User-ID with Azure AD

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

User-ID with Azure AD

L2 Linker

Hello,

 

We have PC's that are only registered inside Azure AAD and managed via Intune they have no connection to the on-prem AD and are connecting via a Wifi zone behind PA to the internet.  How can i determine the USER id, without user interaction.

Or do i need Global protect for this and SSO?

Is there someting like a User ID agent for Azure AAD.

Or maybe i can use SAML SSO with Azure AAD for captive portal, can somebody point me to a good article on how to configure this.

 

 

25 REPLIES 25

Any replies on this Palo? Plenty of people would like to see this functionality.

L1 Bithead

It's July 2021 , Intune/Microsoft Endpoint Manager isn't going away.  People are moving to it.  We have moved all of out endpoints to Intune.  Palo Alto needs a solution.  Is there an update here?

Hi Housing1,

As of today I am not aware of any direct integration with Azure AD.(used id agent for azure)  If you have Azure Active Directory Domain Services you could get group mappings using ldaps. 

https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/authentication/enable-group... .

To get the user info you could use a global protect client internal portal for authentication only using SAML. (portal non-tunnel model)

Or you can setup a captive portal with SAML authentication to Azure AD.

Depends on you use case.

I think the best option is to use global protect client.   For windows laptops no license is needed only for mobile endpoints and linux clients.  

 

 

 

 

L3 Networker

Hello PAN team,

 

Were there any updates about supporting Azure AAD for User-ID since Jeff Hochberg commented in 2019?

 

Thanks,

--
"The Simplicity is the ultimate sophistication." - Leonardo da Vinci.

L1 Bithead

Bump. Any update to this, 3 years now, this is a major problem now?

my entire environment is also in Azure-AD. 
It would be nice to use userID with the logins that come over the SAML for globalprotect.  We have zero intention of putting any more hardware on site.  So introducing a hybrid setup would be a step backwards for us.


Hi Jeff,

Were there any updates about supporting Azure AAD for User-ID since you commented on it in 2019?

 

Thanks,

--
"The Simplicity is the ultimate sophistication." - Leonardo da Vinci.

L0 Member

Hello checking if we have a solution to this issue now please ?

L2 Linker

Bumping this thread. 01/26/2023 still looking for options. Thanks!

L2 Linker

This may be the answer we are looking for. Still looking into the details.

https://www.youtube.com/watch?v=fZWMP5Bp_Go

L0 Member

Has anyone got this working yet?  

  • 38293 Views
  • 25 replies
  • 2 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!