<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect SSO and 3rd Party Credential Providers, What did you do? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-sso-and-3rd-party-credential-providers-what-did/m-p/162372#M52689</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/49049"&gt;@BrianRa&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you share some more details why it does not fit in your environment?&lt;/P&gt;&lt;P&gt;Your drive encryption software uses its own credential provider right? So you have set this credential provider as default credential provider at least in windows 10? In windows 8 it is (unfortunately) somewhere between diffcult and impossible to set a default credential provider. And windows 7 is completely different, there your only chance to set a "default" is to hide all others.&lt;/P&gt;&lt;P&gt;Or could you share how you did your tests and what the problems were? Another possibility is may be to user GlobalProtect with SAML, which then obvisously requires an SAML IdP or ADFS Server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Remo&lt;/P&gt;</description>
    <pubDate>Tue, 20 Jun 2017 20:16:32 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2017-06-20T20:16:32Z</dc:date>
    <item>
      <title>GlobalProtect SSO and 3rd Party Credential Providers, What did you do?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-sso-and-3rd-party-credential-providers-what-did/m-p/141723#M48433</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We recently installed Palo Alto firewalls (3000 series) and are currently working on our VPN configurations.&lt;/P&gt;&lt;P&gt;We have multiple 3rd party credential providers including drive encryption and Windows single sign on.&amp;nbsp; One of the selling points was the ability to have SSO VPN and full tunneling of the traffic on our laptops while off site.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have been unable to make this work with any of the other credential providers installed on the laptops.&amp;nbsp; The available documentation suggests wrapping the PAN credentials using a registry edit but this breaks the Windows SSO and does not fix the PAN GP SSO.&amp;nbsp; To be fair a stock domain laptop running Windows 7 or 8 does work with PAN GP SSO.&amp;nbsp; Unfortunately that is not an option for us.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PAN OS versions: 7.0.11, 7.0.12, 7.0.13, 7.1.6, 7.1.7&lt;/P&gt;&lt;P&gt;GP Client versions: 3.1.13, 3.1.14, 3.1.15&lt;/P&gt;&lt;P&gt;Windows OS versions: 7, 8, 10&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What have people been doing with multiple third party credential providers and using PAN GP SSOs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;EDIT&lt;/P&gt;&lt;P&gt;Sorry I didn't provide the link support keeps giving me:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Tips-amp-Tricks-Single-Sign-on-SSO-for-GlobalProtect/ta-p/112186" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Featured-Articles/Tips-amp-Tricks-Single-Sign-on-SSO-for-GlobalProtect/ta-p/112186&lt;/A&gt;&lt;/P&gt;&lt;P&gt;We have tried this as mentioned above but it doesn't allow it to work.&lt;/P&gt;&lt;P&gt;/EDIT&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2017 16:07:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-sso-and-3rd-party-credential-providers-what-did/m-p/141723#M48433</guid>
      <dc:creator>BrianRa</dc:creator>
      <dc:date>2017-03-15T16:07:54Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect SSO and 3rd Party Credential Providers, What did you do?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-sso-and-3rd-party-credential-providers-what-did/m-p/157993#M51735</link>
      <description>Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/49049"&gt;@BrianRa&lt;/a&gt;&lt;BR /&gt;&lt;BR /&gt;Probably you already found a solution, but a possibility would be the way I am describing here: &lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/Global-Protect-quot-Single-Sign-on-quot-with-Windows-Hello-on/m-p/157569#M51667" target="_blank"&gt;https://live.paloaltonetworks.com/t5/General-Topics/Global-Protect-quot-Single-Sign-on-quot-with-Windows-Hello-on/m-p/157569#M51667&lt;/A&gt;&lt;BR /&gt;As written in the post I am not 100 percent sure about possible security problems, but you probably don' t have problems with 3rd party credential providers anymore.&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;Remo</description>
      <pubDate>Tue, 23 May 2017 23:07:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-sso-and-3rd-party-credential-providers-what-did/m-p/157993#M51735</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-05-23T23:07:05Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect SSO and 3rd Party Credential Providers, What did you do?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-sso-and-3rd-party-credential-providers-what-did/m-p/158100#M51769</link>
      <description>&lt;P&gt;Remo,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the reply.&amp;nbsp; I will look into your write up.&amp;nbsp; We still have a ticket open with support on this subject as it is still not functioning.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2017 16:01:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-sso-and-3rd-party-credential-providers-what-did/m-p/158100#M51769</guid>
      <dc:creator>BrianRa</dc:creator>
      <dc:date>2017-05-24T16:01:38Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect SSO and 3rd Party Credential Providers, What did you do?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-sso-and-3rd-party-credential-providers-what-did/m-p/162371#M52688</link>
      <description>&lt;P&gt;Remo,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you again for the reply.&amp;nbsp; This did not quite fit our environment.&amp;nbsp; We are using drive encryption that then logs into windows with SSO based on the credentials provided during the drive decryption.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2017 19:48:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-sso-and-3rd-party-credential-providers-what-did/m-p/162371#M52688</guid>
