StudyToCert

All certifications / NGFW Engineer / Lessons

Palo Alto Networks Certified Next-Generation Firewall Engineer NGFW-Engineer · Domain 2: PAN-OS device setting configuration

Authentication policy and Authentication Portal

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

User-ID usually learns who is behind an IP address silently, from domain controllers, GlobalProtect or syslog. Sometimes that is not enough: a contractor's laptop is not on the domain, a guest network has no directory at all, or a sensitive server should demand fresh proof of identity, possibly with multi-factor authentication (MFA). Authentication policy and the Authentication Portal, formerly called Captive Portal, cover these cases by asking the user to prove who they are.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study NGFW Engineer for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the NGFW Engineer study plan