- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
01-23-2025 07:02 PM
Hello everyone!
I am looking into setting up custom portal name in Prisma access GP VPN.
Currently configured is
Paloalto CIE <> MS Azure AD (Entra ID) integration completed
GlobalProtect <> PA CIE SAML authentication integration completed
When accessing ~.gpcloudservice.com with GP Agent, connection established with Azure AD SAML authentication.
I checked that there is a Saml signing cert method in the custom portal name > Portal Certificate setting.
My question is this.
Download SAML certificate from Azure AD and distribute and install it to the client > Is the GPcloudservice authentication method correct through the SAML certificate that the user has?
When using the custom portal name method, I think it would be correct to distribute a SAML certificate to the client since it is a method for encrypting the connection between the user <> GP Cloud service.
Thank you.
02-08-2025 06:18 PM
@SGCHOI wrote:
Hello everyone!
I am looking into setting up custom portal name in Prisma access GP VPN.
Currently configured is
Paloalto CIE <> MS Azure AD (Entra ID) integration completed
GlobalProtect <> PA CIE SAML authentication integration completed
When accessing ~.gpcloudservice.com with GP Agent, connection established with Azure AD SAML authentication.I checked that there is a Saml signing cert method in the custom portal name > Portal Certificate setting.
My question is this.
Download SAML certificate from Azure AD and distribute and install it to the client > Is the GPcloudservice authentication method correct through the SAML certificate that the user has?
When using the custom portal name method, I think it would be correct to distribute a SAML certificate to the client since it is a method for encrypting the connection between the user <> GP Cloud service.
Thank you.
Hello @SGCHOI , Yes, distributing and installing the SAML certificate from Azure AD to the client is the correct approach for ensuring secure authentication through the GP Cloud service. When using the custom portal name method, distributing the SAML certificate to the client ensures that the connection between the user and the GP Cloud service is encrypted and authenticated properly. Reference Document: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000008U48CAE
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!