How Do I Configure Separate Global Protect Authentication Profiles for macOS and Windows Users in Strata Cloud Manager?

How Do I Configure Separate Global Protect Authentication Profiles for macOS and Windows Users in Strata Cloud Manager?

2265
Created On 03/01/25 01:14 AM - Last Modified 05/22/25 21:33 PM


Question


How do I configure separate Global Protect authentication profiles for macOS and Windows users in Strata Cloud Manager?



Environment


  • Prisma Access
  • Strata Cloud Manager


Answer


  1. Begin by configuring GlobalProtect Mobile Users following the instructions in this document.
  2. Once the initial setup is complete, navigate to Manage > Configuration > NGFW and Prisma Access > Identity Services > Authentication and configure distinct authentication profiles for each operating system. The supported authentication methods are detailed here.
  3. Proceed to Workflows > Prisma Access Setup > GlobalProtect > Infrastructure > User Authentication > Add Authentication.
  4. Within this section, configure user authentication settings for each operating system.
  5. The key differentiating factor is the operating system selection in the Authenticate Users From section, specify the appropriate Authentication Method and the corresponding Authentication Profile created in the previous step.
  6. For enhanced security, you can select certificate-based authentication, and select whether users must authenticate with a client certificate, the authentication profile, or both.

    Example: In the following scenario, Windows users authenticate with SAML, while macOS users authenticate with the Cloud Identity Engine. 



    Actions
    • Print
    • Copy Link

      https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000sdSqCAI&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail