- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-26-2024 05:09 AM - edited 11-26-2024 05:11 AM
Hi Support,
I am trying to configure Globalprotect with Azure Saml integration.
The authentication part is configured following the link ( https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000008U48CAE).
Additionally usergroup in Azure are configured with the attribute "group" and is mapped to each usergroup name.
Saml authentication profile in PA firewall contains the user group attribute name as "group" (matching the usergroup attribute from Azure).
Now the question here is , do i need to create multiple Saml authentication profiles like one for the GP Portal authentication which contains the Allow list as "all",
And one each for every user group with their respective Asserted Azure user group name in Allow list. which can be called in GP Gateway authentication configuration to map the usergroup with their vpn pool and other settings.
Regards,