GlobalProtect SAML Login Loop

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

GlobalProtect SAML Login Loop

L0 Member

Hi All,

I am using CIE and EntraID with SAML to allow logins to GP. This is working very well but I am having an issue. I had a user whose name changed. When logging into GP, it just continuously asks her to log in. Inside of the GP Portal, I get the error 'username from cas sso response is different from the input' and can see where it is trying to use her old email address to log in. She is using her new address and has tried with multiple browsers but no luck. 

I am guessing it is something with the Microsoft profile but I have no idea where to look. Has anyone seen this and then resolved the issue?

3 REPLIES 3

L3 Networker

Firewall just redirects the user to CIE and waits for the validated token for that user. I think you should look at EntraID and check CIE logs for authentication.

L0 Member

Thank you for the response. CIE logs are actually showing the right username. It seems that only the firewall is showing the wrong one. 

We need to take a look at the firewall logs for more clarity. 

  • 358 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!