- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-05-2026 06:02 AM
Hello,
I am trying to set up GlobalProtect to include SAML identity for our remote users to have MFA to go along with their username and password. Is there a step-by-step document that can walk me through this setup?
08-06-2026 12:12 PM
Hi @M.Phelps ,
Which identity provider are you going with?
The overall configuration on the Palo Alto side is fairly straightforward. I don't know the exact steps on the identity provider side, but you will typically need to create a SAML application with your IdP and export the IdP metadata XML.
One important item during the IdP configuration is the ACS URL (Assertion Consumer Service URL). This is the URL where the IdP sends the SAML assertion after successful authentication. The value must match what is configured on your portal. For example, lets say your portal URL is https://gp.company.com. You would use https://gp.company.com/SAML20/SP/ACS for the SAML ACS.
On the firewall side, the general workflow is:
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

