Azure RADIUS MFA Not Prompting for Text Code for GlobalProtect

Azure RADIUS MFA Not Prompting for Text Code for GlobalProtect

11764
Created On 02/13/19 15:44 PM - Last Modified 07/26/21 19:00 PM


Symptom


  • GlobalProtect Authentication set to RADIUS
  • RADIUS Server Authentication Protocol PEAP-MSCHAPv2
  • Azure RADIUS MFA configured with Text Message
  • After entering username/password for GlobalProtect second authentication prompt for "Enter PIN code" never popped up.  
  • The authd.log in CLI shows ""Auth FAILED"
>less mp-log authd.log

Auth FAILED for user "testuser" thru <"Radius_Authentication", "vsys1">: remote server 10.0.0.10 of server profile "Radius" is down, or in retry interval, or request timed out (elapsed time 55 secs, max allowed 55 secs)
  • Text Message MFA option requires Azure Radius server to send authentication challenge to the firewall relaying to the GP client. In firewall authd.log, we did not see any indication of receiving RADIUS challenge to pass down to client. 


Environment


  • PAN-OS 8.1.3
  • GlobalProtect
  • RADIUS Authentication using PEAP-MSCHAPv2
  • Azure MFA via Text message


Cause


  • one-way text message is not supported for CHAPV2 and EAP for Azure AD Multi-Factor



Resolution


Use a supported Azure AD Multi-Factor based on the protocol used
  • PAP supports all the authentication methods of Azure AD Multi-Factor Authentication in the cloud: phone call, one-way text message, mobile app notification, OATH hardware tokens, and mobile app verification code.
  • CHAPV2 and EAP support phone call and mobile app notification.

Integrate your existing Network Policy Server (NPS) infrastructure with Azure AD Multi-Factor Authentication


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cmp7CAC&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language