|
Item |
Details |
|
|---|---|---|
|
Prerequisites |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on how to configure custom attributes, see here |
||
|
SP-side Settings |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
API-based provisioning support (accounts can be managed via TrustLogin) |
|
|
SAML JITprovisioning support (accounts can be managed via TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
|
IdP-Initiated SSO |
|
|
Verified Operation Status by Device |
〇 |
PC - Browser |
|
〇 |
PC - Desktop App |
|
|
|
iOS - Standard Browser (Safari) |
|
|
|
iOS - TrustLogin Mobile App Internal Browser |
|
|
〇 |
iOS - Native App |
|
|
|
Android - Standard Browser (Chrome) |
|
|
|
Android - TrustLogin Mobile App Internal Browser |
|
|
〇 |
Android - Native App |
|
Obtain SAML Configuration Information from Prisma Access
Obtain the following information from Prisma Access.
Note: Since Prisma Access has two SPs, the GP Portal and the GP Gateway, you need to obtain the SAML information for each of them.
| Entity ID |
◆ GP Portal |
| ACS URL to Service |
◆ GP Portal |
| Logout URL |
◆ GP Portal |
[How to Check the FQDN of the GP Portal and GP Gateway]
- Open the settings management screen (Panorama WebUI), and from the [PANORAMA] tab, select [Cloud Service]>[Status].
- [Network Details] tab, select [Mobile Users - GlobalProtect].
-
Confirm the FQDN displayed on the Portal and Gateway.
TrustLogin Admin Page Settings
-
[Register the SAML App for the GP Portal]
Log in to TrustLogin, open the “Admin Page > Apps” menu, and click the “Register App” button in the upper right of the screen.
- On the “Register Corporate App” screen, search for and select “Prisma Access (GP Portal) (SAML)”.
- Download the metadata from “Download Metadata” under “Identity Provider Information”.
- In the three blank fields under “Service Provider Settings,” enter the “GP Portal FQDN” obtained from Prisma Access.
- Click the “Register” button to save.
-
[Register the SAML App for the GP Gateway]
Next, register the SAML app for the GP Gateway in the same way. Return to the “Admin Page > Apps” menu and click the “Register App” button in the upper right of the screen.
- On the “Register Corporate App” screen, search for and select “Prisma Access (GP Gateway) (SAML)”.
- Download the metadata from “Download Metadata” under “Identity Provider Information”.
- In the three blank fields under “Service Provider Settings,” enter the “GP Gateway FQDN” obtained from Prisma Access. If there are multiple GP Gateway FQDNs, use the preferred FQDN for the Entity ID and Logout URL, and configure the ACS URL for each FQDN.
Note: If there are three or more FQDNs, Register a Custom SAML App for instructions.
- Click the “Register” button to save.
TrustLogin User Settings
① When a User Adds the App from My Page
- Click the “Add App” button on “My Page.”
- On the “Register App” screen, select “Prisma Access (GP Portal) (SAML)” and click the “Next” button in the upper right of the screen.
- If you want to change the “Display Name,” enter a new one, then click the “Register” button.
- Add “Prisma Access (GP Gateway) (SAML)” in the same way.
② When an Administrator Adds a Member
- In the “Admin Page > Apps” menu, search for and click the “Prisma Access (GP Portal) (SAML)” app.
- Click “Add Member,” select the user to add from the member list, then click the “Register” button to add them.
- Add “Prisma Access (GP Gateway) (SAML)” in the same way.
Prisma Access Settings
Add SAML IdP
- Open the settings management screen, and from the [DEVICE] tab, select the template: [Mobile_User_Template].
- [Server Profile]>[SAML Identity Provider], select this, then click [Import].
-
SAML IdP import screen: enter a profile name (any name is fine), click [Browse...], then specify the metadata (xml file) obtained from TrustLogin, [Verify Identity Provider Certificate]: turn this off, then click [OK].
-
Click the profile name added in step 3 (GP Portal).
-
SAML IdP server profile screen: change [Identity Provider SLO URL] to the following, then click [OK].
https://portal.trustlogin.com/users/sign_out
- [DEVICE] tab, select the template: [Mobile_User_Template].
