How to configure MDM attributes as HIP objects for GlobalProtect using Microsoft Intune with iOS devices

How to configure MDM attributes as HIP objects for GlobalProtect using Microsoft Intune with iOS devices

31614
Created On 07/23/23 21:08 PM - Last Modified 02/05/25 16:07 PM


Objective


  • This document will explain how to configure MDM attributes as HIP objects for GlobalProtect using Microsoft Intune with iOS devices


Environment


  • Existing GlobalProtect infrastructure
  • IOS devices managed by the Microsoft Intune MDM
  • MDM attributes used for HIP-Based Policy Enforcement


Procedure


Microsoft Intune configuration:

1. Navigate to Devices → Configuration Profiles. Select the appropriate Profile and click “Edit” next to “Configuration settings”. Note: The profile must be a "iOS/iPadOS” “VPN Template” profile. Ensure the connection type is “Custom VPN”

screenshot for configuration profile

2.  Enter the tags under “Base VPN” and click 'Review + save'
 
screenshot of tag configuration

When you integrate your GlobalProtect deployment with the Microsoft Intune MDM system, the GlobalProtect app for iOS devices can obtain the following data attributes: tagcompliance, and ownership are the keys. The keys are case-sensitive (must be lower-case), and the value can be set as anything
  • tag—Tags to enable you to match against other attributes
  • compliance —Compliance status to indicate whether the iOS device is compliant
  • ownership—Ownership category of the iOS device (for example, Employee Owned)
3. For Per-App configuration, click "Automatic VPN" and select "Provider Type" as "packet-tunnel" and click 'Review + save'
 
 
4. Click "Save"
 
screenshot of vpn config


 Firewall configuration:

  1. Create the HIP object under “Mobile Device” → “Tag” and set HIP objects checking for the values you assigned in Microsoft Intune

      screenshot hip object

     
       2. Configure a HIP profile using the HIP object configured in step # 1

  screenshot of hip profile
   
        3.  HIP reports for the devices with the MDM VPN profile will include the tags

    Screenshot hip report
 


Additional Information





 


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000kIMDCA2&lang=en_US%E2%80%A9&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language