      <dc:creator>BrianRa</dc:creator>
      <dc:date>2017-06-20T19:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect SSO and 3rd Party Credential Providers, What did you do?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-sso-and-3rd-party-credential-providers-what-did/m-p/162372#M52689</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/49049"&gt;@BrianRa&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you share some more details why it does not fit in your environment?&lt;/P&gt;&lt;P&gt;Your drive encryption software uses its own credential provider right? So you have set this credential provider as default credential provider at least in windows 10? In windows 8 it is (unfortunately) somewhere between diffcult and impossible to set a default credential provider. And windows 7 is completely different, there your only chance to set a "default" is to hide all others.&lt;/P&gt;&lt;P&gt;Or could you share how you did your tests and what the problems were? Another possibility is may be to user GlobalProtect with SAML, which then obvisously requires an SAML IdP or ADFS Server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Remo&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2017 20:16:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-sso-and-3rd-party-credential-providers-what-did/m-p/162372#M52689</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-06-20T20:16:32Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect SSO and 3rd Party Credential Providers, What did you do?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-sso-and-3rd-party-credential-providers-what-did/m-p/162379#M52690</link>
      <description>&lt;P&gt;Remo,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have not played with SAML that I am aware of, I will ask.&lt;/P&gt;&lt;P&gt;We are running primarily Windows 7 in our environment.&amp;nbsp; We are in the process of getting Windows 10 to work with our drive encryption and WSUS/KBox distribution servers, we skipped over windows 8.&amp;nbsp; We have tried to force every credential provider option in Windows 7 including default but have only been successful in breaking the Windows login SSO.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2017 20:32:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-sso-and-3rd-party-credential-providers-what-did/m-p/162379#M52690</guid>
      <dc:creator>BrianRa</dc:creator>
      <dc:date>2017-06-20T20:32:51Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect SSO and 3rd Party Credential Providers, What did you do?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-sso-and-3rd-party-credential-providers-what-did/m-p/162394#M52692</link>
      <description>&lt;P&gt;This sounds to me still like your drive encryption software needs its own credential provider for SSO. In windows 7 you also have the ability to wrap the GP credential provider around another credential provider.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2017 21:08:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-sso-and-3rd-party-credential-providers-what-did/m-p/162394#M52692</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-06-20T21:08:45Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect SSO and 3rd Party Credential Providers, What did you do?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-sso-and-3rd-party-credential-providers-what-did/m-p/162852#M52780</link>
      <description>&lt;P&gt;Have you looked to see if you may need to go to a newer client revision?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the bottom of the Tips and tricks document you linked, there is a Conclusions section wih the following info:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;For Windows 8 and Windows 10&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Because changes Microsoft had made to Windows login and the credential provider framework, users have to set GlobalProtect as the default sing-in option to ensure GlobalProtect SSO works as expected. Once set, Windows stores the sign-in option. Users don’t have to set this option each time they log in. With GlobalProtect 4.0 and later, you can use SetGPCPDefault to 1 force GlobalProtect to be the default credential provider.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;They tend to change things pretty significantly between client versions.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;In our case, we had to wait until GP 4.02 to use SAML to auth to Google G Suite.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Mark&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 21:26:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-sso-and-3rd-party-credential-providers-what-did/m-p/162852#M52780</guid>
      <dc:creator>mtsujihara</dc:creator>
      <dc:date>2017-06-22T21:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect SSO and 3rd Party Credential Providers, What did you do?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-sso-and-3rd-party-credential-providers-what-did/m-p/162982#M52811</link>
      <description>&lt;P&gt;Remo,&lt;/P&gt;&lt;P&gt;Unfortunately when we tried that it did not fix the problem.&amp;nbsp; We tried wraping GP around all the credential providers the machines had in registry.&lt;/P&gt;&lt;P&gt;Mark,&lt;/P&gt;&lt;P&gt;We have not moved to PAN 8.0.x yet.&amp;nbsp; We are running on current 7.1.x but the newest GP version available for that is 3.1.6, we are running this.&lt;BR /&gt;Both Windows 10 and PAN 8.0.x will be implemented in the fututer but we are not ready for that yet.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;Brian&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 16:34:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-sso-and-3rd-party-credential-providers-what-did/m-p/162982#M52811</guid>
      <dc:creator>BrianRa</dc:creator>
      <dc:date>2017-06-23T16:34:09Z</dc:date>
    </item>
  </channel>
</rss>