-
[Certificate Management]>[Certificates]: select this, then check the [Device Certificates] tab to confirm that a device certificate for GP Portal IdP has been created.(Name: crt.(GP Portal IdP Profile Name).shared)
- Following the same steps, also add the SAML IdP for the GP Gateway.
Add Authentication Profile
- [DEVICE] tab, select the template: [Mobile_User_Template].
-
[Authentication Profile]: select this, then click [Add].
-
On the Authentication Profile screen, enter a name; on the [Authentication] tab, set the Type to [SAML], and configure any other required information.
-
[Advanced] tab: click [Add] in the Allow List and select “all”, then click [OK].
- Following the same steps, also add the authentication profile for the GP Gateway.
Configure SAML Authentication (GP Portal)
- [NETWORK] tab, select the template: [Mobile_User_Template].
- [GlobalProtect] > [Portals]: select this, then click GP Portal (GlobalProtect_Portal).
- GlobalProtect Portal settings screen: click the [Authentication] tab, then click [Add] under Client Authentication.
-
On the Client Authentication screen, enter a name, select the authentication profile, then click [OK].
-
GlobalProtect Portal settings screen: take the SAML authentication setting created in step 4 on the previous page and click [Move Up], moving it to the top of Client Authentication.
-
GlobalProtect Portal settings screen: click the [Agent] tab: from the agent list, select “FENICS-DEFAULT” then click [Copy].
-
On the [Authentication] tab of the settings screen, enter [Name], confirm that each Authentication Override setting is unchecked, then click [OK].
-
GlobalProtect Portal settings screen: take the SAML authentication agent setting created in step 7 on the previous page and click [Move Up], moving it to the top of the agent list, then click [OK].
-
【Note】GP Portal agent settings: for iOS SAML authentication, the GP Client’s connection method “Pre-logon” and “User-logon” are not supported.
-
iOS: create a dedicated agent setting separate from the common OS setting for iOS (iOS-specific)), and set GP Client’s connection method to “On-Demand.”iOS agent setting: when using this, be sure to move it, from the list of agent settings, above the “OS: any” agent setting.
-
【Note] Choosing the Web Browser for SAML AuthenticationFor SAML authentication performed by GlobalProtect, using the default browser is recommended.

It can be difficult to explicitly clear cookies retained by the built-in browser. As a result, if a valid session remains with the SAML IdP at the time of a second authentication, the connection may complete without going through the authentication screen. If you want to force the authentication screen to be displayed again, you will need to wait for the session to expire, restart the client, or delete the session on the SAML IdP side.
For more information, please refer to the following.
Note 1: Choosing the Web Browser for SAML Authentication (paloaltonetworks.com)
-
【Note】GP Portal agent settings: for iOS SAML authentication, the GP Client’s connection method “Pre-logon” and “User-logon” are not supported.
Configure SAML Authentication (GP Gateway)
- [NETWORK] tab, select the template: [Mobile_User_Template].
-
[GlobalProtect] > [Gateways]: select this, then click GP Gateway (GlobalProtect_External_Gateway).
- GlobalProtect Gateway settings screen: click the [Authentication] tab, then click [Add] under Client Authentication.
-
On the Client Authentication screen, enter a name, select the authentication profile, then click [OK].
-
GlobalProtect Gateway settings screen: take the SAML authentication setting created in step 4 on the previous page and click [Move Up], moving it to the top of Client Authentication.
-
GlobalProtect Gateway settings screen: click the [Agent] tab, then on the [Client Configuration] tab, from the agent list, select “FENICS-DEFAULT” and click [Copy].
-
On the [Configuration Selection Criteria] tab of the settings screen, enter [Name].
-
On the [Authentication Override] tab of the settings screen, confirm that each setting is unchecked, then click [OK].
-
GlobalProtect Gateway settings screen: take the settings created in steps 7 and 8 on the previous page (the SAML authentication agent settings), and click [Move Up] to move them to the top of the agent list, then click [OK].