Limitations for SAML SSO

Review these limitations when using SAML SSO authentication:

General limitations

  • Do not provide SAML authentication attributes in a DAP evaluation similar to RADIUS attributes sent in a RADIUS authentication response from a AAA server. Although the Firewall Threat Defense device supports SAML-enabled group policy in a DAP policy, you cannot check the username attribute during SAML authentication because the SAML IdP masks it.

  • Duo does not work with internal SAML deployments on the Firewall Threat Defense device if client authentication requires proxying due to FQDN changes during two-factor authentication challenges and responses.

  • You cannot access internal servers with SSO after logging in using an internal IdP.

  • Firewall Threat Defense device does not support receiving multiple attributes with a SAML assertion.

Secure Client limitations

  • A Firewall Threat Defense device does not support embedded browser SAML integration in CLI or Start Before Logon (SBL) modes.

  • SAML SSO in Cloud-Delivered Firewall Management Center does not support Start Before Logon (SBL) mode.