Deploy machine certificates to GlobalProtect endpoints for authentication by using a
public-key infrastructure (PKI) to issue and distribute machine certificates to each
endpoint or generating a self-signed machine certificate. Configure an authentication
profile to authenticate the user and follow a workflow to create and deploy the client
certificate to the endpoint.
| Where Can I Use This? | What Do I Need? |
- NGFW (managed by Panorama or Strata Cloud Manager)
- Prisma Access (managed by Panorama or Strata Cloud
Manager)
|
- GlobalProtect Gateway license or Prisma Access license with
the Mobile User subscription
|
To confirm that the endpoint belongs to your organization, use your own public-key
infrastructure (PKI) to issue and distribute machine certificates to each endpoint
(recommended) or generate a self-signed machine certificate for export. With the
pre-logon connect methods, a machine certificate is required and must be installed
on the endpoint before GlobalProtect components grant access.
To confirm that the endpoint belongs to your organization, you must also configure an
authentication profile to authenticate the user (see
Two-Factor
Authentication).