- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-06-2025 11:33 PM
The current setup for User VPN Connection requires users to log in using their email address as the username and OTP from google authenticator as the password.
For VPN Client Verification, we would like to update the configuration to include password-based authentication for each user.
10-09-2025 09:45 PM
Hi @K.Mishra548222 ,
Currently, users log in to GlobalProtect using username + OTP, and you’d like to move to username + password, followed by OTP.
To achieve this, you’ll need to add password validation on the NPS server before the OTP challenge. The NPS server will handle both the username/password verification and the OTP challenge, while the Palo Alto firewall simply points to the NPS server via the server profiles you create and attach to the GP portal/gw, and forwards the authentication requests.
Make sure your NPS server or RADIUS plugin supports multi-factor (password + OTP) authentication, such as the Google Authenticator RADIUS plugin or a similar MFA extension.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!