Identity provider not excluded from the SSE proxy
medium
Explicit proxies that authenticate through SAML redirect the browser to the identity provider. If the IdP itself is reached through the proxy, the login loops. Netskope, Cloudflare and Palo Alto Networks all require the IdP to be bypassed in the PAC.
Why it matters
The three vendors say it in their own words. Netskope: “you must not send your IdP request/response to Netskope but instead send the traffic directly to the IdP server”. Cloudflare’s template starts with “CRITICAL: Bypass your IdP to prevent authentication loops” and ships commented blocks for Okta, Microsoft Entra ID, Google Workspace and GitHub. Palo Alto Networks’ sample bypasses its SAML provider’s domains (Okta in the example) and the best practices say to bypass all SAML, CIE and ACS URLs. The checker cannot know your IdP, so it looks for a DIRECT branch whose pattern contains a common IdP name or an authentication-looking label (login., sso., idp., auth., adfs). If your IdP is called something else, the finding is a false alarm; a comment does not silence it, a matching DIRECT rule does.
How to fix
Add a DIRECT rule for your IdP hosts before the proxy return, e.g. if (dnsDomainIs(host, ".login.idp.example")) return "DIRECT";
Examples
Bad
function FindProxyForURL(url, host) {
if (isPlainHostName(host)) {
return "DIRECT";
}
return "PROXY eproxy-exampletenant.goskope.com:8081";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
if (isPlainHostName(host)) {
return "DIRECT";
}
if (dnsDomainIs(host, ".login.idp.example")) {
return "DIRECT";
}
return "PROXY eproxy-exampletenant.goskope.com:8081";
}
Open good example in checkerRelated rules
- Prisma Access service domains not returned DIRECT PAC-C030
- Long list of public hostnames routed around the proxy PAC-B008
References
- https://docs.netskope.com/en/explicit-proxy
- https://developers.cloudflare.com/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/best-practices/
- https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/explicit-proxy-best-practices
- https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/pac-file-guidelines