<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Globalprotect SAML Auth with Azure and MFA not prompting for MFA after reconnect in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-auth-with-azure-and-mfa-not-prompting-for-mfa/m-p/591287#M117744</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What connectivity mode were you using : Always or Pre-Logon&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;was&amp;nbsp;&lt;SPAN&gt;'single sign out' enabled on saml auth profile still required after modifing the Session Sign-in Frequency on the contitional access a requirements to continue prompting for MFA?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 05 Jul 2024 20:01:41 GMT</pubDate>
    <dc:creator>bauernet32</dc:creator>
    <dc:date>2024-07-05T20:01:41Z</dc:date>
    <item>
      <title>Globalprotect SAML Auth with Azure and MFA not prompting for MFA after reconnect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-auth-with-azure-and-mfa-not-prompting-for-mfa/m-p/576241#M115662</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;There are a few topics on this.. I read most of them still unable to resolve this..&lt;/P&gt;
&lt;P&gt;we have panorama with managed FWs (10.2.6) and GP portal and GW setup pointing to SAML profile that integrates into Azure and Azure IdP for MFA&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;at first logon, i was prompted for MFA and connected successfully.&lt;/P&gt;
&lt;P&gt;log off, log back in again and does not prompt for MFA anymore.&lt;/P&gt;
&lt;P&gt;i have 'single sign out' enabled on my saml auth profile.&lt;/P&gt;
&lt;P&gt;in my gateway &amp;gt; agents &amp;gt; connection settings I have 'authentication cookie usage restrictions' disabled.&lt;/P&gt;
&lt;P&gt;I deleted default browser cookies, deleted all gp cookies i can find on my local system.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;however, when I reconnect it connects without asking for MFA.&lt;/P&gt;
&lt;P&gt;any other settings i might need to look at on PA perhaps? or where this specific cookie is kept that is telling MFA i am still valid?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;could this being a setting on Azure in the GP enterprise application? ie conditional access policy etc?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;edit:&amp;nbsp; ok looks like it is by design using PRT (primary refresh tokens) - we are MFA'd, but just not realizing it perhaps &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;found a good article on this below&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/why-are-my-users-not-prompted-for-mfa-as-expected/ba-p/1449032" target="_blank" rel="noopener"&gt;https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/why-are-my-users-not-prompted-for-mfa-as-expected/ba-p/1449032&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;any ideas?&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 12:46:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-auth-with-azure-and-mfa-not-prompting-for-mfa/m-p/576241#M115662</guid>
      <dc:creator>PA_nts</dc:creator>
      <dc:date>2024-02-06T12:46:38Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect SAML Auth with Azure and MFA not prompting for MFA after reconnect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-auth-with-azure-and-mfa-not-prompting-for-mfa/m-p/576244#M115663</link>
      <description>&lt;P&gt;changing conditional access in Azure to require MFA with every authentication should fix the issue (make sure you're not using authentication cookies on the gateway)&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 12:40:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-auth-with-azure-and-mfa-not-prompting-for-mfa/m-p/576244#M115663</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-02-06T12:40:48Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect SAML Auth with Azure and MFA not prompting for MFA after reconnect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-auth-with-azure-and-mfa-not-prompting-for-mfa/m-p/576430#M115689</link>
      <description>&lt;P&gt;Hi Reaper,&lt;/P&gt;
&lt;P&gt;thanks for that.. we did the following with the following results..&lt;/P&gt;
&lt;P&gt;note. auth cookies are disabled on the FWs&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;created a conditional policy for palo alto globalprotect and set the 'Session sign-in frequency' to 1 hour to do MFA&lt;/P&gt;
&lt;P&gt;logged in to gp app and was prompted for MFA.. great. disconnected and reconnected (no MFA second time round) so will wait an hour and see if this prompts for MFA again. hope it does.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;however i fear this might only be for BYOD / third parties and not applicable to Azure AD joined devices ie company laptops.. will test this still later today with client device.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2 more things and might post new discussions on them..&lt;/P&gt;
&lt;P&gt;sometimes i get a 'can't reach this page' error for &lt;A href="https://login.microsftonline.com" target="_blank"&gt;https://login.microsftonline.com&lt;/A&gt; when connecting to gp vpn - then close it, reconnect and it works.. might be bug or something. happens intermittently it seems.&lt;/P&gt;
&lt;P&gt;the other thing. i suspect because i have saml auth profile applied to both portal and gateway, i get prompted to select my azure account twice. will investigate on this still.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;anyways.. will keep this post updated with findings.&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2024 10:22:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-auth-with-azure-and-mfa-not-prompting-for-mfa/m-p/576430#M115689</guid>
      <dc:creator>PA_nts</dc:creator>
      <dc:date>2024-02-07T10:22:27Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect SAML Auth with Azure and MFA not prompting for MFA after reconnect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-auth-with-azure-and-mfa-not-prompting-for-mfa/m-p/576436#M115690</link>
      <description>&lt;P&gt;on the 2x authentication: this can be an expected behavior as you're also authenticating twice (portal and gw are different entities)&lt;/P&gt;
&lt;P&gt;this can be bridged by setting the portal to accept cookies for example, so that you can always use cookies to auth against the portal to retrieve configuration etc, but need to auth against the gateways&lt;/P&gt;
&lt;P&gt;the reverse is also possible&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;for the microsoftonline url, you could try creating split tunnel config to ensure authentication always happens outside of the tunnel regardless of what your connection state is&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2024 11:18:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-auth-with-azure-and-mfa-not-prompting-for-mfa/m-p/576436#M115690</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-02-07T11:18:55Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect SAML Auth with Azure and MFA not prompting for MFA after reconnect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-auth-with-azure-and-mfa-not-prompting-for-mfa/m-p/576763#M115757</link>
      <description>&lt;P&gt;thanks..&lt;/P&gt;
&lt;P&gt;so i have configured the portal to generate cookies and for the gateway to accept cookies.. this seems to work and resolve the dual auth issue.&lt;/P&gt;
&lt;P&gt;randomly still getting the 'can't find this page' error upon first connection.. when you close it and reconnect, it then goes through as expected. it's also intermittent, sometimes goes in first time round.. other times get the error, close the window, reconnect then it works.&lt;/P&gt;
&lt;P&gt;will log a tac also as not finding many docs on this issue on pan site atm.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;edit: in portal/agent/name/app - ipv6 preferred was set to yes.. changed to no.&lt;/P&gt;
&lt;P&gt;also changed 'use default browser for saml authentication' from no to yes&lt;/P&gt;
&lt;P&gt;seems to be working sofar.. will get users to test and confirm it finally resolved.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2024 08:42:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-auth-with-azure-and-mfa-not-prompting-for-mfa/m-p/576763#M115757</guid>
      <dc:creator>PA_nts</dc:creator>
      <dc:date>2024-02-09T08:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect SAML Auth with Azure and MFA not prompting for MFA after reconnect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-auth-with-azure-and-mfa-not-prompting-for-mfa/m-p/591287#M117744</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What connectivity mode were you using : Always or Pre-Logon&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;was&amp;nbsp;&lt;SPAN&gt;'single sign out' enabled on saml auth profile still required after modifing the Session Sign-in Frequency on the contitional access a requirements to continue prompting for MFA?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2024 20:01:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-auth-with-azure-and-mfa-not-prompting-for-mfa/m-p/591287#M117744</guid>
      <dc:creator>bauernet32</dc:creator>
      <dc:date>2024-07-05T20:01:41Z</dc:date>
    </item>
  </channel>
</rss>

