User-ID with Azure AD

Showing results for 
Show  only  | Search instead for 
Did you mean: 

User-ID with Azure AD

L2 Linker



We have PC's that are only registered inside Azure AAD and managed via Intune they have no connection to the on-prem AD and are connecting via a Wifi zone behind PA to the internet.  How can i determine the USER id, without user interaction.

Or do i need Global protect for this and SSO?

Is there someting like a User ID agent for Azure AAD.

Or maybe i can use SAML SSO with Azure AAD for captive portal, can somebody point me to a good article on how to configure this.





what you could to to get the user id is use global protect client with SAML authentication to azure.

You can connect to internal or external portal and use always on. 

Hi. Have there been any updates regarding direct integration with Azure AD? We are looking to move to SaaS infrastructure.

Hi Olson,


No user-id agent for azure directly but you can solve this issue by using global protect and SAML authentication.

It depends on what you need and what is your use-case.

What do you want to accomplish in the end?

You can also look into Prisma.



Hi there


We are currently using UserID in schools to implement internet filtering during exams. The number of students far exceed our VPN tunnel capacity in our Palo Alto firewall so we can't use Globalprotect either. Another issue with Azure AD mentioned elsewhere is that you'll see the public NAT IP externally, so maybe UserID isn't an option at all? Maybe we have to look at alternativ implementation in our Cisco wifi solution.

Hi Olsen,


If you are using Cisco ISE you could try forwarding you logs to a palo alto user id agent configured as a syslog listener.

I have not tried it myself but was also something i was thinking about. 

Another thing you could to is use an internal portal only without creating a tunnel but only for authentication. This is called a non-tunnel mode gateway. (always on configuration)

This will require you to deploy global protect to all your clients.

This solution will give you the most accurate solution I think.

I am assuming all your users and computer are in azure ad only? How are your users authenticated on the WIFI?



Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!