GlobalProtect Azure Saml user/group attribute Mapping

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

GlobalProtect Azure Saml user/group attribute Mapping

L0 Member

Hi Support,

 

 

I am trying to configure Globalprotect with Azure Saml integration.

The authentication part is configured following the link ( https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000008U48CAE).

 

Additionally usergroup in Azure are configured with the attribute "group"  and is mapped to each usergroup name.

 

Saml authentication profile in PA firewall contains the user group attribute name as "group" (matching the usergroup attribute from Azure).

 

Now the question here is , do i need to create multiple Saml authentication profiles like one for the GP Portal authentication which contains the Allow list as "all",

 

And one each for every user group with their respective Asserted Azure user group name in Allow list. which can be called in GP Gateway authentication configuration to map the usergroup with their vpn pool and other settings.

 

 

Regards,

 

2 REPLIES 2

Cyber Elite
Cyber Elite

@l2-security,

If I understand the question properly, you should be able to just have a single profile. You can utilize the user group on the portal and the gateway to control the configuration that each group receives or whether they're able to utilize that portal/gateway. So the authentication will use the single authentication profile while the actual portal agent configuration can be driven by the group alongside the gateways client settings.

L0 Member

@BPry ,

Thanks for the reply , It is still unclear how the GP will distinguish which usergroup gets which VPN pool range with a single authentication profile that includes the usergroups (derived from Azure saml) in the allow list..
My aim is to make sure each usergroup fetched from Azure SAML is assigned with a specific set of vpn pool range , and with that a security rule can be configured to allow specific destination access based on the vpn pool ranges.

 

Regards,

 

 

  • 128 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!