Content filtering for MAC OSx

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Content filtering for MAC OSx

L1 Bithead

I am trying to finalize my content filtering for our PA 820 rollout. I have the user-ID, group mapping and content filtering rules (By group) working just fine for my windows PC's. Where I am stuck is trying to figure it out for all of our MAC OSx users. None of our MAC's are joined to our domain and I am not sure about adding them at this time. Is there a good source for configuring content filtering in this scenario?


Cyber Elite
Cyber Elite


Do you use on-site Exchange at all? If not, you are essentially left with two options. 



GlobalProtect can be used to provide user-id information and your users would essentially just sign-in to GlobalProtect (or configure user certificates and always-on ideally) so that your macOS users map to their AD credentials (assuming you create users for them). 


Authentication Policy

You can setup an authentication policy so that your macOS users are actually authenticated and map to a user properly. Essentially you would just trigger for any unknown user accessing any service and they would need to login via a web form. 


Personally I would give these users GlobalProtect and tell them that they have to use it, or even enforce it across your entire network, because there's less friction and user involvement. You would simply setup a GlobalProtect internal gateway and allow the gateway and the GlobalProtect agent to keep the user-id information in place. This is less friction then authentication policy even if you don't setup an always-on certificate based method and simply have the users utilize on-demand mode. 

Yes, we have an onsite exchange server. With that said, what are my options there? I do have user ID set up for my exchange server. Should I add my file servers as well? Is this the best choice?

  • 2 replies
  • 101 Subscriptions
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!