<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Windows 10 - Allow Pre-Logon, Windows Hello sign-ins and SSO in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/windows-10-allow-pre-logon-windows-hello-sign-ins-and-sso/m-p/518530#M3344</link>
    <description>&lt;P&gt;I'm unable to get the Windows Hello credentials (such as fingerprint/face ID) to passthrough to Global Protect at logon.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have our computer tunnel configured to handoff to the user tunnel 60 seconds after logon, so during the logon process, the connection isn't dropped and re-established.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, if a user uses face id or fingerprint to logon, global protect will not re-connect with the user tunnel.&amp;nbsp; I've read through all the command line switches on the agent to install, but I'm still lost.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Would someone be able to assist or point me in the right direction?&lt;/P&gt;</description>
    <pubDate>Thu, 20 Oct 2022 15:43:49 GMT</pubDate>
    <dc:creator>TANielsenBest</dc:creator>
    <dc:date>2022-10-20T15:43:49Z</dc:date>
    <item>
      <title>Windows 10 - Allow Pre-Logon, Windows Hello sign-ins and SSO</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/windows-10-allow-pre-logon-windows-hello-sign-ins-and-sso/m-p/518530#M3344</link>
      <description>&lt;P&gt;I'm unable to get the Windows Hello credentials (such as fingerprint/face ID) to passthrough to Global Protect at logon.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have our computer tunnel configured to handoff to the user tunnel 60 seconds after logon, so during the logon process, the connection isn't dropped and re-established.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, if a user uses face id or fingerprint to logon, global protect will not re-connect with the user tunnel.&amp;nbsp; I've read through all the command line switches on the agent to install, but I'm still lost.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Would someone be able to assist or point me in the right direction?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 15:43:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/windows-10-allow-pre-logon-windows-hello-sign-ins-and-sso/m-p/518530#M3344</guid>
      <dc:creator>TANielsenBest</dc:creator>
      <dc:date>2022-10-20T15:43:49Z</dc:date>
    </item>
    <item>
      <title>Re: Windows 10 - Allow Pre-Logon, Windows Hello sign-ins and SSO</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/windows-10-allow-pre-logon-windows-hello-sign-ins-and-sso/m-p/522520#M3462</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/173989"&gt;@TANielsenBest&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;I have recently researched the same question. My understanding is unfortunately it is not possible to have Fingerprint,&amp;nbsp; Face recognition and GlobalProtect SSO.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The reason for that is when GP is configured to use SSO it will introduce its own Credential Provider, so when user enter his credentials on logon they will be passed to GP first. If you choose to use fingerprint or face you are choosing different credential provider and GP will not "see" the credentials and will SSO will fail, resulting in GP prompting the user for credentials.&lt;/P&gt;
&lt;P&gt;Some details here - &lt;A href="https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-apps/deploy-app-settings-transparently/deploy-app-settings-to-windows-endpoints/deploy-globalprotect-credential-provider-settings-in-the-windows-registry" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-apps/deploy-app-settings-transparently/deploy-app-settings-to-windows-endpoints/deploy-globalprotect-credential-provider-settings-in-the-windows-registry&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the following is described how GP can "wrap" other credential providers so and I was wondering if this also could be achieved for Windows Hello, but I haven't been able to test it - &lt;A href="https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-apps/deploy-app-settings-transparently/deploy-app-settings-to-windows-endpoints/sso-wrapping-for-third-party-credential-providers-on-windows-endpoints" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-apps/deploy-app-settings-transparently/deploy-app-settings-to-windows-endpoints/sso-wrapping-for-third-party-credential-providers-on-windows-endpoints&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Nov 2022 22:18:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/windows-10-allow-pre-logon-windows-hello-sign-ins-and-sso/m-p/522520#M3462</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-11-27T22:18:28Z</dc:date>
    </item>
  </channel>
</rss>

