<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect authentication with Azure SAML question for multiple portals. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-authentication-with-azure-saml-question-for/m-p/575341#M115589</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes you can use the same Azure app and meta data for multiple GlobalProtect portals and gateways as thats what we do. On the Azure app you would need to add the additional urls under the SSO settings.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 01 Feb 2024 14:57:48 GMT</pubDate>
    <dc:creator>Claw4609</dc:creator>
    <dc:date>2024-02-01T14:57:48Z</dc:date>
    <item>
      <title>GlobalProtect authentication with Azure SAML question for multiple portals.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-authentication-with-azure-saml-question-for/m-p/575277#M115573</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;maybe more a question for Azure, will do more research but thought in the meantime id check with the livecommunity also.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so trying to find out if this is possible.. not that familiar with Azure side of things.&lt;/P&gt;
&lt;P&gt;we have 1 Panorama that manages a number of NGFWs all in their own device groups/template stacks etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FW_A has a gp portal called fwaportal.domain.com&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FW_D also has it's own portal called fwdportal.domain.com&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so the Azure team has setup the palo alto globalprotect app and used the fqdn for 'fwaportal.domain.com' and did an export and then import into the FW_A template all good as per the doc below&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000008U48CAE" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000008U48CAE&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;now.. if we want FW_D to also start using saml - how can this be done?&lt;/P&gt;
&lt;P&gt;can we ingest fwdportal.domain.com into the same saml config or should/can we have multiple SAML configs on Azure?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks in adv&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2024 09:53:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-authentication-with-azure-saml-question-for/m-p/575277#M115573</guid>
      <dc:creator>PA_nts</dc:creator>
      <dc:date>2024-02-01T09:53:53Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect authentication with Azure SAML question for multiple portals.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-authentication-with-azure-saml-question-for/m-p/575341#M115589</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes you can use the same Azure app and meta data for multiple GlobalProtect portals and gateways as thats what we do. On the Azure app you would need to add the additional urls under the SSO settings.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2024 14:57:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-authentication-with-azure-saml-question-for/m-p/575341#M115589</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-02-01T14:57:48Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect authentication with Azure SAML question for multiple portals.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-authentication-with-azure-saml-question-for/m-p/575474#M115598</link>
      <description>&lt;P&gt;Thanks Claw..&lt;/P&gt;
&lt;P&gt;one question on the sso settings.. so we can additional portal URLs under the 'identifier' and 'reply URL'. however under the 'Sign On URL', it does not have the option to add additional URLs and is currently set to 'fwaportal.domain.com '&lt;/P&gt;
&lt;P&gt;can it be left as is or will this have any impact for users connecting to the second portal - fwdportal.domain.com&amp;nbsp;&lt;/P&gt;
&lt;P&gt;or do we just leave this as blank?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 07:48:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-authentication-with-azure-saml-question-for/m-p/575474#M115598</guid>
      <dc:creator>PA_nts</dc:creator>
      <dc:date>2024-02-02T07:48:41Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect authentication with Azure SAML question for multiple portals.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-authentication-with-azure-saml-question-for/m-p/575506#M115603</link>
      <description>&lt;P&gt;Yeah you can only add one item under the sign-on url, and you cant leave it blank as its a required field. Gonna be honest not exactly sure what that piece is needed for, it may be if you initiate a connection from Azure to your GP portals webpage. We've brought down our main potal/gateway (the one we have listed in the sign on url) and been able to connect to our other ones via the same SAML Azure app.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 13:28:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-authentication-with-azure-saml-question-for/m-p/575506#M115603</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-02-02T13:28:26Z</dc:date>
    </item>
  </channel>
</rss>

