- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
04-21-2024 07:26 PM
Is it possible to apply conditional rules on a GlobalProtect login so the means of login can vary? For example; If a Windows client is operating within a particular country or public IP range, just require simple SAML user login and maybe AD machine membership. However, if the client is outside of the country/ip-range, prompt the user for an MFA login.
04-22-2024 07:59 AM
Hi @JimMcGrady ,
That is a very interesting question! The only option you have for different authentication policies on the portal or gateway is OS. That doesn't help.
However, you can have clients select different gateways based upon countries, and the gateways can be configured with different authentication methods.
For example, you could have SAML for your portal login. The login info is cached by the portal and sent to the gateway. One gateway can have the same SAML, and the client will not be prompted for login again. Another gateway could have the same SAML (so same creds) with MFA enabled, and those clients will be prompted for MFA.
MFA is always recommended for RA VPN. Another option you may consider is have a long cookie lifetime for the trusted country and a short lifetime for the untrusted countries. As long as the cookie is not expired, users will not be prompted for MFA. However, they will not be prompted for username and password either. This is not the portal/gateway authentication cookie, but rather the IdP MFA authentication cookie.
Thanks,
Tom
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!