gt;选择配置&amp;gt;外部&amp;gt;选择外部网关&amp;gt;使用FQDN或IP地址ip来定位。&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 登录的URL。&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;A href="https://FQDN" target="_blank"&gt;https://FQDN&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;A href="https://IP-address" target="_blank"&gt;https://IP-address&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; 识别码（实体ID）&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="https://FQDN:443/SAML20/SP" target="_blank"&gt;https://FQDN:443/SAML20/SP&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="https://IP-address:443/SAML20/SP" target="_blank"&gt;https://IP-address:443/SAML20/SP&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 回复URL（主张消费者服务URL）。&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="https://FQDN:443/SAML20/SP/ACS" target="_blank"&gt;https://FQDN:443/SAML20/SP/ACS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="https://IP-address:443/SAML20/SP/ACS" target="_blank"&gt;https://IP-address:443/SAML20/SP/ACS&lt;/A&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&amp;nbsp;例如：&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="7.png" style="width: 815px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47899i83AA89C0E550D48A/image-size/large?v=v2&amp;amp;px=999" role="button" title="7.png" alt="7.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&amp;nbsp;或者IP地址：&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="8.png" style="width: 772px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47900iF0DAF7940814D3E8/image-size/large?v=v2&amp;amp;px=999" role="button" title="8.png" alt="8.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&amp;nbsp;第8步. 下载联邦元数据XML并保存在你的电脑上（这将被导入到防火墙中）&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="9.jfif" style="width: 871px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47901i6DF730680721B2F4/image-size/large?v=v2&amp;amp;px=999" role="button" title="9.jfif" alt="9.jfif" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 这样就完成了在Azure上的配置。登录到防火墙并添加SAML身份提供者&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&lt;U&gt;&amp;nbsp;配置SAML认证的步骤，以便将其用于GlobalProtect 门户和网关。&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 按照这篇文章配置&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFbCAK" target="_self"&gt;GlobalProtect 门户/网关&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;SAML配置步骤：&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-size: 11.0pt;" lang="zh-CN"&gt;&lt;SPAN&gt;第&lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;步. 登录到防火墙并导航到设备&amp;gt;SAML身份提供者&amp;gt;导入&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-size: 11.0pt;" lang="zh-CN"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-size: 11.0pt;" lang="zh-CN"&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="11.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47902i88FB292F9C387AAC/image-size/large?v=v2&amp;amp;px=999" role="button" title="11.png" alt="11.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;第2步. 导入步骤8中从Azure下载的联邦元数据XML。&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="22.png" style="width: 657px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47903i3C35C7A812B4A20B/image-size/large?v=v2&amp;amp;px=999" role="button" title="22.png" alt="22.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;选项：取消勾选验证身份提供者证书。如果勾选，来自Azure的证书也需要上传到防火墙上。&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;第3步. 创建认证配置文件并选择SAML和IDP服务器配置文件&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="33.png" style="width: 622px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47904i527B4F46E767513D/image-size/large?v=v2&amp;amp;px=999" role="button" title="33.png" alt="33.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-size: 11.0pt;"&gt;&lt;SPAN&gt;第&lt;/SPAN&gt;&lt;SPAN&gt;4&lt;/SPAN&gt;&lt;SPAN&gt;步. 点击 "高级 "标签，选择 "允许列表"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="44.png" style="width: 618px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47905i77C81506C48147FF/image-size/large?v=v2&amp;amp;px=999" role="button" title="44.png" alt="44.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;第5步. 