Two Factor Authentication for Customer Support Portal (2024)

Two Factor Authentication (2FA) Overview

Two Factor Authentication (2FA) is required for users to log into Palo Alto Networks apps, such as Customer Support Portal (CSP). To increase your security posture, Domain Admins are no longer able administer 2FA for users in their account.

  • To learn how to login with a 2FA method, read Section Login To Customer Support Portal (CSP) .
  • To learn how to configure 2FA methods, read Section Configure 2FA Methods .
    • Note - To reach the Okta service, your DNS will need to resolve sso.paloaltonetworks.com

If you have problems logging in, please:

  1. Select Need Help on the SSO password page


Login To Customer Support Portal (CSP)

2FA Methods Depend on Your Account Type

If your account is FedRAMP (federal), single sign-on (SSO) supports the following 2FA methods:

  • Email
    • Okta validation email is generated in an AWS SES environment and your email server may block it as spam. If you don't receive the email or the link is no longer valid when you receive it, please have your email admin whitelist the below:
      • 23.249.212.62
        23.249.212.63
        23.249.212.64
        23.249.212.65
    • For additional Okta IP addresses please see https://support.okta.com/help/s/article/Allowlist-of-IP-Addresses-for-processing-email-delivery?language=en_US
      • Note: Okta recommends using the other MFA options for enhanced security.
      • Note: PANW currently does not have plans to implement the restriction of using Email as MFA form on account level (forcing the users to choose other MMFA forms).
  • Okta Verify

If your account is not FedRAMP, SSO supports the following 2FA methods:

  • Email
    • Okta validation email is generated in an AWS SES environment and your email server may block it as spam. If you don't receive the email or the link is no longer valid when you receive it, please have your email admin whitelist the below:
      • 23.249.212.62
        23.249.212.63
        23.249.212.64
        23.249.212.65
        • Note: Okta recommends using the other MFA options for enhanced security.
  • Okta Verify
  • Google Authenticator (can be used with any form of two factor authentication by scanning the QR code for your chosen application)

If you are unsure about your account type, ask your Domain Administrator.

Login to Customer Support Portal

To login to Customer Support Portal (CSP), click CSP login link (https://support.paloaltonetworks.com/). Then, enter your user ID.

Two Factor Authentication for Customer Support Portal (1)

Followed by your password.

Two Factor Authentication for Customer Support Portal (2)

The next step depends on the 2FA methods configured for your account.

2FA Methods

Email 2FA

If your account is configured for email 2FA, click Send me the code.

Two Factor Authentication for Customer Support Portal (3)

Check. your email. SSO sends you an email with a six-digit code. A sample email follows.

Two Factor Authentication for Customer Support Portal (4)

Enter the six-digit code, 324262 in this case to login.

Two Factor Authentication for Customer Support Portal (5)

Okta Verify 2FA

If your account is configured for Okta Verify 2FA, follow directions to verify your identity. Or, you can choose to push a notification to your Okta Verify mobile app. In the following illustration, the user set the option to always send a push automatically.

Two Factor Authentication for Customer Support Portal (6)

Open Okta Verify app on your phone, and tap on the number displayed above to login.

Google Authenticator 2FA

If your account is configured for Google Authenticator 2FA, go to Google Authenticator app on your phone to get a new six-digit code. Enter the code to login.

Two Factor Authentication for Customer Support Portal (7)

Note: Google Authenticatorcan be used with any form of two factor authentication by scanning the QR code for your chosen application.

If you have changed to another phone and would like to re-enroll your google authenticator, select Need Help on the SSO password page (logging in to the Support Portal is NOT required here to create a support case)

Multiple 2FA Methods

If your account is configured for multiple 2FA methods, you can decide which 2FA method to use during login. In the following sample illustration, CSP initially prompts for an Okta Verify code or push.

To change your 2FA method during login, click on the down arrow to select another 2FA method.

Two Factor Authentication for Customer Support Portal (8)

Two Factor Authentication for Customer Support Portal (9)

Configure 2FA Methods

Manage Account Settings

To manage your account settings, e.g., change password, set up 2FA, go to:

https://sso.paloaltonetworks.com/enduser/settings

IMPORTANT! Please use the link above to configure your 2FA settings. Configuring 2FA is no longer done in CSP My Profile. Your DNS will need to resolve sso.paloaltonetworks.com to reach the Okta service.

