<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GP with saml authentication always redirects to idp in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/gp-with-saml-authentication-always-redirects-to-idp/m-p/1253353#M126360</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/24977"&gt;@Carracido&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, I have seen that behavior.&amp;nbsp; Although there are many documents which say that Authentication Override is an effective way to stop double &lt;U&gt;SAML&lt;/U&gt; authentication prompts for the portal and the gateway, I have rarely seen it work.&amp;nbsp; I no longer configure&amp;nbsp;Authentication Override with SAML, ... AND I don't need to.&amp;nbsp; As in your case, I can configure the IdP to achieve the same result.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The reason, I believe, why it doesn't work is "&lt;SPAN&gt;that the default SAML IDP session cookie, also known as a token, is used for SAML authentication before&amp;nbsp;the GlobalProtect Authentication Override cookies is used."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004NCxCAM&amp;amp;lang=en_US%E2%80%A9" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004NCxCAM&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I guess the gateway &lt;EM&gt;has to check&lt;/EM&gt; the IdP cookie against the IdP.&amp;nbsp; So, the key is to configure the IdP cookie to achieve the desired results.&amp;nbsp; For example, the default Entra ID cookie lifetime is too long.&amp;nbsp; After logging in once, your users won't have to log in for a while.&amp;nbsp; Most people would prefer more frequent MFA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Apr 2026 17:27:58 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2026-04-30T17:27:58Z</dc:date>
    <item>
      <title>GP with saml authentication always redirects to idp</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-with-saml-authentication-always-redirects-to-idp/m-p/1253343#M126359</link>
      <description>&lt;P&gt;Hi community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In our globalprotect configuration, with SAML authentication and cookies in both portal and gateway, we observe that the firewall will redirect to the idp always, regardless of using cookies for authentication. We can see in the GP logs the cookies are being used but in the auth.log we see the redirection from firewall to idp.&lt;/P&gt;
&lt;P&gt;The only difference is that when cookies are valid, the user is not asked to enter username and password and the authentication happens transparent to the user.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In summary:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;(*)How it should work the authentication:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;-&amp;gt; First login:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;---&amp;gt; User is redirected to IdP (browser opens) for user authentication&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;---&amp;gt; Cookie is issued&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;-&amp;gt; Subsequent connections:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;---&amp;gt; GP sends cookie&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;---&amp;gt; Firewall validates/authenticates locally without redirection&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;(*) what is the behavior in our firewall:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-&amp;gt; First login:&lt;BR /&gt;---&amp;gt; User is redirected to IdP (browser opens) for user authentication&lt;BR /&gt;---&amp;gt; Cookie is issued&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-&amp;gt; Subsequent connections:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;--&amp;gt; Firewall redirects to idp&lt;BR /&gt;--&amp;gt; IdP auto-authenticates without asking the user for authentication.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tried config with Pan-OS &lt;SPAN&gt;11.2.10-h3 and GP 6.3.3-828&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is anyone having the same behavior?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2026 13:42:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-with-saml-authentication-always-redirects-to-idp/m-p/1253343#M126359</guid>
      <dc:creator>Carracido</dc:creator>
      <dc:date>2026-04-30T13:42:10Z</dc:date>
    </item>
    <item>
      <title>Re: GP with saml authentication always redirects to idp</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-with-saml-authentication-always-redirects-to-idp/m-p/1253353#M126360</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/24977"&gt;@Carracido&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, I have seen that behavior.&amp;nbsp; Although there are many documents which say that Authentication Override is an effective way to stop double &lt;U&gt;SAML&lt;/U&gt; authentication prompts for the portal and the gateway, I have rarely seen it work.&amp;nbsp; I no longer configure&amp;nbsp;Authentication Override with SAML, ... AND I don't need to.&amp;nbsp; As in your case, I can configure the IdP to achieve the same result.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The reason, I believe, why it doesn't work is "&lt;SPAN&gt;that the default SAML IDP session cookie, also known as a token, is used for SAML authentication before&amp;nbsp;the GlobalProtect Authentication Override cookies is used."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004NCxCAM&amp;amp;lang=en_US%E2%80%A9" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004NCxCAM&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I guess the gateway &lt;EM&gt;has to check&lt;/EM&gt; the IdP cookie against the IdP.&amp;nbsp; So, the key is to configure the IdP cookie to achieve the desired results.&amp;nbsp; For example, the default Entra ID cookie lifetime is too long.&amp;nbsp; After logging in once, your users won't have to log in for a while.&amp;nbsp; Most people would prefer more frequent MFA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2026 17:27:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-with-saml-authentication-always-redirects-to-idp/m-p/1253353#M126360</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2026-04-30T17:27:58Z</dc:date>
    </item>
  </channel>
</rss>

