I'd like to know about certificates for GlobalProtect user authentication.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

I'd like to know about certificates for GlobalProtect user authentication.

L2 Linker

Attention: JAPAC TPM team
Hello Team,

 

Is it possible to apply client certificates to only some user authentications using GlobalProtect depending on the OS type?

 

My understanding is that if a certificate is specified in GlobalProtect's user authentication settings, it will also be set in other user authentication settings, so I don't think this is possible.

 

Also, for example, is the following configuration possible?
- Windows devices: SAML authentication
- iOS devices: SAML authentication + certificate authentication

 

1 accepted solution

Accepted Solutions

L0 Member

Yes, it is possible to apply different authentication methods, including client certificates, to GlobalProtect users based on their OS type. GlobalProtect allows you to define multiple client authentication configurations and prioritize them. You can create different authentication profiles and associate them with specific OS types. This enables scenarios like your example: Windows devices using SAML authentication, and iOS devices using SAML authentication plus certificate authentication. The GlobalProtect portal or gateway will then evaluate these configurations in order to determine the appropriate authentication method for each connecting device.

 

Regards,
Rose S.

 

View solution in original post

2 REPLIES 2

L0 Member

Yes, it is possible to apply different authentication methods, including client certificates, to GlobalProtect users based on their OS type. GlobalProtect allows you to define multiple client authentication configurations and prioritize them. You can create different authentication profiles and associate them with specific OS types. This enables scenarios like your example: Windows devices using SAML authentication, and iOS devices using SAML authentication plus certificate authentication. The GlobalProtect portal or gateway will then evaluate these configurations in order to determine the appropriate authentication method for each connecting device.

 

Regards,
Rose S.

 

@rose42snowden 

Thank you for your response.

This has been accepted as a solution.

 

  • 1 accepted solution
  • 627 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!