User-ID with Azure AD

Reply
L1 Bithead

User-ID with Azure AD

Hello,

 

We have PC's that are only registered inside Azure AAD and managed via Intune they have no connection to the on-prem AD and are connecting via a Wifi zone behind PA to the internet.  How can i determine the USER id, without user interaction.

Or do i need Global protect for this and SSO?

Is there someting like a User ID agent for Azure AAD.

Or maybe i can use SAML SSO with Azure AAD for captive portal, can somebody point me to a good article on how to configure this.

 

 

L2 Linker

Re: User-ID with Azure AD

Hello,

 

Thanks for your question! This is an awesome use-case however, it's not one that we natively support at this time. There are other customers that have expressed interest in this capability.

 

If there's a chance you're running in a hybrid mode and have a Windows Server running AD and synchronizing with Azure AD then, of course, you can use the User-ID agent to communicate with the domain controller. SAML authentication works great with GlobalProtect, but it is not intended for use with User-ID.

 

If you'd like, you can contact me directly (email is first initial last name - no spaces or hyphens [at] paloaltonetworks[dot]com and provide me with your contact information, I'd be happy to add you to the enhancement request list.

 

Thanks for reaching out!

 

Best regards,

 

-JeffH

 

Jeff Hochberg | Sr. Systems Engineer - Technical Business Development

Palo Alto Networks | Atlanta, GA |  USA

Mobile: 404.432.1112 | www.paloaltonetworks.com

 

The content of this message is the proprietary and confidential property of Palo Alto Networks and should be treated as such. If you are not the intended recipient and have received this message in error, please delete this message from your computer system and notify me immediately by reply e-mail. Any unauthorized use or distribution of the content of this message is prohibited.

 

 

L1 Bithead

Re: User-ID with Azure AD

Hi Jeff,

 

I have dropped you an e-mail with my contact details.  To get around this limitation i could maybe user a captive portal and SAML SSO?

In my case these user are all on a seperate segment.

I will have to test this out.  

Never the less  integrating User-ID with Azure AAD would be a good enhancement.

 

 

L1 Bithead

Re: User-ID with Azure AD

Hi Jeff,

 

Any idea if this i a feature that will be introduced or palo alto is considering this?


L0 Member

Re: User-ID with Azure AD

I'm in the same boat as FDEMUYTER - all machines being managed via AzureAD/Azure Intune without any AD infra to speak of ( not in Hybrid ). Having to enter a userID kind of breaks the SSO experience IMO. Hoping there is a better way to do this.  

L1 Bithead

Re: User-ID with Azure AD

Hi.

what you could to to get the user id is use global protect client with SAML authentication to azure.

You can connect to internal or external portal and use always on. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!