Authentication Changes

PAN-OS® 8.0 has the following changes in default behavior for authentication features:
Feature
Change
Hardware security modules
(PAN-OS 8.0.2 and later releases) To downgrade to a release earlier than PAN-OS 8.0.2, you must ensure that the master key is stored locally on Panorama or on the firewall, not on a hardware security module (HSM).
Authentication policy
Authentication policy replaces Captive Portal policy.
Logging
When an authentication event invokes a policy rule, the firewall now generates Authentication logs instead of System logs.
RADIUS and TACACS+
You now use the web interface instead of a CLI command to set the authentication protocol to CHAP or PAP for TACACS+ and RADIUS server profiles.

Related Documentation