Palo Alto SAML user group attribute for VPN filtering/policy enforcement Skip to main content
https://support.okta.com/help/answers?id=9060z00000078jzqay&refurl=http%3a%2f%2fsupport.okta.com%2fhelp%2fanswers
How satisfied are you with the Okta Help Center?
Thank you for your feedback!
How satisfied are you with the Okta Help Center?
1
2
3
4
5
Very Dissatisfied
Very satisfied
Enter content less than 200 characters.
Ask Search:
Yolanda LiuYolanda Liu 

Palo Alto SAML user group attribute for VPN filtering/policy enforcement

Where can I find instructions for how to use OKTA group assignment information passed through SAML authentication to enforce Palo Alto Global Protect VPN filtering or policy enforcement?
 
Stefan PescaruStefan Pescaru (Okta, Inc.)
Hello,

The way I would see the group membership being passed towards the SP would be via the Group Attribute Statements available in the SAML Settings section of the General tab of the app, within your Okta Admin Dashboard.
Due to the complexity and the variables of the setup, if this is not something you are familiar with, I would recommend opening a Support Ticket with us, and me or my colleagues would be more than glad to assist you!

Thank You,

Stefan Pescaru
Technical Support Engineer
Okta Global Customer Care