MFA Vendor Support

For the following authentication use cases, Palo Alto Networks® appliances can integrate with multi-factor authentication (MFA) vendors using RADIUS and, in PAN-OS® 8.0, using SAML:
  • Remote user authentication through the GlobalProtect™ portals and gateways.
  • Administrator authentication in the PAN-OS and Panorama™ web interface.
  • Authentication through the Captive Portal policy (PAN-OS 7.1 and earlier releases) and Authentication policy (PAN-OS 8.0 and later releases).
Additionally, firewalls running a PAN-OS 8.0 or later release can also integrate with the following MFA vendors using the API to enforce MFA through Authentication policy.
Palo Alto Networks provides support for MFA vendors through Applications content updates. This means that if you use Panorama to push device group configurations to firewalls, you must install the same Applications release version on the firewalls as on Panorama to avoid mismatches in vendor support.
MFA VendorMinimum Content Release Version
Duo v2
Okta Adaptive
RSA SecurID Access

Related Documentation