Two Factor Authentication for Customer Support Portal (10)

2FA Methods Depend on Your Account Type

If your account is FedRAMP (federal), single sign-on (SSO) supports the following 2FA methods:

  • Email
  • Okta Verify

If your account is not FedRAMP, SSO supports the following 2FA methods:

  • Email
  • Okta Verify
  • Google Authenticator

If you are unsure about your account type, ask your Domain Administrator.

Okta Verify

Okta Verify does not support multi-device authentication.
To configure Okta Verify as your 2FA method, click Set up button for Okta Verify.

Two Factor Authentication for Customer Support Portal (11)

Click Setup button to set up Okta Verify.

Two Factor Authentication for Customer Support Portal (12)

Select your phone type. And, download Okta Verify to your phone. Click Next button.

Two Factor Authentication for Customer Support Portal (13)

CSP displays a QR code. Use Okta Verify on your phone to scan the QR code.

Two Factor Authentication for Customer Support Portal (14)

On your phone, go to Okta Verify app, and click '+' icon. Choose Organization for account type, and clickYes, Ready to Scan button. Point your phone camera at the QR code. Okta Verify will scan the QR code, and add your account.

When you login next, CSP enables you to enter a six-digit code from Okta Verify app. Or, prompt Okta Verify to send a push; confirm your identity by clicking Yes, It's Me.

Google Authenticator

Google Authenticator supports multi-device authentication. See the details here .
Note: Google Authenticatorcan be used with any form of two factor authentication by following these instructions but downloading and scanning the QR code for your chosen application).
To configure Google Authenticator as your 2FA method, click Set up button for Google Authenticator.

Two Factor Authentication for Customer Support Portal (15)

Click Setup button to set up Google Authenticator for 2FA.

Two Factor Authentication for Customer Support Portal (16)

Select your phone type. And, download Google Authenticator to your phone. Click Next button.


Two Factor Authentication for Customer Support Portal (17)

CSP displays a QR code. Use Google Authenticator on your phone to scan the QR code.

Two Factor Authentication for Customer Support Portal (18)

Select Scan a QR code in Google Authenticator. Point your phone camera at the QR code. Google Authenticator will scan the QR code, and add your account. Click Next button.

To verify Google Authenticator is set up correctly, enter a new six-digit code from Google Authenticator.

Two Factor Authentication for Customer Support Portal (19)

When you login next, enter a six-digit code from Google Authenticator app.

If you have changed to another phone and would like to re-enroll your google authenticator, select Need Help on the SSO password page (logging in to the Support Portal is NOT required here to create a support case)

Email

Email is set up as your default 2FA. To remove email 2FA, click Remove button.

Two Factor Authentication for Customer Support Portal (20)

To confirm you want to disable email 2FA, click Yes button. Use the same procedure to configure all 2FA methods.

Two Factor Authentication for Customer Support Portal (21)

Getting an Error?
Two Factor Authentication for Customer Support Portal (22)
Confirm that these URLs are white listed:

  • https://sso.paloaltonetworks.com
  • https://sso.paloaltonetworks.com/.well-known/webfinger
    • Clear cache and cookies to see if issue is resolved.

NOTE: It is not possible to disable MFA for security reasons. We want to harden the way each user authenticates to our environment and align more closely with NIST guidance so that we can further improve our security posture.

Two Factor Authentication for Customer Support Portal (2024)

FAQs

How to solve two-factor authentication problem? ›

If you have already set up two-factor authentication and cannot access the authentication code on your mobile device, you will need to ask your user manager or administrator to contact our support team to reset your account security. You will need to set up your account security with a different mobile device.

How do I complete two-factor authentication? ›

Allow 2-Step Verification
  1. Open your Google Account.
  2. In the navigation panel, select Security.
  3. Under “How you sign in to Google,” select 2-Step Verification. Get started.
  4. Follow the on-screen steps.

Is two-factor authentication enough? ›

With 2FA in place, the likelihood of unauthorized individuals gaining access to user accounts is significantly reduced. This is particularly crucial for sensitive accounts such as financial or email accounts.

Why authentication failed when signing in using 2 step verification? ›

It may be because the time isn't correctly synced on your Google Authenticator app. On the next screen, the app confirms the time has been synced. You should be able to sign in. The sync will only affect the internal time of your Google Authenticator app, and will not change your device's Date & Time settings.

What to do if you can't access two-factor authentication? ›

If you have forgotten your password and you've lost access to your two-factor authentication credentials, you can start account recovery to regain access to your account. You'll need to verify your identity using a recovery authentication factor, such as an SSH key or previously verified device.

