<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: RSA SecurID Windows MFA Agent stops working when GlobalProtect is installed in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/rsa-securid-windows-mfa-agent-stops-working-when-globalprotect/m-p/488362#M2789</link>
    <description>&lt;P&gt;I think I found the solution. If someone can confirm it's the right solution, I would appreciate it.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;The Group Policies under &lt;STRONG&gt;Local Computer Policy -&amp;gt; Computer Configuration -&amp;gt; Administrative Templates -&amp;gt; RSA Desktop -&amp;gt; Confidential Provider Filter Settings&lt;/STRONG&gt;&amp;nbsp;include a setting called&amp;nbsp;&lt;STRONG&gt;Exclude all third-party Credential Providers&lt;/STRONG&gt;. Normally this is disabled, enabling the setting now will allow Windows Hello to prompt for the MFA challenge.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Oddly, it seems to only apply to the Windows Hello prompt and not when unlocking a session. The MFA challenge is still not presented when unlocking a session.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 18 May 2022 21:06:01 GMT</pubDate>
    <dc:creator>fpascal4</dc:creator>
    <dc:date>2022-05-18T21:06:01Z</dc:date>
    <item>
      <title>RSA SecurID Windows MFA Agent stops working when GlobalProtect is installed</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/rsa-securid-windows-mfa-agent-stops-working-when-globalprotect/m-p/488325#M2787</link>
      <description>&lt;P&gt;We are trying to implement RSA SecurID MFA across our infrastructure, specifically to lock down VPN, cross zone traffic, and essential network assets. On the Window servers and some of the more sensitive mobile devices (Windows laptops) we are installing the RSA SecurID Windows MFA Agent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The RSA MFA works fine if GlobalProtect is not installed on my test laptop. If GlobalProtect is installed the MFA challenge fails to be presented on login or unlocking a session. When I look at the login options on the Windows Hello prompt for logging in, GlobalProtect is presented first, then RSA Windows MFA Agent. MFA does work when bringing up the VPN or hitting the VPN portal with the browser.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't believe it is a DNS or routing issue, the problem still presents itself when the laptop is on the physical network and VPN is not being used. It might&amp;nbsp; simply be a sequencing issue with GP getting in the way some how.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas on solutions, causes, or settings I need to change?&amp;nbsp; Googling and searching the knowledge bases here and at RSA have yielded nothing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Freeman Pascal, Rhinocorps, Ltd CO.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 19:51:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/rsa-securid-windows-mfa-agent-stops-working-when-globalprotect/m-p/488325#M2787</guid>
      <dc:creator>fpascal4</dc:creator>
      <dc:date>2022-05-18T19:51:50Z</dc:date>
    </item>
    <item>
      <title>Re: RSA SecurID Windows MFA Agent stops working when GlobalProtect is installed</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/rsa-securid-windows-mfa-agent-stops-working-when-globalprotect/m-p/488362#M2789</link>
      <description>&lt;P&gt;I think I found the solution. If someone can confirm it's the right solution, I would appreciate it.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;The Group Policies under &lt;STRONG&gt;Local Computer Policy -&amp;gt; Computer Configuration -&amp;gt; Administrative Templates -&amp;gt; RSA Desktop -&amp;gt; Confidential Provider Filter Settings&lt;/STRONG&gt;&amp;nbsp;include a setting called&amp;nbsp;&lt;STRONG&gt;Exclude all third-party Credential Providers&lt;/STRONG&gt;. Normally this is disabled, enabling the setting now will allow Windows Hello to prompt for the MFA challenge.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Oddly, it seems to only apply to the Windows Hello prompt and not when unlocking a session. The MFA challenge is still not presented when unlocking a session.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 21:06:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/rsa-securid-windows-mfa-agent-stops-working-when-globalprotect/m-p/488362#M2789</guid>
      <dc:creator>fpascal4</dc:creator>
      <dc:date>2022-05-18T21:06:01Z</dc:date>
    </item>
    <item>
      <title>Re: RSA SecurID Windows MFA Agent stops working when GlobalProtect is installed</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/rsa-securid-windows-mfa-agent-stops-working-when-globalprotect/m-p/539214#M3944</link>
      <description>&lt;P&gt;Hi - We are running into the same issue. Did you happen to figure out the cause and fix?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 15:21:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/rsa-securid-windows-mfa-agent-stops-working-when-globalprotect/m-p/539214#M3944</guid>
      <dc:creator>Manny_Rodgers</dc:creator>
      <dc:date>2023-04-18T15:21:40Z</dc:date>
    </item>
  </channel>
</rss>

