- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-19-2022 03:07 AM
Hi,
I configured Global Protect with Azure MFA (SAML).I have set this up as described here: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000008U48CAE
Unfortunately I can´t see the FIDO Key in the Login-mask. The other authentification methods are displayed.
Since some users have only one FIDO key the question would be if the keys are supported and how do I set this up?
PAN-OS: 10.1
Global Protect-Version: 5.2.11 and 6.0.1
01-30-2024 11:47 PM
Old question without answer....
It seems that the embedded browser in the Global Protect client does not support FIDO MFA. Instead, configure Global Protect to use the default system browser. This works with Fido, but not as smooth as authenticating with the embedded browser.
Palo Alto Networks does not state the lack of support directly, but there is a hint of this information here: https://docs.paloaltonetworks.com/globalprotect/5-2/globalprotect-app-new-features/new-features-rele...
I found the solution to this problem here: https://community.rsa.com/s/article/FIDO-Authentication-Section
03-20-2024 03:57 AM
The embedded browser support for Fido is soon to arrive in the next 6.2.3 version 😊
Seems to work fine (I testet a pre release build), the Fido option is then presented as expected in this browser.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!