Why is my two-factor authentication failing? ›

Problems logging into your account

The most common cause of 2-factor authentication problems is that the time on your Google Authenticator app is not synced correctly.

How can I recover my two-factor authentication? ›

When you set up two-factor authentication (2FA) in your account using the Authenticator App method, you're prompted to download a backup key. This code lets you restore access to your account in case of changed or lost smartphone, or accidental deletion of the Authenticator App.

How do I opt out of two-factor authentication? ›

Turn off 2-Step Verification
  1. Open your device's Settings app and tap Google. Manage your Google Account.
  2. At the top, tap Security.
  3. Under "How you sign in to Google," tap 2-Step Verification. You might need to sign in.
  4. Tap Turn off.
  5. Confirm by tapping Turn off.

How to find two-factor authentication code? ›

If your device is online:
  1. Go to Settings > [your name].
  2. Tap Sign-In & Security > Two Factor Authentication.
  3. Tap Get Verification Code.
Apr 19, 2024

What is the difference between 2 factor authentication and 2 factor verification? ›

The key difference between 2-step verification vs. 2-factor authentication is that 2FA requires two independent forms of authentication from different categories. In contrast, 2SV only requires two pieces of information with no regard for whether they are from the same type of authentication category.

Can you beat two-factor authentication? ›

By sending codes to the person attempting to log in, the goal of 2FA is to authenticate users, but that doesn't mean it's an impervious cybersecurity layer. Threat actors understand that certain tactics allow them to bypass two-factor authentication, including SIM card swapping and browser cookie theft.

What is the strongest form of two-factor authentication? ›

FIDO U2F is the most secure form of 2FA that prevents against password cracking, man-in-the-middle, and phishing attacks. Learn more about FIDO U2F here.

Why is my two authentication not working? ›

Authenticator apps rely on the time set on your device to create the authentication code. If the time on your device does not match the time on your computer then the code will not work. Check the time and date on your phone and make sure they match the computer or device you are logging in from.

Why does it keep saying authentication failed? ›

Signal interference from nearby electronic devices, neighboring networks, or other physical obstacles can cause slow or unstable connections, which could lead to network authentication issues. The easiest way to avoid signal interference is to reposition your Wi-Fi router.

Why is my authenticator app not letting me log in? ›

Go to your device's Settings and make sure push notifications are enabled and you have network connectivity. You can also remove your account and attempt the sign-in again. If you are still not able to add your account, please contact Support for personal accounts or reach out to your IT admin for work/school accounts.

How to recover two-factor authentication if you lose your phone? ›

If you've lost access to your 2FA device, you can recover your account by using backup codes, alternative recovery options like a secondary email or phone number, or by contacting customer support. Be ready to confirm your identity by answering a few security questions or providing proof of ID.

How do I fix my authenticator problem? ›

Go to Settings and make sure push notifications are enabled and you have network connectivity. You can also remove your account and attempt the sign in again. If you are still not able to add your account, please contact Support or reach out to your IT admin.

How do I recover my account with two-factor authentication? ›

Recover an account
  1. Sign in to your Google Admin console. ...
  2. In the Admin console, go to Menu Directory. ...
  3. Click the user you want in the list. ...
  4. Click Security.
  5. Click 2-step verification. ...
  6. Click Get Backup Verification Codes.
  7. Copy one of the verification codes.
  8. Send the backup code to the user in an IM or text message.

How do I get rid of two factor authenticator? ›

Turn off 2-Step Verification
  1. Open your device's Settings app and tap Google. Manage your Google Account.
  2. At the top, tap Security.
  3. Under "How you sign in to Google," tap 2-Step Verification. You might need to sign in.
  4. Tap Turn off.
  5. Confirm by tapping Turn off.

Top Articles
Latest Posts
Article information

Author: Rev. Porsche Oberbrunner

Last Updated:

Views: 6196

Rating: 4.2 / 5 (53 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Rev. Porsche Oberbrunner

Birthday: 1994-06-25

Address: Suite 153 582 Lubowitz Walks, Port Alfredoborough, IN 72879-2838

Phone: +128413562823324

Job: IT Strategist

Hobby: Video gaming, Basketball, Web surfing, Book restoration, Jogging, Shooting, Fishing

Introduction: My name is Rev. Porsche Oberbrunner, I am a zany, graceful, talented, witty, determined, shiny, enchanting person who loves writing and wants to share my knowledge and understanding with you.