- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-17-2021 04:58 PM
As BPry mentioned, you should get a CA certificate for the GP portal and gateways.
In addition to that, you need to export the Microsoft Azure Federated SSO Certificate from the Azure Portal and import it to the firewall (Device -> Certificate Management -> Certificates).
The following KB shows how to set up Azure SAML authentication with GlobalProtect, but this export/import certificate step is missing.
How to setup Azure SAML authentication with GlobalProtect
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000008U48CAE
You may refer to this KB for the SAML IdP.
Identity Provider Configuration for SAML
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UXPCA2
Hope this helps!