Allow single user to bypass MFA

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Allow single user to bypass MFA

L2 Linker

Hi All,

 

I would like to access Global Protect for myself using different profile to access one of our resources subnet 10.21.xx.xx.

 

I want to access without having to go through 2FA. Any idea for it? is it possible?

 

Do we need to create another gateway on the GP for a single user?

 

 

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

Hi @isentric89 ,

 

Yes, you can have different authentication methods for different users.

 

  1. Create a new authentication profile without MFA and list only yourself under Advanced > Allow List.
  2. Add a new Authentication Sequence, with your new authentication profile on top.
  3. Change you authentication profile under both the portal and gateway to the authentication sequence.
  4. Since you are the only one in the allow list, the new authentication profile will be used for you.  The existing one will be used for everyone else.

You do not need a new gateway.  With regard to access to resources, that is controlled in the security policy.

 

Thanks,

 

Tom

 

Edit:  Thank you @aleksandar.astardzhiev for the feedback!  I actually made this same mistake when doing this for a customer months ago, and forgot my lesson learned!  I have corrected my steps above.

Help the community: Like helpful comments and mark solutions.

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

Hi @isentric89 ,

 

Yes, you can have different authentication methods for different users.

 

  1. Create a new authentication profile without MFA and list only yourself under Advanced > Allow List.
  2. Add a new Authentication Sequence, with your new authentication profile on top.
  3. Change you authentication profile under both the portal and gateway to the authentication sequence.
  4. Since you are the only one in the allow list, the new authentication profile will be used for you.  The existing one will be used for everyone else.

You do not need a new gateway.  With regard to access to resources, that is controlled in the security policy.

 

Thanks,

 

Tom

 

Edit:  Thank you @aleksandar.astardzhiev for the feedback!  I actually made this same mistake when doing this for a customer months ago, and forgot my lesson learned!  I have corrected my steps above.

Help the community: Like helpful comments and mark solutions.

Hey @TomYoung ,

Will the GP falback to the second authentication schema, if the first one reject the the user?

I have used two authentication schema only for two different types of OS, so I got the impresion that GP will select auth schema based on the OS, top-to-bottom, but it reject the authentication it will not falback to the rest in the list.

 

I was thinking more like using authentication sequence

- Create auth sequenece and put the authentication profile without MFA first and second the auth profile with MFA

- Non-MFA profile can be configured with allow list as you suggested

- Use the Authentication Sequence as authentication schema for GlobalPortect Portal and Gateway authentication.

  • 1 accepted solution
  • 2634 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!