在GlobalProtect门户网站上添加认证资料&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="55.png" style="width: 808px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47906i400AC49338DA74D2/image-size/large?v=v2&amp;amp;px=999" role="button" title="55.png" alt="55.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-size: 11.0pt;" lang="zh-CN"&gt;&lt;SPAN&gt;第&lt;/SPAN&gt;&lt;SPAN&gt;6&lt;/SPAN&gt;&lt;SPAN&gt;步. 在&lt;/SPAN&gt;&lt;SPAN&gt;GlobalProtect&lt;/SPAN&gt;&lt;SPAN&gt;网关配置中添加认证配置文件。&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-size: 11.0pt;" lang="zh-CN"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="66.png" style="width: 858px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47907i0E32DA5F60981D61/image-size/large?v=v2&amp;amp;px=999" role="button" title="66.png" alt="66.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;配置部分到此结束。&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
    <pubDate>Tue, 14 Feb 2023 06:46:15 GMT</pubDate>
    <dc:creator>zji</dc:creator>
    <dc:date>2023-02-14T06:46:15Z</dc:date>
    <item>
      <title>如何使用GlobalProtect设置Azure SAML认证</title>
      <link>https://live.paloaltonetworks.com/t5/%E9%85%8D%E7%BD%AE%E5%92%8C%E5%AE%9E%E6%96%BD/%E5%A6%82%E4%BD%95%E4%BD%BF%E7%94%A8globalprotect%E8%AE%BE%E7%BD%AEazure-saml%E8%AE%A4%E8%AF%81/ta-p/531019</link>
      <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;H2 id="toc-hId-1732525362"&gt;&lt;FONT color="#FF6600"&gt;目标&lt;/FONT&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN&gt;逐步说明如何为&lt;/SPAN&gt;&lt;SPAN&gt;GlobalProtect&lt;/SPAN&gt;&lt;SPAN&gt;门户和网关设置&lt;/SPAN&gt;&lt;SPAN&gt;Azure SAML&lt;/SPAN&gt;&lt;SPAN&gt;认证。&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2 id="toc-hId--819631623"&gt;&lt;FONT color="#FF6600"&gt;环境&lt;/FONT&gt;&lt;/H2&gt;
&lt;P style="margin: 0in; font-size: 11.0pt;" lang="zh-CN"&gt;&lt;SPAN&gt;使用&lt;/SPAN&gt;&lt;SPAN&gt;Azure SAML&lt;/SPAN&gt;&lt;SPAN&gt;的&lt;/SPAN&gt;&lt;SPAN&gt;GlobalProtect&lt;/SPAN&gt;&lt;SPAN&gt;认证&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="lia-message-template-symptoms-zone"&gt;
&lt;H2 id="toc-hId-1732525338"&gt;&lt;FONT color="#FF6600"&gt;&lt;SPAN&gt;步骤&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/H2&gt;
&lt;P style="margin: 0in; font-size: 11.0pt;" lang="zh-CN"&gt;&lt;SPAN&gt;第&lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;步. 登录&lt;/SPAN&gt;&lt;A title="Azure门户" href="https://login.microsoftonline.com/organizations/oauth2/v2.0/authorize?redirect_uri=https%3A%2F%2Fportal.azure.com%2Fsignin%2Findex%2F&amp;amp;response_type=code%20id_token&amp;amp;scope=https%3A%2F%2Fmanagement.core.windows.net%2F%2Fuser_impersonation%20openid%20email%20profile&amp;amp;state=OpenIdConnect.AuthenticationProperties%3DF3x9Fz6EfMaukFugOm5eQhoeKcSjUSkYaBg1tXlOtWXa15fL_y_N-1g2_7xzd9vHooKG1bT2uK8NKE6lJidBwa52uD7WTh_YFXVHwIadQNILHYFl1-ih6jaIgyz63pV39UAPb4YzRVZ5dfLdOjQEJ1XSJ9s4ZyL3B4xQ-bov24K9NagckYPzADKqApiPFsdR_I7fIAVtp8LTk_VfglxxoFHfAY6YWbNzaLjkqb-WdTi5NhYBjkgQZ9H-R6eqpWIQh4LHeNC603lVvIGWoNJqmFE9v24ZeJyZ8pBJ3cUs5BMxXjp6xqldOrXrJwEbJZ2xdAzyq3iijoODmpLdiSwsiY6YUVL2W-qGITd9cpNomNNKxyO1nzro26SF4Isyq_aA2QqUsg-dxE0ne-zdVuy_OmUKZzjG9bJ20QMnmO5he0seG1OQoVXjJS8pHaHZZML_e_LlWYmrFAF6bwGL519pdFOZPIuBB7Oaaxz1IHKHe3Q&amp;amp;response_mode=form_post&amp;amp;nonce=638119538586570728.MTU2OTQ1YjUtYTE3Zi00N2QzLWFiNDgtZWU5NDEwYTI4Yjc2ZjNkYzRlNGEtOTExMi00MTg2LTllMWQtNWNiN2NjM2NjZjQz&amp;amp;client_id=c44b4083-3bb0-49c1-b47d-974e53cbdf3c&amp;amp;site_id=501430&amp;amp;client-request-id=0ff31631-fecf-4e77-8f8d-dfdf7363ec00&amp;amp;x-client-SKU=ID_NET472&amp;amp;x-client-ver=6.22.1.0&amp;amp;sso_reload=true" target="_self"&gt;&lt;SPAN&gt;Azure&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&lt;A