Setting up SAML authentication for GlobalProtect users involves creating a server
profile, importing the SAML metadata file from the identity provider, and configuring the
authentication profile. GlobalProtect supports Remote Access VPN with Pre-Logon with SAML
authentication beginning with GlobalProtect app 5.0.
| Where Can I Use This? | What Do I Need? |
- NGFW (managed by Panorama or Strata Cloud Manager)
- Prisma Access (managed by Panorama or Strata Cloud
Manager)
|
- GlobalProtect Gateway license or Prisma Access license with
the Mobile User subscription
|
Security Assertion Markup Language (SAML)
is an XML-based, open-standard data format used to exchange authentication
and authorization data between parties, specifically between an
identity provider (IdP) and a service provider. SAML is a product
of the OASIS Security Services Technical Committee.
(Windows endpoints only; Requires
GlobalProtect app 6.3.3 and later; Supported only on GlobalProtect embedded
browser)Starting with GlobalProtect 6.3.3 release, you can enforce SAML
authentication to succeed only if the authorization request comes from trusted IP
addresses. Users that authenticate via untrusted IP addresses from unmanaged devices
are not allowed access to apps and other resources. In order for this to work, you
can specify either a proxy server or Proxy Auto-Configuration (PAC) file via the
predeployment parameter SAMLAUTHPROXY. For more information about the paraameter,
see.
App Behavior Options.