<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Setting up dual authentication or single authentication based on the user group in global protect in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/setting-up-dual-authentication-or-single-authentication-based-on/m-p/165358#M53166</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have the requirement where we have to setup dual authentication for some set (Group) of &amp;nbsp;user and single authentication for remaining global protect user. Is this duable? if yes, please provide info.&lt;/P&gt;&lt;P&gt;Note : We have the single gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Guru&lt;/P&gt;</description>
    <pubDate>Sat, 08 Jul 2017 16:42:21 GMT</pubDate>
    <dc:creator>Gururaj</dc:creator>
    <dc:date>2017-07-08T16:42:21Z</dc:date>
    <item>
      <title>Setting up dual authentication or single authentication based on the user group in global protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/setting-up-dual-authentication-or-single-authentication-based-on/m-p/165358#M53166</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have the requirement where we have to setup dual authentication for some set (Group) of &amp;nbsp;user and single authentication for remaining global protect user. Is this duable? if yes, please provide info.&lt;/P&gt;&lt;P&gt;Note : We have the single gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Guru&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jul 2017 16:42:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/setting-up-dual-authentication-or-single-authentication-based-on/m-p/165358#M53166</guid>
      <dc:creator>Gururaj</dc:creator>
      <dc:date>2017-07-08T16:42:21Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up dual authentication or single authentication based on the user group in global protec</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/setting-up-dual-authentication-or-single-authentication-based-on/m-p/165365#M53167</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/30661"&gt;@Gururaj&lt;/a&gt;&lt;BR /&gt;Are you using PAN-OS 8.0.x?&lt;BR /&gt;&lt;BR /&gt;I would setup two Authentication profiles and one Authentication Sequence profile.&lt;BR /&gt;For example:&lt;BR /&gt;Authentication profiles:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;LDAP-PROFILE01&lt;UL&gt;&lt;LI&gt;Two Factor: Enabled&lt;/LI&gt;&lt;LI&gt;Advanced: Specify the AD group you want to enforce two factor authenticantion&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;LDAP-PROFILE02&lt;UL&gt;&lt;LI&gt;Two Factor: Disabled&lt;/LI&gt;&lt;LI&gt;Advanced: Specify "All" or the specific AD group which should not have two factor authentication enforced&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Authentication Sequence:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;LDAP-AUTH-SEQUENCE&lt;UL&gt;&lt;LI&gt;Add LDAP-PROFILE01&lt;/LI&gt;&lt;LI&gt;Add LDAP-PROFILE02&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; The authentication sequence will try to match the username against each one of the profiles above in a sequence, once it matches, and access is validated the access is granted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;GlobalProtectPortal&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Specify the LDAP-AUTH-SEQUENCE Profile&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;GlobalProtect Gateway&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Specify the LDAP-AUTH-SEQUENCE Profile&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;You can still speicify in the User/Group tab inside the portal and gateway configuration the AD groups you want to allow, but the auth factor will be enforced via the profiles created before.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope it makes sense.&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jul 2017 17:02:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/setting-up-dual-authentication-or-single-authentication-based-on/m-p/165365#M53167</guid>
      <dc:creator>acc6d0b3610eec313831f7900fdbd235</dc:creator>
      <dc:date>2017-07-08T17:02:53Z</dc:date>
    </item>
  </channel>
</rss>

