Limitations for SAML SSO
Review these limitations when using SAML SSO authentication:
General limitations
-
Do not provide SAML authentication attributes in a DAP evaluation similar to RADIUS attributes sent in a RADIUS authentication response from a AAA server. Although the Firewall Threat Defense device supports SAML-enabled group policy in a DAP policy, you cannot check the username attribute during SAML authentication because the SAML IdP masks it.
-
Duo does not work with internal SAML deployments on the Firewall Threat Defense device if client authentication requires proxying due to FQDN changes during two-factor authentication challenges and responses.
-
You cannot access internal servers with SSO after logging in using an internal IdP.
-
Firewall Threat Defense device does not support receiving multiple attributes with a SAML assertion.
Secure Client limitations
-
A Firewall Threat Defense device does not support embedded browser SAML integration in CLI or Start Before Logon (SBL) modes.
-
SAML SSO in Cloud-Delivered Firewall Management Center does not support Start Before Logon (SBL) mode.