Use the Cloud Authentication (CAS) component of the Cloud Identity Engine to
authenticate Prisma Access mobile users in a Mobile Users—GlobalProtect deployment.
This functionality is only available for Panorama Managed Prisma Access 3.0
Innovation and later Innovation deployments.
The Cloud Identity Engine has two components to provide authentication and
enforcement of user- and group-based policy:
To configure the Cloud Authentication Service to authenticate GlobalProtect mobile
users, you must have the following minimum required product and software versions:
A minimum Prisma Access version of 3.0 Innovation or a later Innovation
version, which requires a dataplane version of 10.1.
To verify your dataplane version, select and view the Current Dataplane version
in the DataPlane PAN-OS version area.
If your dataplane is running 10.1, you are running the Prisma Access 3.0
Innovation or later Innovation release and can use the Cloud Identity Engine
to authenticate GlobalProtect mobile users. If your dataplane is running
10.0, you are running a Prisma Access Preferred release and you cannot
authenticate mobile users with the Cloud Identity Engine.
A minimum GlobalProtect app version of 6.0.
A SAML IdP provider that is supported with the Cloud Identity Engine.
A minimum Panorama version of 10.1.
To configure authentication for a mobile users using the Cloud Authentication Engine,
complete the following steps.