<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect Authentication SAML plus certificate (backup mode) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-authentication-saml-plus-certificate-backup-mode/m-p/1226435#M123974</link>
    <description>&lt;P&gt;So if we use SAML (EntraID) for 2FA and we dont have any backup authentication.what would it be if anything in EntraID is down? what is recommended in this case?&lt;/P&gt;</description>
    <pubDate>Mon, 14 Apr 2025 13:42:02 GMT</pubDate>
    <dc:creator>BigPalo</dc:creator>
    <dc:date>2025-04-14T13:42:02Z</dc:date>
    <item>
      <title>GlobalProtect Authentication SAML plus certificate (backup mode)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-authentication-saml-plus-certificate-backup-mode/m-p/1226424#M123968</link>
      <description>&lt;P&gt;I would like to know if it is possible to configure SAML to authenticate and in case something in the SAML part is not working, certificate authentication is used. This is for GP authentication.&lt;/P&gt;
&lt;P&gt;So SAML + certificate auth (backup option).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I understand that i will need a authprofile with SAML auth. But where can i choose the backup auth by certificate?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 11:27:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-authentication-saml-plus-certificate-backup-mode/m-p/1226424#M123968</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2025-04-14T11:27:56Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Authentication SAML plus certificate (backup mode)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-authentication-saml-plus-certificate-backup-mode/m-p/1226428#M123970</link>
      <description>&lt;P&gt;I am not aware of straight forward way to achieve this.&lt;/P&gt;
&lt;P&gt;Only way to have backup auth would be to use auth sequence but you can't use SAML with auth sequence.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With DUO 2FA you could set it as LDAP proxy in between Palo and AD.&lt;/P&gt;
&lt;P&gt;This would allow to use auth sequence and use secondary auth profile if first is not accessible.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 12:43:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-authentication-saml-plus-certificate-backup-mode/m-p/1226428#M123970</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2025-04-14T12:43:30Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Authentication SAML plus certificate (backup mode)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-authentication-saml-plus-certificate-backup-mode/m-p/1226431#M123972</link>
      <description>&lt;P&gt;So Can i create a auth sequence 1) SAML 2) LDAP (just in case SAML fails) ??&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Because if i have only SAML and anything in SAML part goes down, i would have outage. RIght?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 13:04:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-authentication-saml-plus-certificate-backup-mode/m-p/1226431#M123972</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2025-04-14T13:04:14Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Authentication SAML plus certificate (backup mode)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-authentication-saml-plus-certificate-backup-mode/m-p/1226433#M123973</link>
      <description>&lt;P&gt;No SAML and auth sequence are not compatible.&lt;/P&gt;
&lt;P&gt;If you use SAML you can't use auth sequence.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you reconfigure your 2FA to use LDAP instead of SAML then you can accomplish redundancy.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 13:11:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-authentication-saml-plus-certificate-backup-mode/m-p/1226433#M123973</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2025-04-14T13:11:16Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Authentication SAML plus certificate (backup mode)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-authentication-saml-plus-certificate-backup-mode/m-p/1226435#M123974</link>
      <description>&lt;P&gt;So if we use SAML (EntraID) for 2FA and we dont have any backup authentication.what would it be if anything in EntraID is down? what is recommended in this case?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 13:42:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-authentication-saml-plus-certificate-backup-mode/m-p/1226435#M123974</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2025-04-14T13:42:02Z</dc:date>
    </item>
  </channel>
</rss>

