We tried to implement the OKTA SAML authentication method for GP in our organization.
Does Global Protect - "Prelogon Then On-Demand" connection method supports Okta SAML for authentication (MFA).?
If not what is a recommended GP connection method to use Okta SAML authentication.
Could you please help us here! I tried all resources I didn't got an answer..!!
Having GP authentication working with the different connection methods strongly depends on the GP agent version you are using. With which version do you try this configuration and also which PAN-OS version do you have installed on the firewall?
Btw. I assume you already know about this critical vulnerability: https://security.paloaltonetworks.com/CVE-2020-2021
So make sure you use either one of the PAN-OS versions that are fixed or enable the option "Validate Identity Provider Certificate".
We have configured GP Pre log on Machine cert based Authentication and then we added Authentication Profile using SAML in Azure.
To config OKTA for SAML please follow this link'
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!