<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Allow single user to bypass MFA in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/allow-single-user-to-bypass-mfa/m-p/465048#M102550</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/194770"&gt;@isentric89&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, you can have different authentication methods for different users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Create a new authentication profile without MFA and list only yourself under Advanced &amp;gt; Allow List.&lt;/LI&gt;&lt;LI&gt;Add a new Authentication Sequence, with your new authentication profile on top.&lt;/LI&gt;&lt;LI&gt;Change you authentication profile under both the portal and gateway to the authentication sequence.&lt;/LI&gt;&lt;LI&gt;Since you are the only one in the allow list, the new authentication profile will be used for you.&amp;nbsp; The existing one will be used for everyone else.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;You do not need a new gateway.&amp;nbsp; With regard to access to resources, that is controlled in the security policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit:&amp;nbsp; Thank you &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt; for the feedback!&amp;nbsp; I actually made this same mistake when doing this for a customer months ago, and forgot my lesson learned!&amp;nbsp; I have corrected my steps above.&lt;/P&gt;</description>
    <pubDate>Wed, 16 Feb 2022 16:51:13 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2022-02-16T16:51:13Z</dc:date>
    <item>
      <title>Allow single user to bypass MFA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-single-user-to-bypass-mfa/m-p/465015#M102548</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to access Global Protect for myself using different profile to access one of our resources subnet 10.21.xx.xx.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to access without having to go through 2FA. Any idea for it? is it possible?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do we need to create another gateway on the GP for a single user?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 23:14:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-single-user-to-bypass-mfa/m-p/465015#M102548</guid>
      <dc:creator>isentric89</dc:creator>
      <dc:date>2022-02-10T23:14:43Z</dc:date>
    </item>
    <item>
      <title>Re: Allow single user to bypass MFA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-single-user-to-bypass-mfa/m-p/465048#M102550</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/194770"&gt;@isentric89&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, you can have different authentication methods for different users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Create a new authentication profile without MFA and list only yourself under Advanced &amp;gt; Allow List.&lt;/LI&gt;&lt;LI&gt;Add a new Authentication Sequence, with your new authentication profile on top.&lt;/LI&gt;&lt;LI&gt;Change you authentication profile under both the portal and gateway to the authentication sequence.&lt;/LI&gt;&lt;LI&gt;Since you are the only one in the allow list, the new authentication profile will be used for you.&amp;nbsp; The existing one will be used for everyone else.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;You do not need a new gateway.&amp;nbsp; With regard to access to resources, that is controlled in the security policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit:&amp;nbsp; Thank you &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt; for the feedback!&amp;nbsp; I actually made this same mistake when doing this for a customer months ago, and forgot my lesson learned!&amp;nbsp; I have corrected my steps above.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 16:51:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-single-user-to-bypass-mfa/m-p/465048#M102550</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2022-02-16T16:51:13Z</dc:date>
    </item>
    <item>
      <title>Re: Allow single user to bypass MFA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-single-user-to-bypass-mfa/m-p/466071#M102646</link>
      <description>&lt;P&gt;Hey &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Will the GP falback to the second authentication schema, if the first one reject the the user?&lt;/P&gt;
&lt;P&gt;I have used two authentication schema only for two different types of OS, so I got the impresion that GP will select auth schema based on the OS, top-to-bottom, but it reject the authentication it will not falback to the rest in the list.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was thinking more like using authentication sequence&lt;/P&gt;
&lt;P&gt;- Create auth sequenece and put the authentication profile without MFA first and second the auth profile with MFA&lt;/P&gt;
&lt;P&gt;- Non-MFA profile can be configured with allow list as you suggested&lt;/P&gt;
&lt;P&gt;- Use the Authentication Sequence as authentication schema for GlobalPortect Portal and Gateway authentication.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 07:39:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-single-user-to-bypass-mfa/m-p/466071#M102646</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-02-16T07:39:35Z</dc:date>
    </item>
  </channel>
</rss>

