<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SAML - Integration - Globalprotect Azure-AD-EntraID  - Policy Based Groups Azure-AD for GP Zone in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/saml-integration-globalprotect-azure-ad-entraid-policy-based/m-p/1225867#M123899</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179185"&gt;@Metgatz&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Look into the Cloud Identity Engine, it's the answer to this exact problem. &lt;/P&gt;</description>
    <pubDate>Mon, 07 Apr 2025 21:52:25 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2025-04-07T21:52:25Z</dc:date>
    <item>
      <title>SAML - Integration - Globalprotect Azure-AD-EntraID  - Policy Based Groups Azure-AD for GP Zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/saml-integration-globalprotect-azure-ad-entraid-policy-based/m-p/1225735#M123881</link>
      <description>&lt;P&gt;SAML - Integration - Globalprotect Azure-AD-EntraID&amp;nbsp; - Policy Based Groups Azure-AD for GP&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hello Live community, how's it going? I hope it's going well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a question, today we have via GP the integration with Azure-AD Entra ID, via SAML, where everything works correctly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At the level of what is the assignment of groups, we already assigned several groups in the enterprise application, where you read who or who can log in via GP, now the big question.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it feasible to make group based policies, ie:&lt;/P&gt;
&lt;P&gt;GP source zone - destination DMZ01 Azure Source Group: IT01&lt;/P&gt;
&lt;P&gt;I.e. Azure Group-AD&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="relative pointer-events-auto a cursor-pointer
  
  
  
  
  underline
  " href="mailto:IT01@contoso.com" target="_blank" rel="noopener nofollow ugc"&gt;IT01@contoso.com&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;, another with&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="relative pointer-events-auto a cursor-pointer
  
  
  
  
  underline
  " href="mailto:SEC01@contos.com" target="_blank" rel="noopener nofollow ugc"&gt;SEC01@contos.com&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="relative pointer-events-auto a cursor-pointer
  
  
  
  
  underline
  " href="mailto:Infra@contoso.com" target="_blank" rel="noopener nofollow ugc"&gt;Infra@contoso.com&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This to avoid having to make policies, user, by user, to reach and filter the destinations.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this feasible ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;There is no AD-Onprem.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you I remain attentive&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Fri, 04 Apr 2025 16:55:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/saml-integration-globalprotect-azure-ad-entraid-policy-based/m-p/1225735#M123881</guid>
      <dc:creator>Metgatz</dc:creator>
      <dc:date>2025-04-04T16:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: SAML - Integration - Globalprotect Azure-AD-EntraID  - Policy Based Groups Azure-AD for GP Zone</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/saml-integration-globalprotect-azure-ad-entraid-policy-based/m-p/1225867#M123899</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179185"&gt;@Metgatz&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Look into the Cloud Identity Engine, it's the answer to this exact problem. &lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 21:52:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/saml-integration-globalprotect-azure-ad-entraid-policy-based/m-p/1225867#M123899</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2025-04-07T21:52:25Z</dc:date>
    </item>
  </channel>
</rss>

