Requirements for Disabling SAML Authentication
- Decryption is disabled in the security profile, or is enabled only for notifications.
- The security profile will be used in rules that include sources that:
- Are not configured for SAML authentication.
- Cannot be authenticated using SAML. For example, if the rule source includes:
- Devices that are not managed by your organization, when certificates are required for authentication but cannot be installed on the device. Such devices might be used by contractors or vendors on your guest network.
- Devices such as IoT devices, printers, or kiosks that cannot respond to authentication requests or present certificates required for authentication.
- Should not be authenticated using SAML. For example, if users should not be identified for privacy or confidentiality reasons, such as by regulation or policy.