title="Azure门户" href="https://login.microsoftonline.com/organizations/oauth2/v2.0/authorize?redirect_uri=https%3A%2F%2Fportal.azure.com%2Fsignin%2Findex%2F&amp;amp;response_type=code%20id_token&amp;amp;scope=https%3A%2F%2Fmanagement.core.windows.net%2F%2Fuser_impersonation%20openid%20email%20profile&amp;amp;state=OpenIdConnect.AuthenticationProperties%3DF3x9Fz6EfMaukFugOm5eQhoeKcSjUSkYaBg1tXlOtWXa15fL_y_N-1g2_7xzd9vHooKG1bT2uK8NKE6lJidBwa52uD7WTh_YFXVHwIadQNILHYFl1-ih6jaIgyz63pV39UAPb4YzRVZ5dfLdOjQEJ1XSJ9s4ZyL3B4xQ-bov24K9NagckYPzADKqApiPFsdR_I7fIAVtp8LTk_VfglxxoFHfAY6YWbNzaLjkqb-WdTi5NhYBjkgQZ9H-R6eqpWIQh4LHeNC603lVvIGWoNJqmFE9v24ZeJyZ8pBJ3cUs5BMxXjp6xqldOrXrJwEbJZ2xdAzyq3iijoODmpLdiSwsiY6YUVL2W-qGITd9cpNomNNKxyO1nzro26SF4Isyq_aA2QqUsg-dxE0ne-zdVuy_OmUKZzjG9bJ20QMnmO5he0seG1OQoVXjJS8pHaHZZML_e_LlWYmrFAF6bwGL519pdFOZPIuBB7Oaaxz1IHKHe3Q&amp;amp;response_mode=form_post&amp;amp;nonce=638119538586570728.MTU2OTQ1YjUtYTE3Zi00N2QzLWFiNDgtZWU5NDEwYTI4Yjc2ZjNkYzRlNGEtOTExMi00MTg2LTllMWQtNWNiN2NjM2NjZjQz&amp;amp;client_id=c44b4083-3bb0-49c1-b47d-974e53cbdf3c&amp;amp;site_id=501430&amp;amp;client-request-id=0ff31631-fecf-4e77-8f8d-dfdf7363ec00&amp;amp;x-client-SKU=ID_NET472&amp;amp;x-client-ver=6.22.1.0&amp;amp;sso_reload=true" target="_self"&gt;门户&lt;/A&gt;，在所有服务下浏览企业应用程序&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 942px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47890iECE474241483EA06/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;"&gt;&lt;SPAN&gt;第2步. &lt;/SPAN&gt;&lt;SPAN&gt;搜索Palo Alto并选择Palo Alto Global Protect&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 691px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47893i8DAB946AB9345072/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;"&gt;&lt;SPAN&gt;第3步&lt;/SPAN&gt;&lt;SPAN&gt;. &lt;/SPAN&gt;&lt;SPAN&gt;点击 "添加"来添加应用程序。&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.png" style="width: 334px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47895i5AA5998D85719C00/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-size: 11.0pt;"&gt;&lt;SPAN&gt;第&lt;/SPAN&gt;&lt;SPAN&gt;4&lt;/SPAN&gt;&lt;SPAN&gt;步&lt;/SPAN&gt;&lt;SPAN&gt;. &lt;/SPAN&gt;&lt;SPAN&gt;在应用程序成功添加后&amp;gt;点击单点登录&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="4.png" style="width: 282px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47896iB2A6EFEB9CC8C8CF/image-size/large?v=v2&amp;amp;px=999" role="button" title="4.png" alt="4.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;"&gt;&lt;SPAN&gt;第5步&lt;/SPAN&gt;&lt;SPAN&gt;. &lt;/SPAN&gt;&lt;SPAN&gt;选择SAML选项。&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="5.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47897i42DE783EDCE7D1D7/image-size/large?v=v2&amp;amp;px=999" role="button" title="5.png" alt="5.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;"&gt;&lt;SPAN&gt;第6步&lt;/SPAN&gt;&lt;SPAN&gt;. &lt;/SPAN&gt;&lt;SPAN&gt;通过点击编辑按钮编辑基本SAML配置&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="6.png" style="width: 860px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47898iED646F1FAD3C082C/image-size/large?v=v2&amp;amp;px=999" role="button" title="6.png" alt="6.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;SPAN&gt;第7步&lt;/SPAN&gt;&lt;SPAN&gt;. &lt;/SPAN&gt;&lt;SPAN&gt;填写登录URL、标识符（实体ID）和回复URL（主张消费者服务URL），如下所示&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&amp;nbsp; &amp;nbsp; GlobalProtect门户的FQDN/IP地址可以通过登录防火墙，在网络&amp;gt;门户&amp;gt;选择门户&amp;gt;代理&amp;gt;选择配置&amp;gt;外部&amp;gt;选择外部网关&amp;gt;使用FQDN或IP地址ip来定位。&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 登录的URL。&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;A href="https://FQDN" target="_blank"&gt;https://FQDN&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;A href="https://IP-address" target="_blank"&gt;https://IP-address&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; 识别码（实体ID）&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="https://FQDN:443/SAML20/SP" target="_blank"&gt;https://FQDN:443/SAML20/SP&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="https://IP-address:443/SAML20/SP" target="_blank"&gt;https://IP-address:443/SAML20/SP&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 回复URL（主张消费者服务URL）。&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="https://FQDN:443/SAML20/SP/ACS" target="_blank"&gt;https://FQDN:443/SAML20/SP/ACS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="https://IP-address:443/SAML20/SP/ACS" target="_blank"&gt;https://IP-address:443/SAML20/SP/ACS&lt;/A&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&amp;nbsp;例如：&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="7.png" style="width: 815px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47899i83AA89C0E550D48A/image-size/large?v=v2&amp;amp;px=999" role="button" title="7.png" alt="7.