<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using SAML with Global Protect Client and MS Azure in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/238010#M68195</link>
    <description>&lt;P&gt;when i check the cert i get this error&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;SAML -&amp;gt; method -&amp;gt; saml-idp is invalid. Validate Identity Provider Certificate is checked but no Certificate Profile is provided&lt;/LI&gt;&lt;LI&gt;authentication-profile -&amp;gt; SAML -&amp;gt; method is invalid&lt;/LI&gt;&lt;LI&gt;Commit failed&lt;/LI&gt;&lt;/UL&gt;</description>
    <pubDate>Wed, 31 Oct 2018 17:43:20 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2018-10-31T17:43:20Z</dc:date>
    <item>
      <title>Using SAML with Global Protect Client and MS Azure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/237793#M68135</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have configured global protect client 4.1.6.&lt;/P&gt;&lt;P&gt;We want to use MS Azure for MFA can we do this by using SAML?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Oct 2018 15:49:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/237793#M68135</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-30T15:49:20Z</dc:date>
    </item>
    <item>
      <title>Re: Using SAML with Global Protect Client and MS Azure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/237830#M68143</link>
      <description>&lt;P&gt;In general yes it should be possible, but you did not share a lot of information to answer the question ...&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you already have ADFS servers? Do you use Azure MFA there already? Do you use Azure MFA already for another service in your company or do you plan to implement it completely new?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Oct 2018 18:16:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/237830#M68143</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-10-30T18:16:38Z</dc:date>
    </item>
    <item>
      <title>Re: Using SAML with Global Protect Client and MS Azure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/237838#M68149</link>
      <description>&lt;P&gt;No it brand new setup.&lt;/P&gt;&lt;P&gt;We have GP client running version 4.1.6&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No we do not use Azure MFA.&lt;/P&gt;&lt;P&gt;What are ADFS?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How they are linked to SAML?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Oct 2018 18:56:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/237838#M68149</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-30T18:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: Using SAML with Global Protect Client and MS Azure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/237855#M68154</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does your company in this case already uses an Azure AD and/or Office 365 or other Microsoft Cloud Services? Or what is the exact reason to use Azure MFA if there are no prerequisites?&lt;/P&gt;&lt;P&gt;ADFS technically is a SAML Identity Provider (I assumed you use this one as it is probably the only SAML IdP with an Azure MFA Integration). Another way you can go is with a Microsoft NPS RADIUS Server with the Azure MFA Plugin.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Oct 2018 22:23:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/237855#M68154</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-10-30T22:23:36Z</dc:date>
    </item>
    <item>
      <title>Re: Using SAML with Global Protect Client and MS Azure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/237856#M68155</link>
      <description>&lt;P&gt;Yes we have office 365 in cloud and also AD but not ADFS&lt;/P&gt;</description>
      <pubDate>Tue, 30 Oct 2018 22:51:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/237856#M68155</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-30T22:51:04Z</dc:date>
    </item>
    <item>
      <title>Re: Using SAML with Global Protect Client and MS Azure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/237869#M68158</link>
      <description>&lt;P&gt;Is it possible for you that you connect other cloudservices (salesforce, dropbox business, ...) with SAML (with the existing things that you already have with your microsoft subscriptions)? If yes, then I you should be able to configure GP the same way as other SAML cloud services ... if not, you probably need ADFS ...&lt;/P&gt;</description>
      <pubDate>Tue, 30 Oct 2018 23:47:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/237869#M68158</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-10-30T23:47:24Z</dc:date>
    </item>
    <item>
      <title>Re: Using SAML with Global Protect Client and MS Azure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/237873#M68159</link>
      <description>&lt;P&gt;... or A Microsoft RADIUS server as an ADFS server is the more complex way I think ...&lt;/P&gt;</description>
      <pubDate>Tue, 30 Oct 2018 23:48:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/237873#M68159</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-10-30T23:48:54Z</dc:date>
    </item>
    <item>
