---
title: "Active Directory Authentication"
slug: "active-directory-authenticationdoc"
updated: 2023-10-24T14:02:23Z
published: 2023-10-24T14:02:23Z
canonical: "kb.expedient.com/active-directory-authenticationdoc"
stale: true
---

> ## Documentation Index
> Fetch the complete documentation index at: https://kb.expedient.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Active Directory Authentication

## Overview

Expedient offers clients 2-factor authentication (2FA) to Expedient Secure User VPN with OneLogin as an identity provider. If preferred, a client can substitute OneLogin with alternative authentication options, including integrating an existing external solution like Active Directory. However, If a client chooses to use an alternative authentication option, it is the client's responsibility to manage that solution. While Expedient may not manage these alternative solutions, Expedient provides this documentation to assist clients with getting started on integrating their active directory with the Expedient Secure User VPN.

### Prerequisites

The steps described in this document assume that the client has set up external authentication prerequisites and understands what protocol they should utilize to communicate with that service.

### Process

Integrating an external authentication solution with the Expedient Secure User VPN, backed by Palo Alto Networks Global Protect, follows the same outline regardless of the solution.

Navigate to firewall UI after successfully authenticating into fw.expedient.cloud.

Create a server profile

**Device** > **Server Profiles >** select server type > **+Add**

In our example, we're utilizing RADIUS

![](https://cdn.document360.io/69e9f9c7-5da8-45e7-a671-4b8287f36122/Images/Documentation/active-directory-authentication.doc-image-7pa3cq9w.png)

Create authentication profile utilizing server profile

**Device** > **Authentication Profile** > **+Add**

**![](https://cdn.document360.io/69e9f9c7-5da8-45e7-a671-4b8287f36122/Images/Documentation/active-directory-authentication.doc-image-h0ixny0v.png)**

Access global protect portal & gateway configuration tabs and create client profiles pointing to the authentication profile.

**Network** > **GlobalProtect** > **Portals >** Select Portal > **Authentication** > **Client Authentication** > **+Add**

**![](https://cdn.document360.io/69e9f9c7-5da8-45e7-a671-4b8287f36122/Images/Documentation/active-directory-authentication.doc-image-t1cezrh9.png)**

**Network > GlobalProtect > Gateways >** Select Gateway **> Authentication > Client Authentication > +Add**

Perform a firewall commit operation.

![](https://cdn.document360.io/69e9f9c7-5da8-45e7-a671-4b8287f36122/Images/Documentation/active-directory-authentication.doc-image-1j8ffvrb.png)

Please refer to the following Palo Alto Networks document for additional help configuring external authentication for Expedient Secure User VPN.

[Configure External Authentication for Expedient Secure User VPN](https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-user-authentication/set-up-external-authentication)