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&amp;nbsp;或者IP地址：&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="8.png" style="width: 772px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47900iF0DAF7940814D3E8/image-size/large?v=v2&amp;amp;px=999" role="button" title="8.png" alt="8.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&amp;nbsp;第8步. 下载联邦元数据XML并保存在你的电脑上（这将被导入到防火墙中）&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="9.jfif" style="width: 871px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47901i6DF730680721B2F4/image-size/large?v=v2&amp;amp;px=999" role="button" title="9.jfif" alt="9.jfif" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 这样就完成了在Azure上的配置。登录到防火墙并添加SAML身份提供者&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&lt;U&gt;&amp;nbsp;配置SAML认证的步骤，以便将其用于GlobalProtect 门户和网关。&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 按照这篇文章配置&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFbCAK" target="_self"&gt;GlobalProtect 门户/网关&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;SAML配置步骤：&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-size: 11.0pt;" lang="zh-CN"&gt;&lt;SPAN&gt;第&lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;步. 登录到防火墙并导航到设备&amp;gt;SAML身份提供者&amp;gt;导入&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-size: 11.0pt;" lang="zh-CN"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-size: 11.0pt;" lang="zh-CN"&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="11.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47902i88FB292F9C387AAC/image-size/large?v=v2&amp;amp;px=999" role="button" title="11.png" alt="11.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;第2步. 导入步骤8中从Azure下载的联邦元数据XML。&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="22.png" style="width: 657px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47903i3C35C7A812B4A20B/image-size/large?v=v2&amp;amp;px=999" role="button" title="22.png" alt="22.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;选项：取消勾选验证身份提供者证书。如果勾选，来自Azure的证书也需要上传到防火墙上。&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;第3步. 创建认证配置文件并选择SAML和IDP服务器配置文件&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="33.png" style="width: 622px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47904i527B4F46E767513D/image-size/large?v=v2&amp;amp;px=999" role="button" title="33.png" alt="33.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-size: 11.0pt;"&gt;&lt;SPAN&gt;第&lt;/SPAN&gt;&lt;SPAN&gt;4&lt;/SPAN&gt;&lt;SPAN&gt;步. 点击 "高级 "标签，选择 "允许列表"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="44.png" style="width: 618px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47905i77C81506C48147FF/image-size/large?v=v2&amp;amp;px=999" role="button" title="44.png" alt="44.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;第5步. 在GlobalProtect门户网站上添加认证资料&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="55.png" style="width: 808px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47906i400AC49338DA74D2/image-size/large?v=v2&amp;amp;px=999" role="button" title="55.png" alt="55.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-size: 11.0pt;" lang="zh-CN"&gt;&lt;SPAN&gt;第&lt;/SPAN&gt;&lt;SPAN&gt;6&lt;/SPAN&gt;&lt;SPAN&gt;步. 在&lt;/SPAN&gt;&lt;SPAN&gt;GlobalProtect&lt;/SPAN&gt;&lt;SPAN&gt;网关配置中添加认证配置文件。&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-size: 11.0pt;" lang="zh-CN"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="66.png" style="width: 858px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47907i0E32DA5F60981D61/image-size/large?v=v2&amp;amp;px=999" role="button" title="66.png" alt="66.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Microsoft YaHei'; font-size: 11.0pt;" lang="zh-CN"&gt;配置部分到此结束。&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 14 Feb 2023 06:46:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/%E9%85%8D%E7%BD%AE%E5%92%8C%E5%AE%9E%E6%96%BD/%E5%A6%82%E4%BD%95%E4%BD%BF%E7%94%A8globalprotect%E8%AE%BE%E7%BD%AEazure-saml%E8%AE%A4%E8%AF%81/ta-p/531019</guid>
      <dc:creator>zji</dc:creator>
      <dc:date>2023-02-14T06:46:15Z</dc:date>
    </item>
  </channel>
</rss>

