Bit of history. We, our system architect, deployed GlobalProtect prior to covid and work from home. He set it up using SAML and no RADIUS. 5mo into work from home and most users have been required to change their passwords if not all of them. To date everyone is fine except for any user using a Mac.
I see documentation from Palo Alto saying that SAML is not supported. Also sent to me from TAC in regards to the issue. But I have not been able to find anything explaining "why" it doesnt work. This is an important fact I need to articulate especially since it works for all of our windows users, despite the documentation saying SAML is not supported or recommended at all and that we should use a RADIUS server.
Again I have no idea why they insisted on not using it considering we had 1 in place with our previous solution. But I still need to be able to tell them a little more than "because they said so".
Any help is much appreciated.
Do you mean pre-logon feature that is available from 5.2.x using credentials?
Have you tried certificate based pre-logon authentication setup for Macs?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!