<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SAML ADFS for GlobalProtect in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/saml-adfs-for-globalprotect/m-p/172441#M54406</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18904"&gt;@Kashif_Noor&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why don't you just try this to see if it works? Because I would be interested too &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But now something hopefully more helpful:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;As it is also possible with RADIUS, I assume that it will also work with SAML. But it's more a two way communication. One part is to have your firewall connecting to your LDAP directory to get the group mappings and also to be able to use LDAP groups in your policy or in your global protect gateway. If you there configured SAML as authentication, your IdP will tell the firewall which user just logged in and the firewall is able to check to what synchronized groups this user belongs to&lt;/LI&gt;&lt;LI&gt;For pre-logon you can only use a certificate profile, because at that stage the certificate is the only thing which is available without user-interaction. But SAML can then be used afterwards for userlogin, as described somehow in point 1 to apply user/group based policies/configurations.&lt;/LI&gt;&lt;/OL&gt;</description>
    <pubDate>Mon, 21 Aug 2017 18:13:05 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2017-08-21T18:13:05Z</dc:date>
    <item>
      <title>SAML ADFS for GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/saml-adfs-for-globalprotect/m-p/172240#M54393</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Is someone able to shed some ligh on the below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1. Can SAML be used to map to an LDAP group, if so is there guidance?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2. Does PAN&amp;nbsp;support using SAML AND prelogon/alwayson with GP?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2017 15:42:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/saml-adfs-for-globalprotect/m-p/172240#M54393</guid>
      <dc:creator>Kashif_Noor</dc:creator>
      <dc:date>2017-08-18T15:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: SAML ADFS for GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/saml-adfs-for-globalprotect/m-p/172428#M54394</link>
      <description>&lt;P&gt;This question was posted in the wrong area.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am moving this to the General Discussion area.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2017 16:51:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/saml-adfs-for-globalprotect/m-p/172428#M54394</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2017-08-21T16:51:59Z</dc:date>
    </item>
    <item>
      <title>Re: SAML ADFS for GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/saml-adfs-for-globalprotect/m-p/172441#M54406</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18904"&gt;@Kashif_Noor&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why don't you just try this to see if it works? Because I would be interested too &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But now something hopefully more helpful:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;As it is also possible with RADIUS, I assume that it will also work with SAML. But it's more a two way communication. One part is to have your firewall connecting to your LDAP directory to get the group mappings and also to be able to use LDAP groups in your policy or in your global protect gateway. If you there configured SAML as authentication, your IdP will tell the firewall which user just logged in and the firewall is able to check to what synchronized groups this user belongs to&lt;/LI&gt;&lt;LI&gt;For pre-logon you can only use a certificate profile, because at that stage the certificate is the only thing which is available without user-interaction. But SAML can then be used afterwards for userlogin, as described somehow in point 1 to apply user/group based policies/configurations.&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Mon, 21 Aug 2017 18:13:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/saml-adfs-for-globalprotect/m-p/172441#M54406</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-08-21T18:13:05Z</dc:date>
    </item>
  </channel>
</rss>

