<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User not in Allow list in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-not-in-allow-list/m-p/248110#M70581</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We use SAML authentication profile. with PAN-OS 8.0.13 and GP 4.1.8.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Followed the document below but getting error:&amp;nbsp;SAML SSO authentication failed for user. Reason: User is not in allowlist.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="http://saml-doc.okta.com/SAML_Docs/How-to-Configure-SAML-2.0-for-Palo-Alto-Networks-GlobalProtect.html" target="_blank"&gt;http://saml-doc.okta.com/SAML_Docs/How-to-Configure-SAML-2.0-for-Palo-Alto-Networks-GlobalProtect.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have verified our settings as per the guide below and if we set allow list to "All" then it works fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://na01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail%3Fid%3DkA10g000000ClizCAC&amp;amp;data=02%7C01%7Csupport-anz%40arrow.com%7C49adfb5688fa47dba56108d6866c73c2%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C636844197707427391&amp;amp;sdata=ujlTXSn371v3%2F7LPNdqVRXlXqSDbDvpeApC%2FKSJD25I%3D&amp;amp;reserved=0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClizCAC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestion what we can check further?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 30 Jan 2019 06:14:23 GMT</pubDate>
    <dc:creator>FarzanaMustafa</dc:creator>
    <dc:date>2019-01-30T06:14:23Z</dc:date>
    <item>
      <title>User not in Allow list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-not-in-allow-list/m-p/248110#M70581</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We use SAML authentication profile. with PAN-OS 8.0.13 and GP 4.1.8.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Followed the document below but getting error:&amp;nbsp;SAML SSO authentication failed for user. Reason: User is not in allowlist.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="http://saml-doc.okta.com/SAML_Docs/How-to-Configure-SAML-2.0-for-Palo-Alto-Networks-GlobalProtect.html" target="_blank"&gt;http://saml-doc.okta.com/SAML_Docs/How-to-Configure-SAML-2.0-for-Palo-Alto-Networks-GlobalProtect.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have verified our settings as per the guide below and if we set allow list to "All" then it works fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://na01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail%3Fid%3DkA10g000000ClizCAC&amp;amp;data=02%7C01%7Csupport-anz%40arrow.com%7C49adfb5688fa47dba56108d6866c73c2%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C636844197707427391&amp;amp;sdata=ujlTXSn371v3%2F7LPNdqVRXlXqSDbDvpeApC%2FKSJD25I%3D&amp;amp;reserved=0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClizCAC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestion what we can check further?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 06:14:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-not-in-allow-list/m-p/248110#M70581</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2019-01-30T06:14:23Z</dc:date>
    </item>
    <item>
      <title>Re: User not in Allow list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-not-in-allow-list/m-p/248179#M70602</link>
      <description>&lt;P&gt;hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/98673"&gt;@FarzanaMustafa&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You'll always need to add 'something' in the allow list. Okta appears to not have documented that properly.&lt;/P&gt;
&lt;P&gt;The step they propose where you open the advanced tab and then click 'ok' does not work anymore by the way, you now must click add and either choose a user, group or all before being able to click OK &lt;/P&gt;
&lt;P&gt;What version of PAN-OS are you on currently?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 14:46:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-not-in-allow-list/m-p/248179#M70602</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-01-30T14:46:39Z</dc:date>
    </item>
  </channel>
</rss>

