<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can Use Okta SAML for GP- &amp;quot;Prelogon Then On-Demand&amp;quot; connectio in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-use-okta-saml-for-gp-quot-prelogon-then-on-demand-quot/m-p/336578#M84783</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/105434"&gt;@Sethupathi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have configured GP Pre log on Machine cert based Authentication and then we added Authentication Profile using SAML in Azure.&lt;/P&gt;
&lt;P&gt;To config OKTA for SAML please follow this link'&lt;/P&gt;
&lt;P&gt;&lt;A href="https://saml-doc.okta.com/SAML_Docs/How-to-Configure-SAML-2.0-for-Palo-Alto-Networks-GlobalProtect.html" target="_blank"&gt;https://saml-doc.okta.com/SAML_Docs/How-to-Configure-SAML-2.0-for-Palo-Alto-Networks-GlobalProtect.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Fri, 03 Jul 2020 17:44:58 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2020-07-03T17:44:58Z</dc:date>
    <item>
      <title>Can Use Okta SAML for GP- "Prelogon Then On-Demand" connection method</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-use-okta-saml-for-gp-quot-prelogon-then-on-demand-quot/m-p/336477#M84755</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We tried to implement the OKTA SAML authentication method for GP in our organization.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does Global Protect - "Prelogon Then On-Demand" connection method supports Okta SAML for authentication (MFA).?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If not what is a recommended GP connection method to use Okta SAML authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you please help us here! I tried all resources I didn't got an answer..!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;_&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sethupathi M&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2020 16:20:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-use-okta-saml-for-gp-quot-prelogon-then-on-demand-quot/m-p/336477#M84755</guid>
      <dc:creator>Sethupathi</dc:creator>
      <dc:date>2020-07-02T16:20:30Z</dc:date>
    </item>
    <item>
      <title>Re: Can Use Okta SAML for GP- "Prelogon Then On-Demand" connectio</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-use-okta-saml-for-gp-quot-prelogon-then-on-demand-quot/m-p/336504#M84763</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/105434"&gt;@Sethupathi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Having GP authentication working with the different connection methods strongly depends on the GP agent version you are using. With which version do you try this configuration and also which PAN-OS version do you have installed on the firewall?&lt;/P&gt;
&lt;P&gt;Btw. I assume you already know about this critical vulnerability:&amp;nbsp;&lt;A href="https://security.paloaltonetworks.com/CVE-2020-2021" target="_blank"&gt;https://security.paloaltonetworks.com/CVE-2020-2021&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;So make sure you use either one of the PAN-OS versions that are fixed or enable the option "&lt;SPAN&gt;Validate Identity Provider Certificate".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Remo&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2020 20:28:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-use-okta-saml-for-gp-quot-prelogon-then-on-demand-quot/m-p/336504#M84763</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-07-02T20:28:32Z</dc:date>
    </item>
    <item>
      <title>Re: Can Use Okta SAML for GP- "Prelogon Then On-Demand" connectio</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-use-okta-saml-for-gp-quot-prelogon-then-on-demand-quot/m-p/336578#M84783</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/105434"&gt;@Sethupathi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have configured GP Pre log on Machine cert based Authentication and then we added Authentication Profile using SAML in Azure.&lt;/P&gt;
&lt;P&gt;To config OKTA for SAML please follow this link'&lt;/P&gt;
&lt;P&gt;&lt;A href="https://saml-doc.okta.com/SAML_Docs/How-to-Configure-SAML-2.0-for-Palo-Alto-Networks-GlobalProtect.html" target="_blank"&gt;https://saml-doc.okta.com/SAML_Docs/How-to-Configure-SAML-2.0-for-Palo-Alto-Networks-GlobalProtect.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jul 2020 17:44:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-use-okta-saml-for-gp-quot-prelogon-then-on-demand-quot/m-p/336578#M84783</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-07-03T17:44:58Z</dc:date>
    </item>
  </channel>
</rss>

