
User17537036255375776738 (Customer) asked a question.
Hi,
we are using Okta as the SAML IdP for GlobalProtect VPN (Palo Alto Networks firewall).
We have a situation where the same users exist in both GlobalProtect and Okta (e.g., user Antonio and user Paolo).
When the user opens the GlobalProtect VPN client and enters the username "Antonio", the SAML authentication flow is triggered and redirected to Okta as expected.
However, if the user authenticates on the Okta page with Paolo's credentials (email, password, and OTP), the SAML assertion is accepted, and the VPN connection is established under Paolo’s identity, even though "Antonio" was originally typed into the VPN client.

The IdP redirect does not maintain the user identification from the VPN client. Essentially the VPN client is just identifying the user, and is redirecting to Okta for authentication. Okta also needs to identify the user.
This is typical for all federation use cases.