This application has not been formally tested by Kelvin Zero Inc. It is provided solely as a reference guide. If you encounter any issues, kindly submit a ticket directly through the support desk.
This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Palo Alto Next-Gen Firewalls V11.x using Multi-Pass. SSO simplifies user authentication by allowing access to multiple applications with a single set of credentials. This integration enhances security and improves user experience across your organization.
To configure Multi-Pass SSO with Palo Alto Firewalls, ensure you meet the following requirements:
- Palo Alto Firewall Administrator access
- MPAS Admin rights
- All users intended to use SSO in Palo Alto must be registered in your IdP and have the necessary permissions.
Important: Custom elements in URLs (like IP addresses or tenant names) are case sensitive. Match the exact casing from your environment.
Palo Alto Next-Gen Firewalls V11.x - SSO Configuration
- Open Multi-Pass Dashboard
- Select the correct tenant and go to Integrations, then click on Applications.
- Select SAML under the custom integration section.
- Select Download under Tenant XML Data and save the file locally.
- Log into the Palo Alto Firewall as an Administrator.
- Navigate to Device > Server Profiles > SAML Identity Provider > Import.
- If unavailable, browse to Panorama > Server Profiles > SAML Identity Provider.
- Set the Profile Name to KZero Passwordless.
- Select Browse and upload the Tenant Metadata file from Step 1.
- Ensure all fields populate correctly, unselect Validate Identity Provider Certificate, then click OK.
- Go to Device > Authentication Profile and select Add.
- Set the Name to KZero Passwordless and Authentication Type to SAML.
- Select the SAML IDP Server Profile named KZero Passwordless.
- Set the Username Attribute to
username. - Under the Advanced tab, select Allow List and include all users or specific groups as required.
- Click OK to save the profile.
Step 3 - Complete the Configuration of Multi-Pass (IdP)
- Open Multi-Pass Dashboard
- Select the correct tenant and go to Integrations, then click on Applications.
- Select SAML in the custom integration section.
- Confirm or complete the remaining fields based on the table below:
- Go to the Advanced Console by clicking on the left side of your screen
- Click on Client and use the search bar to look for Palo Alto
- Ensure all the fields are populated based on the tables below
General settings (Multi-Pass)
Access settings (Multi-Pass)
SAML Capabilities
| Setting |
Value |
| Name ID Format | username |
| Force Name ID Format | OFF |
| Force POST Binding | ON |
| Include AuthnStatement | ON |
Signature & Encryption