question

RafaelD21 avatar image
0 Votes"
RafaelD21 asked vipulsparsh-MSFT answered

GlobalProtect SSO does not work, seperate MFA prompts for M365 and GlobalProtect

Dear all,

I am doing some testing on Notebooks (Win10, hybrid-joined) that run GlobalProtect and M365 Apps for Enterprise. We have tested them with different Conditional Access Policies, yet there are always separate MFA requests for M365 and GlobalProtect, so I have to assume GP does not access the Primary Refresh Token.
GlobalProtect was configured according to Palo Alto recommendations and SAML SSO enabled.
a) is that behaviour expected? Some personnel of the service provider claimed, as GP didnt support OpenAuth/Openid, this was to be expected.
b) in the latter case, is there a work around?
Thanks so much!

azure-ad-saml-sso
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

vipulsparsh-MSFT avatar image
0 Votes"
vipulsparsh-MSFT answered

@RafaelD-5678 Thanks for reaching out and apologies for delay on this. Can you point to the step by step setup you followed for this ?
Did you follow : https://docs.microsoft.com/en-us/azure/active-directory/saas-apps/palo-alto-networks-globalprotect-tutorial or something else ?


If you have setup the SSO correctly, you should not be having multiple MFA prompts, https://docs.microsoft.com/en-us/azure/active-directory/saas-apps/palo-alto-networks-globalprotect-tutorial#configure-azure-ad-sso

You can share us a user information through which We can try to identify and understand why the multiple prompts. You can email us at azcommunity@microsoft.com with subject "Atten-Vipul" and we can get back to you for further details.



Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.




5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.