- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-26-2024 05:09 AM - edited 11-26-2024 05:11 AM
Hi Support,
I am trying to configure Globalprotect with Azure Saml integration.
The authentication part is configured following the link ( https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000008U48CAE).
Additionally usergroup in Azure are configured with the attribute "group" and is mapped to each usergroup name.
Saml authentication profile in PA firewall contains the user group attribute name as "group" (matching the usergroup attribute from Azure).
Now the question here is , do i need to create multiple Saml authentication profiles like one for the GP Portal authentication which contains the Allow list as "all",
And one each for every user group with their respective Asserted Azure user group name in Allow list. which can be called in GP Gateway authentication configuration to map the usergroup with their vpn pool and other settings.
Regards,
11-26-2024 05:49 PM
If I understand the question properly, you should be able to just have a single profile. You can utilize the user group on the portal and the gateway to control the configuration that each group receives or whether they're able to utilize that portal/gateway. So the authentication will use the single authentication profile while the actual portal agent configuration can be driven by the group alongside the gateways client settings.
11-27-2024 01:39 AM
@BPry ,
Thanks for the reply , It is still unclear how the GP will distinguish which usergroup gets which VPN pool range with a single authentication profile that includes the usergroups (derived from Azure saml) in the allow list..
My aim is to make sure each usergroup fetched from Azure SAML is assigned with a specific set of vpn pool range , and with that a security rule can be configured to allow specific destination access based on the vpn pool ranges.
Regards,
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!