Configure User Authentication for Migration (Panorama)
Focus
Focus
Prisma Agent

Configure User Authentication for Migration (Panorama)

Table of Contents

Configure User Authentication for Migration (Panorama)

Set up Cloud Identity Engine SAML 2.0 authentication for the Prisma Agent on a Panorama-managed tenant.
The first time a user connects to the Prisma Agent app, they are prompted to authenticate to the Endpoint Manager. Upon successful authentication, the agent receives configuration and authentication tokens for connection to gateways as well as communication between various Prisma Agent components.
Prisma Agent supports SAML 2.0 authentication via Cloud Identity Engine.
For more information on authentication types and support, see Set Up Prisma Agent User Authentication.
Configure Cloud Identity Engine
Before configuring user authentication, set up the authentication profile using SAML 2.0 via identity providers (IdPs) in Cloud Identity Engine.
For a commit to succeed, you must configure User Authentication after you enable the Prisma Agent.
  1. Select ConfigurationPrisma Access AgentSettingsPrisma Access Agent.
  2. Click Add User Authentication.
  3. Select Authentication MethodCloud Identity Engine and Authentication TypeSAML,
  4. Select Create New for Authentication Profile.
  5. Enter a Profile Name, select the Authentication Profile created in Cloud Identity Engine, and Save your authentication profile settings.
  6. Select the Authentication Profile you created in the previous step and click Save to complete the configuration.
    If your GlobalProtect deployment uses Client Certificate AND SAML authentication:
    1. Configure the Client Certificate in Cloud Identity Engine to be used as part of Prisma Agent configuration. This is required for coexistence of both GlobalProtect and Prisma Agent on the same Prisma Access Gateway. See Set Up a Client Certificate.
    2. In Strata Cloud Manager, select Authentication MethodCloud Identity Engine and Authentication TypeClient Certificate AND SAML.
    3. Select the respective Certificate Profile and Authentication Profile from Cloud Identity Engine.
    User to group mapping will continue with the Cloud Identity Engine Directory as the only supported option for Panorama Managed Prisma Access tenants.