As soon as I realized what this was, I closed everything up andstarted looking for an exterminator who could help me out. Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type. In the SAML Identify Provider Server Profile Import window, do the following: a. The Source Attribute value, shown above as customadmin, should be the same value as the Admin Role Profile Name, which is configured in step 9 of the the Configure Palo Alto Networks - Admin UI SSO section. url. https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/authentication/configure-saml-authentication. There are three ways to know the supported patterns for the application: Configuring the 'Identity Provider Certificate' is an essential part of a secure SAML authentication configuration. must be a Super Admin to set or change the authentication settings Configure Kerberos Single Sign-On. If the web interfaces are only accessible to a restricted management network, then the issue is lowered to a CVSS Base Score of 9.6 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). can use their enterprise credentials to access the service. When you click the Palo Alto Networks - Admin UI tile in the My Apps, you should be automatically signed in to the Palo Alto Networks - Admin UI for which you set up the SSO. XSOAR - for an environment of 26 Palo Alto Firewalls + 4 PANORAMA - is it worth it? ACC Network Activity Source/Destination Regions (Leveraging the Global Filter feature), GlobalProtect Logs (PAN-OS 9.1.0 and above). https://