Specify the
Maximum Clock Skew (seconds), which is the
allowed difference in seconds between the system times of the IdP and the
firewall at the moment when the firewall validates IdP messages (default is 60;
range is 1–900). If the difference exceeds this value, authentication
fails.
If your IdP requires users to log in using multi-factor authentication (MFA),
select
Multi-factor Authentication is Enabled on the Identity
Provider.
If you enabled the
Force Re-authentication option in
step
1.9, enable the
Force Authentication option to require users to log
in with their credentials to reconnect to GlobalProtect.
Test SAML setup to verify the profile configuration.
This step is necessary to confirm that your firewall and IdP can
communicate.
Select the SAML attributes you want the firewall to use
for authentication and
Submit the IdP profile.
- In the Okta Admin Console, Edit the User
Attributes & Claims.
- In the Cloud Identity Engine, select the Username Attribute and
optionally, the Usergroup Attribute,
Access Domain, User
Domain, and Admin Role, then
Submit your changes.
You must select
the username attribute in the Okta Admin Console for the attribute
to display in the Cloud Identity Engine.