Learn how to authenticate users using SAML.
On-Premises Controller for Prisma SD-WAN supports SAML-based authentication to users
using the Operator’s console. When a non-local user tries to log in to the
Operator’s console, the user is directed to an Identity Provider (IdP) such as
Okta/Ping, where the IdP authenticates the user and then redirects the user to the
Operator’s console login page. After the redirect, the user can log in using the
provided email ID to access the console. After a non-local user logs in, the user is
auto-populated in User Management as a non-local user.
To initiate metadata exchange between controller and IdP: