<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pre-logon than  switch to On-Demand in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/pre-logon-than-switch-to-on-demand/m-p/598564#M862</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/257295"&gt;@Maximt&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have configured prisma access GlobalProtect to authenticate pre-logon with computer certificate and than switch to on-demand.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;pre-logon works as expected and the on-demand authentication with SAML using CIE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was wondering if there is option to configure pre-logon and always-on so when user connects to the station GlobalProtect will automatically start authentication with SAML and connect to the gateway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards,&lt;/P&gt;
&lt;P&gt;Maxim&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/257295"&gt;@Maximt&lt;/a&gt;&amp;nbsp;, I understand you are looking to confirm if there is a way to configure pre-login and always-on&amp;nbsp; when user connects to the workstation so the global protect automatically recognize the user log-on to the workstation with SAML.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, this is possible today. To be able to achieve this, you need to setup two configuration profiles using the app agent.&amp;nbsp;In the first configuration’s&amp;nbsp;&lt;BR /&gt;User/User Group, select the&amp;nbsp;pre-logon&amp;nbsp;filter. With pre-logon, the portal first authenticates the endpoint (not the user) to set up a connection even though the pre-logon parameter is associated with the user. Subsequently, the portal authenticates the user when he or she logs in. After the portal authenticates the user, it deploys the second configuration. In this case,&amp;nbsp;User/User Group&amp;nbsp;is any.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As a best practice, enable SSO in the second configuration so that the correct username is immediately reported to the gateway when the user logs in to the endpoint. If SSO is not enabled, the saved username in the Agent settings panel is used. Check the Step 9 on this documentation for guidance on how to go about it: &lt;A href="https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-quick-configs/remote-access-vpn-with-pre-logon" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-quick-configs/remote-access-vpn-with-pre-logon&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;GlobalProtect pre-logon get connect to the gateway while the system is still booting up or is at the Ctrl+Alt+Del screen, that is, before a user logs in to the machine. Pre-logon will also kick in once a user logs off that machine. Since there is no user associated at these times, the gateway will see this connection coming from a generic username called 'pre-logon'. Once the user logs on to the machine, the tunnel gets renamed (in Windows) from the 'pre-logon' user to the actual 'user' who logged in. In the case of MAC, the tunnel is re-established with the actual user who logged in.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope you find this helpful.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Vickynet&lt;/P&gt;</description>
    <pubDate>Mon, 23 Sep 2024 17:05:06 GMT</pubDate>
    <dc:creator>Vickynet</dc:creator>
    <dc:date>2024-09-23T17:05:06Z</dc:date>
    <item>
      <title>Pre-logon than  switch to On-Demand</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/pre-logon-than-switch-to-on-demand/m-p/598262#M858</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have configured prisma access GlobalProtect to authenticate pre-logon with computer certificate and than switch to on-demand.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;pre-logon works as expected and the on-demand authentication with SAML using CIE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was wondering if there is option to configure pre-logon and always-on so when user connects to the station GlobalProtect will automatically start authentication with SAML and connect to the gateway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards,&lt;/P&gt;
&lt;P&gt;Maxim&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2024 09:58:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/pre-logon-than-switch-to-on-demand/m-p/598262#M858</guid>
      <dc:creator>Maximt</dc:creator>
      <dc:date>2024-09-19T09:58:47Z</dc:date>
    </item>
    <item>
      <title>Re: Pre-logon than  switch to On-Demand</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/pre-logon-than-switch-to-on-demand/m-p/598564#M862</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/257295"&gt;@Maximt&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have configured prisma access GlobalProtect to authenticate pre-logon with computer certificate and than switch to on-demand.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;pre-logon works as expected and the on-demand authentication with SAML using CIE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was wondering if there is option to configure pre-logon and always-on so when user connects to the station GlobalProtect will automatically start authentication with SAML and connect to the gateway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards,&lt;/P&gt;
&lt;P&gt;Maxim&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/257295"&gt;@Maximt&lt;/a&gt;&amp;nbsp;, I understand you are looking to confirm if there is a way to configure pre-login and always-on&amp;nbsp; when user connects to the workstation so the global protect automatically recognize the user log-on to the workstation with SAML.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, this is possible today. To be able to achieve this, you need to setup two configuration profiles using the app agent.&amp;nbsp;In the first configuration’s&amp;nbsp;&lt;BR /&gt;User/User Group, select the&amp;nbsp;pre-logon&amp;nbsp;filter. With pre-logon, the portal first authenticates the endpoint (not the user) to set up a connection even though the pre-logon parameter is associated with the user. Subsequently, the portal authenticates the user when he or she logs in. After the portal authenticates the user, it deploys the second configuration. In this case,&amp;nbsp;User/User Group&amp;nbsp;is any.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As a best practice, enable SSO in the second configuration so that the correct username is immediately reported to the gateway when the user logs in to the endpoint. If SSO is not enabled, the saved username in the Agent settings panel is used. Check the Step 9 on this documentation for guidance on how to go about it: &lt;A href="https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-quick-configs/remote-access-vpn-with-pre-logon" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-quick-configs/remote-access-vpn-with-pre-logon&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;GlobalProtect pre-logon get connect to the gateway while the system is still booting up or is at the Ctrl+Alt+Del screen, that is, before a user logs in to the machine. Pre-logon will also kick in once a user logs off that machine. Since there is no user associated at these times, the gateway will see this connection coming from a generic username called 'pre-logon'. Once the user logs on to the machine, the tunnel gets renamed (in Windows) from the 'pre-logon' user to the actual 'user' who logged in. In the case of MAC, the tunnel is re-established with the actual user who logged in.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope you find this helpful.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Vickynet&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 17:05:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/pre-logon-than-switch-to-on-demand/m-p/598564#M862</guid>
      <dc:creator>Vickynet</dc:creator>
      <dc:date>2024-09-23T17:05:06Z</dc:date>
    </item>
  </channel>
</rss>

