Global Protect Azure MFA SAML FIDO Key

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Global Protect Azure MFA SAML FIDO Key

L0 Member

Hi,

 

I configured Global Protect with Azure MFA (SAML).I have set this up as described here: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000008U48CAE

 

Unfortunately I can´t see the FIDO Key in the Login-mask. The other authentification methods are displayed.

 

Since some users have only one FIDO key the question would be if the keys are supported and how do I set this up?

 

PAN-OS: 10.1
Global Protect-Version: 5.2.11 and 6.0.1

2 REPLIES 2

L0 Member

Old question without answer....

It seems that the embedded browser in the Global Protect client does not support FIDO MFA. Instead, configure Global Protect to use the default system browser.  This works with Fido, but not as smooth as authenticating with the embedded browser. 

 

Palo Alto Networks does not state the lack of support directly, but there is a hint of this information here:   https://docs.paloaltonetworks.com/globalprotect/5-2/globalprotect-app-new-features/new-features-rele...

 

I found the solution to this problem here:  https://community.rsa.com/s/article/FIDO-Authentication-Section

 

L0 Member

The embedded browser support for Fido is soon to arrive in the next 6.2.3 version 😊

Seems to work fine (I testet a pre release build), the Fido option is then presented as expected in this browser. 

  • 2912 Views
  • 2 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!