An administrator needs to onboard new mobile users into Prisma Access using a SAML Identity Provider (IdP). Where in Panorama are the SAML authentication settings configured for GlobalProtect mobile users?
Trap 1: Panorama -> Cloud Services -> Setup -> SAML
This menu path does not exist; SAML profiles follow standard PAN-OS object configuration paths.
Trap 2: Network -> GlobalProtect -> Portals -> Authentication
GlobalProtect portals reference Authentication Profiles, but the profile objects themselves are defined under Objects -> Authentication.
Trap 3: Policies -> Authentication
Authentication policies enforce MFA or secondary logins based on rules, but do not define the IdP SAML server connection.
- A
Panorama -> Cloud Services -> Setup -> SAML
Why wrong: This menu path does not exist; SAML profiles follow standard PAN-OS object configuration paths.
- B
Network -> GlobalProtect -> Portals -> Authentication
Why wrong: GlobalProtect portals reference Authentication Profiles, but the profile objects themselves are defined under Objects -> Authentication.
- C
Policies -> Authentication
Why wrong: Authentication policies enforce MFA or secondary logins based on rules, but do not define the IdP SAML server connection.
- D
Objects -> Authentication
Authentication profiles referencing SAML Server Profiles are created under Objects -> Authentication and assigned to the GlobalProtect gateway configuration.