GlobalProtect SSO does not work, seperate MFA prompts for M365 and GlobalProtect

RafaelD 11 Reputation points
2022-01-25T11:07:40.613+00:00

Dear all,

I am doing some testing on Notebooks (Win10, hybrid-joined) that run GlobalProtect and M365 Apps for Enterprise. We have tested them with different Conditional Access Policies, yet there are always separate MFA requests for M365 and GlobalProtect, so I have to assume GP does not access the Primary Refresh Token.
GlobalProtect was configured according to Palo Alto recommendations and SAML SSO enabled.
a) is that behaviour expected? Some personnel of the service provider claimed, as GP didnt support OpenAuth/Openid, this was to be expected.
b) in the latter case, is there a work around?
Thanks so much!

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,067 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. VipulSparsh-MSFT 16,271 Reputation points Microsoft Employee
    2022-02-02T09:34:21.76+00:00

    @RafaelD-5678 Thanks for reaching out and apologies for delay on this. Can you point to the step by step setup you followed for this ?
    Did you follow : https://learn.microsoft.com/en-us/azure/active-directory/saas-apps/palo-alto-networks-globalprotect-tutorial or something else ?

    If you have setup the SSO correctly, you should not be having multiple MFA prompts, https://learn.microsoft.com/en-us/azure/active-directory/saas-apps/palo-alto-networks-globalprotect-tutorial#configure-azure-ad-sso

    You can share us a user information through which We can try to identify and understand why the multiple prompts. You can email us at azcommunity@microsoft.com with subject "Atten-Vipul" and we can get back to you for further details.

    -----------------------------------------------------------------------------------------------------------------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.