How to setup Azure SAML authentication with GlobalProtect
Created On 05/15/20 00:59 AM - Last Modified 09/11/22 09:14 AM
Step-by-step instruction on how to setup Azure SAML authentication for GlobalProtect portal and gateway.
GlobalProtect authentication with Azure SAML
Step 1. Login to Azure Portal and navigate Enterprise application under All services
Step 2. Search for Palo Alto and select Palo Alto Global Protect
Step 3.Click ADD to add the app
Step 4. After App is added successfully> Click on Single Sign-on
Step 5. Select SAML option:
Step 6. Edit Basic SAML configuration by clicking edit button
Step 7. Fill out Sign-on URL,Identifier (Entity ID) and Reply URL (Assertion Consumer Service URL) as follows
GlobalProtect portal FQDN/IP address could be located by login into the firewall ang going under Network> Portal> Select the portal> Agent> Select config>External > Select External Gateway> Use either FQDN or IP address ip
Identifier (Entity ID)
Reply URL (Assertion Consumer Service URL)
Or IP address:
Step 8. Download the Federation Metadata XML and save it on your computer( This will be imported into the firewall).
This conclude the config on Azure. Login to firewall and add SAML identity provider
Steps to configure SAML authentication to use it for GlobalProtect Portal and Gateway:
Follow this article to configure GlobalProtect Portal/gateway
SAML configuration steps:
Step 1. Login to firewall and Navigate to Device>SAML Identity provider >import
Step 2. Import the federed Metadata XML downloaded from Azure in step 8.
Option: Uncheck validate Identity Provider certificate. If checked, Certificate from Azure is needs to be uploaded on firewall as well.
Step 3. Create Authentication Profile and select SAML and IDP server Profile
Step 4. Click on Advanced tab and select "Allow list"
Step 5. Add authentication profile to GlobalProtect Portal
Step 6. Add authentication profile to GlobalProtect gateway config:
This concludes the configuration part.