Authenticating GlobalProtect and Prisma Access remote access users against Office365 Azure AD

Опубликовано: 31 Март 2026
на канале: Consigas - Palo Alto Networks Training Channel
15,319
131

Palo Alto Networks Training @ www.consigas.com - FireWall Best Practices | Want to learn more? Our Palo Alto Networks Courses teach you how to master the Next-Generation FireWall.

Update 29.06.2020 - Mitigate SAML Bypass Vulnerability without an upgrade (CVE-2020-2021) - This video explains how to securely set up SAML authentication end-to-end against Office 365 Azure AD. The critical element which explains how to set up certificate validation of the SAML Identity Provider starts at 29:35. With this configuration, there is no immediate need to upgrade the FireWall, although an upgrade should always be considered. It also fixes the commit error "Validate Identity Provider Certificate is checked but no Certificate Profile is provided authentication-profile"

Being able to authenticate your GlobalProtect or Prisma Access remote workers against Office 365 is very convenient as it provides a seamless single sign-on experience to the user. Of course its great from a security point of view as well, because you can use the integrated dual-factor authentication that comes with Office 365.
But of course, in order to authenticate against Office 365, you cannot use classical protocols like LDAP or Radius, instead, you need SAML. Luckily, both Microsoft and Palo Alto Networks have made the integration very simple, and in this video, we will show you the configuration end-to-end with all the tips and tricks you need to know to make to work.

Follow us on:
➜ LinkedIn http://bit.ly/consigaslinkedin
➜ Twitter   / consigascom