To enable two-factor authentication using smart cards on GlobalProtect, import the
Root CA certificate onto the portal and gateway, create a certificate profile that includes
the Root CA, and assign the certificate profile to the portal or gateway configuration.
Verify the configuration by attempting to authenticate using a smart card.
If you want to enable your end users to authenticate using a smart card or common
access card (CAC), you must import the Root CA certificate that issued the
certificates contained on the CAC or smart cards onto the portal and gateway. You
can then create a certificate profile that includes that Root CA and apply it to
your portal and/or gateway configurations to enable use of the smart card in the
authentication process.
Two-factor authentication using smart cards is supported on macOS and Windows
endpoints.