<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to sign into GP client with Azure AD SSO in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-sign-into-gp-client-with-azure-ad-sso/m-p/452005#M101208</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/181759"&gt;@Ben-Price&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;From what you've posted, this isn't really a firewall issue. Something within your SSO configuration on the Microsoft side of things isn't configured/working properly. Off hand, the first thing that I would ask is just verifying that you aren't trying to use a nested group. Outside of that I would just open a support case with Microsoft since the error is on that side of things.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 08 Dec 2021 01:14:44 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2021-12-08T01:14:44Z</dc:date>
    <item>
      <title>Unable to sign into GP client with Azure AD SSO</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-sign-into-gp-client-with-azure-ad-sso/m-p/451160#M101121</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Trying to setup Azure AD SSO with Global Protect, but am receiving the below error. According, to the Microsoft documentation it means that the user is not assigned to the application in Azure, but I can confirm that the user is assigned correctly to the application. Is there anything else I can check?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BenPrice_1-1638510522152.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37924i6BE2D312E409A83D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="BenPrice_1-1638510522152.png" alt="BenPrice_1-1638510522152.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BenPrice_2-1638510770774.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37925i2B4D43A50DDDC130/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="BenPrice_2-1638510770774.png" alt="BenPrice_2-1638510770774.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Dec 2021 05:53:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-sign-into-gp-client-with-azure-ad-sso/m-p/451160#M101121</guid>
      <dc:creator>Ben-Price</dc:creator>
      <dc:date>2021-12-03T05:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to sign into GP client with Azure AD SSO</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-sign-into-gp-client-with-azure-ad-sso/m-p/451964#M101202</link>
      <description>&lt;P&gt;Message from the authd.log&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2021-11-30 13:19:35.231 +1100 debug: _log_saml_respone(pan_auth_server.c:348): Sent PAN_AUTH_FAILURE SAML response:(authd_id: 6998778942614154583) (SAML err code "2" means SSO failed) (return username 'Test.User@company.com') (auth profile 'Azure-AD-SAML') (reply msg 'SAML single-sign-on failed') (NameID 'Test.User@company.com') (SessionIndex '_a4abc986-aa3c-4717-923c-39a4e7717d00') (Single Logout enabled? 'No')&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 23:07:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-sign-into-gp-client-with-azure-ad-sso/m-p/451964#M101202</guid>
      <dc:creator>Ben-Price</dc:creator>
      <dc:date>2021-12-07T23:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to sign into GP client with Azure AD SSO</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-sign-into-gp-client-with-azure-ad-sso/m-p/451965#M101203</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;Any ideas here?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 23:08:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-sign-into-gp-client-with-azure-ad-sso/m-p/451965#M101203</guid>
      <dc:creator>Ben-Price</dc:creator>
      <dc:date>2021-12-07T23:08:48Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to sign into GP client with Azure AD SSO</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-sign-into-gp-client-with-azure-ad-sso/m-p/452005#M101208</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/181759"&gt;@Ben-Price&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;From what you've posted, this isn't really a firewall issue. Something within your SSO configuration on the Microsoft side of things isn't configured/working properly. Off hand, the first thing that I would ask is just verifying that you aren't trying to use a nested group. Outside of that I would just open a support case with Microsoft since the error is on that side of things.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Dec 2021 01:14:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-sign-into-gp-client-with-azure-ad-sso/m-p/452005#M101208</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-12-08T01:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to sign into GP client with Azure AD SSO</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-sign-into-gp-client-with-azure-ad-sso/m-p/452018#M101214</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;Thanks for the feedback. They have tested with a user in a group and a user directly assigned to the app. I have asked them to check Microsoft.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Dec 2021 03:45:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-sign-into-gp-client-with-azure-ad-sso/m-p/452018#M101214</guid>
      <dc:creator>Ben-Price</dc:creator>
      <dc:date>2021-12-08T03:45:08Z</dc:date>
    </item>
  </channel>
</rss>