      <title>Re: Using SAML with Global Protect Client and MS Azure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/237897#M68166</link>
      <description>&lt;P&gt;Yes earlier today i exported the SAML&amp;nbsp; &amp;nbsp;xml file in PA.&lt;/P&gt;&lt;P&gt;Then i try to connect to the Client&amp;nbsp; &amp;nbsp;everytime i see the error message&amp;nbsp; in system logs of PA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="pbSubsection"&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;'SAML SSO authentication failed for user \'\'. Reason: SAML web single-sign-on failed. reply message \'Reason: SAML web single-sign-on failed.\'' )&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 31 Oct 2018 03:10:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/237897#M68166</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-31T03:10:50Z</dc:date>
    </item>
    <item>
      <title>Re: Using SAML with Global Protect Client and MS Azure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/237898#M68167</link>
      <description>&lt;P&gt;Yes earlier today i exported the SAML&amp;nbsp; &amp;nbsp;xml file in PA.&lt;/P&gt;&lt;P&gt;Then i try to connect to the Client&amp;nbsp; &amp;nbsp;everytime i see the error message&amp;nbsp; in system logs of PA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;SAML SSO authentication failed for user&amp;nbsp; Reason: SAML web single-sign-on failed. reply message \'Reason: SAML web single-sign-on failed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="pbSubsection"&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 31 Oct 2018 03:19:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/237898#M68167</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-31T03:19:37Z</dc:date>
    </item>
    <item>
      <title>Re: Using SAML with Global Protect Client and MS Azure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/237921#M68171</link>
      <description>&lt;P&gt;Did you follow the help documents from paloalto and microsoft (&lt;A href="https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/configure-single-sign-on-non-gallery-applications" target="_blank"&gt;https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/configure-single-sign-on-non-gallery-applications&lt;/A&gt;) to configure this?&lt;/P&gt;&lt;P&gt;This error message sounds very generic. When did it show up?&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 10:34:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/237921#M68171</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-10-31T10:34:21Z</dc:date>
    </item>
    <item>
      <title>Re: Using SAML with Global Protect Client and MS Azure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/237953#M68176</link>
      <description>&lt;P&gt;I did not do the Azure part.&lt;/P&gt;&lt;P&gt;Which documents of PA you refer to?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We get this error message after&lt;/P&gt;&lt;P&gt;saml-client-redirect&lt;/P&gt;&lt;P&gt;saml-signature validated&lt;/P&gt;&lt;P&gt;saml out of band massage&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 13:48:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/237953#M68176</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-31T13:48:37Z</dc:date>
    </item>
    <item>
      <title>Re: Using SAML with Global Protect Client and MS Azure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/237956#M68177</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture11.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17374i715FB3EB08FE9BD8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture11.PNG" alt="Capture11.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture12.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17375i4783780A8DBBDF1B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture12.PNG" alt="Capture12.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 13:55:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/237956#M68177</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-31T13:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: Using SAML with Global Protect Client and MS Azure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/237991#M68191</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;I did not do the Azure part.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Without the configuration on azure side you will always get errors when you try to log in.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Which documents of PA you refer to?&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/authentication/set-up-external-authentication/set-up-saml-authentication" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/authentication/set-up-external-authentication/set-up-saml-authentication&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/globalprotect-features/saml-20-authentication-for-globalprotect" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/globalprotect-features/saml-20-authentication-for-globalprotect&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Wed, 31 Oct 2018 15:38:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/237991#M68191</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-10-31T15:38:26Z</dc:date>
    </item>
    <item>
