cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who Me Too'd this topic

GlobalProtect Azure Saml user/group attribute Mapping

L1 Bithead

Hi Support,

 

 

I am trying to configure Globalprotect with Azure Saml integration.

The authentication part is configured following the link ( https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000008U48CAE).

 

Additionally usergroup in Azure are configured with the attribute "group"  and is mapped to each usergroup name.

 

Saml authentication profile in PA firewall contains the user group attribute name as "group" (matching the usergroup attribute from Azure).

 

Now the question here is , do i need to create multiple Saml authentication profiles like one for the GP Portal authentication which contains the Allow list as "all",

 

And one each for every user group with their respective Asserted Azure user group name in Allow list. which can be called in GP Gateway authentication configuration to map the usergroup with their vpn pool and other settings.

 

 

Regards,

 

Who Me Too'd this topic