We have Entra ID with Global protect works well with SSO but security wants additional MFA

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

We have Entra ID with Global protect works well with SSO but security wants additional MFA

L3 Networker

We already have the SSO setup with MFA. but security wants us to have a additional MFA.

 

Is their a way to do this ? 

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

Hi @din100 ,

 

This may be an issue with your Azure cookie settings.  Check these posts.

 

https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-azure-saml-mfa-prompt-e...

 

https://live.paloaltonetworks.com/t5/globalprotect-discussions/force-user-credentials-at-every-login...

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

View solution in original post

5 REPLIES 5

Community Team Member

Hi @din100 ,


Do you have 2FA setup for your SSO? Or do users just auth via username/pass creds. On the Azure side, Conditional Access is where you can setup 2FA with DUO/authenticator/RSA

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

L3 Networker

yes we have a 2fa with SSO but security wants users to MFA in every time they connect to the VPN. because it's SSO they connect automatically which they think It's not secure 🤕

Cyber Elite
Cyber Elite

Hi @din100 ,

 

This may be an issue with your Azure cookie settings.  Check these posts.

 

https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-azure-saml-mfa-prompt-e...

 

https://live.paloaltonetworks.com/t5/globalprotect-discussions/force-user-credentials-at-every-login...

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

L3 Networker

Thank you sorry my search didn't come up with that result 

Your security staff or whomever is in control of your VPN configuration, need to test and learn how to get the 2FA/MFA to work properly and turn off the SSO if they feel that is not secure.  And then they need to have the patience of saints teaching their users how to install some Authenticator App on a phone so that you all can experience the LOVELY MFA that my company has me going thru... every 24 hours... I have to show my face to my phone... in between it remembers I did it already that day.  The stuff works.  But it probably is easy to mess up the configuration of it.

 

  • 1 accepted solution
  • 840 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!