An authentication profile defines the authentication
service that validates the login credentials of administrators who
access the firewall web interface and end users who access applications
through Authentication Portal or GlobalProtect. The service can
be
Local
Authentication that the firewall provides or
External
Authentication Services. The authentication profile also
defines options such as
Kerberos single
sign-on (SSO).
Some networks have multiple databases (such as TACACS+ and LDAP) for different users and user
groups. To authenticate users in such cases, configure an
authentication
sequence—a ranked order of authentication profiles that the firewall
matches a user against during login. By default, the firewall checks against each
profile in sequence until one successfully authenticates the user and a user is
denied access only if authentication fails for all the profiles in the sequence. The
sequence can specify authentication profiles that are based on any authentication
service that the firewall supports excepts
Multi-Factor
Authentication (MFA) and
SAML.