
p8st0 (p8st0) asked a question.
Hello all...
Testing and researching various products to add a 2nd factor to our Palo global protect clients. I don't see anywhere in the Octa documentation where their service or agent connects to AD\LDAP for a 1st factor. Tested both DUO and Login TC, and their proxies\agents connect to your on-prem AD...and you can scope AD groups that you want to trigger the 2nd Radius factor. Am I missing something or is this the intended configuration? I realize you can scope your auth profile allow list on the Palo to specific groups...and I suppose this does suffice. Just curious if I am indeed missing something. Have not started a trial just yet - only reading\researching. Thanks in advance for any help.
Dennis

Hello @p8st0 (p8st0)
Thanks for posting.
In the following diagram you will find the Okta Radius flow.
First of all, the AD/LDAP integration must be configured before starting the VPN Radius process and the steps go like this:
First factor will always be username/password, and after authentication the chosen MFA factor will be displayed, as you mentioned based on the groups you choose to receive the challenge.
Palo Alto VPN configuration via Radius:
https://help.okta.com/en/prod/Content/Topics/integrations/palo-alto-radius-intg.htm?Highlight=globalprotect
Palo Alto Networks supported features and factors
https://help.okta.com/oie/en-us/Content/Topics/integrations/palo-alto-radius-intg-support.htm
Let us know if this helps you.
Daniela Chavarria.
Okta Inc.
Great Daniela ! Appreciate that. So there is indeed a separate AD integration piece, correct? That's the part I was missing.
https://help.okta.com/en/prod/Content/Topics/Directory/ad-agent-get-started.htm