      <title>Re: Using SAML with Global Protect Client and MS Azure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/238010#M68195</link>
      <description>&lt;P&gt;when i check the cert i get this error&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;SAML -&amp;gt; method -&amp;gt; saml-idp is invalid. Validate Identity Provider Certificate is checked but no Certificate Profile is provided&lt;/LI&gt;&lt;LI&gt;authentication-profile -&amp;gt; SAML -&amp;gt; method is invalid&lt;/LI&gt;&lt;LI&gt;Commit failed&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Wed, 31 Oct 2018 17:43:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/238010#M68195</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-31T17:43:20Z</dc:date>
    </item>
    <item>
      <title>Re: Using SAML with Global Protect Client and MS Azure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/238070#M68201</link>
      <description>&lt;P&gt;... then uncheck the checkbox or create a cert profile with the root cert of the server certificate that microsoft uses &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 20:18:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/238070#M68201</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-10-31T20:18:54Z</dc:date>
    </item>
    <item>
      <title>Re: Using SAML with Global Protect Client and MS Azure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/238107#M68205</link>
      <description>&lt;P&gt;creating a cookie override&amp;nbsp; on portal&amp;nbsp; and accepting on gateway make it worked&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 23:12:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/238107#M68205</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-31T23:12:40Z</dc:date>
    </item>
    <item>
      <title>Re: Using SAML with Global Protect Client and MS Azure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/238108#M68206</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;creating a cookie override&amp;nbsp; on portal&amp;nbsp; and accepting on gateway make it worked&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Isn't this something completely different than what you were asking in your initial post?&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&lt;SPAN&gt;We want to use MS Azure for MFA can we do this by using SAML?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 23:39:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/238108#M68206</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-10-31T23:39:16Z</dc:date>
    </item>
    <item>
      <title>Re: Using SAML with Global Protect Client and MS Azure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/238121#M68207</link>
      <description>&lt;P&gt;I agree i should have open separte discussion for this but things happened very quickly at my end.&lt;/P&gt;&lt;P&gt;My apologies for that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Nov 2018 00:46:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/238121#M68207</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-11-01T00:46:41Z</dc:date>
    </item>
    <item>
      <title>Re: Using SAML with Global Protect Client and MS Azure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/335973#M84659</link>
      <description>&lt;P&gt;We posted a &lt;A href="https://www.consigas.com/best-practices/authenticating-globalprotect-and-prisma-access-remote-access-users-against-office365-azure-ad" target="_self"&gt;training video&lt;/A&gt; explaining how to securely set up SAML authentication end-to-end against Office 365 Azure AD. The critical element which explains how to set up certificate validation of the SAML Identity Provider to address the SAML Bypass Vulnerability (CVE-2020-2021) starts at 29:35. It shows how to enable "Validate Identity Provider Certificate" and fix the commit error "Validate Identity Provider Certificate is checked but no Certificate Profile is provided authentication-profile"&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 07:19:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/335973#M84659</guid>
      <dc:creator>LarsAtConsigas</dc:creator>
      <dc:date>2020-06-30T07:19:06Z</dc:date>
    </item>
    <item>
      <title>Re: Using SAML with Global Protect Client and MS Azure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/336207#M84696</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/32514"&gt;@LarsAtConsigas&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;What about for Okta if we don't use Azure AD for this?&amp;nbsp;&lt;/P&gt;&lt;P&gt;We use GlobalProtect and VPN.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Okta's guide here says to&amp;nbsp;&lt;STRONG&gt;not check&lt;/STRONG&gt; the Validate Identity Provider certificate:&lt;/P&gt;&lt;P&gt;&lt;A href="https://saml-doc.okta.com/SAML_Docs/How-to-Configure-SAML-2.0-for-Palo-Alto-Networks-GlobalProtect.html" target="_blank"&gt;https://saml-doc.okta.com/SAML_Docs/How-to-Configure-SAML-2.0-for-Palo-Alto-Networks-GlobalProtect.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2020 03:11:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-saml-with-global-protect-client-and-ms-azure/m-p/336207#M84696</guid>
      <dc:creator>JohnQuile</dc:creator>
      <dc:date>2020-07-01T03:11:28Z</dc:date>
    </item>
  </channel>
</rss>

