Configure Palo Alto GlobalProtect VPN (PA-3050) with Azure MFA Cloud

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Configure Palo Alto GlobalProtect VPN (PA-3050) with Azure MFA Cloud

L0 Member


* We have Azure AD Connect sync On-Premise Active Directory with Azure AD

* We have valid Azure AD Premium license


We would like to know whether we can configure MFA for our VPN. If so which one we need to choose

Azure MFA server or Azure MFA cloud?


Please give me the highlevel steps to accomplish our requirement


L5 Sessionator

Hi @Hameed310382


The vendor support list for MFA via RADIUS is outlined below.


Documentation for configuring GlobalProtect with 2FA can be found in the GlobalProtect Administrators Guide.





Hi @Hameed310382


For integrating Azure MFA you need to configure your on premise Azure MFA server as RADIUS server in your configuration. The list mentionned by @LukeBullimore shows only the natively integrated MFA cloud providers. With RADIUS, Paloalto supports almost every MFA software including Azure MFA.

So I need MFA server installed in On-Premise, can't I configure without any server in on-premise

I know this is way old,  but did you ever get this configured?

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!