<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FIDO2 support for GlobalProtect client in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/fido2-support-for-globalprotect-client/m-p/589844#M5491</link>
    <description>&lt;P&gt;FIDO2 Security cards during Entra ID SAML authentication does not work. The option to select a hardware "security key" during the Entra ID login flow is not shown. Only the built-in/embeded GlobalProtect web browser exhibits this issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The feature listing for GlobalProtect 6.2.3 says, "&lt;STRONG&gt;Starting with GlobalProtect 6.2.3, the embedded browser framework&lt;/STRONG&gt; for SAML authentication has been upgraded to Microsoft Edge WebView2 (Windows) and WebKit (macOS). &lt;STRONG&gt;This provides a consistent experience between the embedded browser and the GlobalProtect client&lt;/STRONG&gt;. WebView2 and WebKit are also compatible with &lt;STRONG&gt;FIDO2&lt;/STRONG&gt;-based authentication methods. "&lt;A href="https://docs.paloaltonetworks.com/globalprotect/6-2/globalprotect-app-release-notes/features-introduced-in-gp-app" target="_blank" rel="noopener"&gt;&amp;nbsp;https://docs.paloaltonetworks.com/globalprotect/6-2/globalprotect-app-release-notes/features-introduced-in-gp-app&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We tried the workaround to use the default OS browser for authentication, but the integration is not very smooth so it won’t be a good solution for us. E&lt;/SPAN&gt;ven with GlobalProtect 6.2.3 FIDO2 is not shown as an option during login.&amp;nbsp; we see the MSWebVIew2 process running during GlobalProtect SAML login.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Based on&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://urldefense.com/v3/__https:/knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000g1I9CAI&amp;amp;lang=en_US__;!!HUqgN_M!oTv4zhaFBTNE3sLSLuDyaG_j5bKQgPFjY29Gt04BeqAYtdR0tEZFenWpaMckkBUig9PmLak-6hJE61jjUhIG7XduZXH4$" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000g1I9CAI&amp;amp;lang=en_US&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;article date 2nd Apr 2024, the current PANOS versions do not support&lt;/STRONG&gt;&amp;nbsp;the FIDO2 authentication through GlobalProtect. Could someone please confirm this or give us some advise here. Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="GlobalProtect" id="GlobalProtect"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;#FIDO2&lt;/P&gt;</description>
    <pubDate>Tue, 18 Jun 2024 19:26:07 GMT</pubDate>
    <dc:creator>Param_Upadhyay</dc:creator>
    <dc:date>2024-06-18T19:26:07Z</dc:date>
    <item>
      <title>FIDO2 support for GlobalProtect client</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/fido2-support-for-globalprotect-client/m-p/589844#M5491</link>
      <description>&lt;P&gt;FIDO2 Security cards during Entra ID SAML authentication does not work. The option to select a hardware "security key" during the Entra ID login flow is not shown. Only the built-in/embeded GlobalProtect web browser exhibits this issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The feature listing for GlobalProtect 6.2.3 says, "&lt;STRONG&gt;Starting with GlobalProtect 6.2.3, the embedded browser framework&lt;/STRONG&gt; for SAML authentication has been upgraded to Microsoft Edge WebView2 (Windows) and WebKit (macOS). &lt;STRONG&gt;This provides a consistent experience between the embedded browser and the GlobalProtect client&lt;/STRONG&gt;. WebView2 and WebKit are also compatible with &lt;STRONG&gt;FIDO2&lt;/STRONG&gt;-based authentication methods. "&lt;A href="https://docs.paloaltonetworks.com/globalprotect/6-2/globalprotect-app-release-notes/features-introduced-in-gp-app" target="_blank" rel="noopener"&gt;&amp;nbsp;https://docs.paloaltonetworks.com/globalprotect/6-2/globalprotect-app-release-notes/features-introduced-in-gp-app&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We tried the workaround to use the default OS browser for authentication, but the integration is not very smooth so it won’t be a good solution for us. E&lt;/SPAN&gt;ven with GlobalProtect 6.2.3 FIDO2 is not shown as an option during login.&amp;nbsp; we see the MSWebVIew2 process running during GlobalProtect SAML login.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Based on&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://urldefense.com/v3/__https:/knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000g1I9CAI&amp;amp;lang=en_US__;!!HUqgN_M!oTv4zhaFBTNE3sLSLuDyaG_j5bKQgPFjY29Gt04BeqAYtdR0tEZFenWpaMckkBUig9PmLak-6hJE61jjUhIG7XduZXH4$" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000g1I9CAI&amp;amp;lang=en_US&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;article date 2nd Apr 2024, the current PANOS versions do not support&lt;/STRONG&gt;&amp;nbsp;the FIDO2 authentication through GlobalProtect. Could someone please confirm this or give us some advise here. Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="GlobalProtect" id="GlobalProtect"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;#FIDO2&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2024 19:26:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/fido2-support-for-globalprotect-client/m-p/589844#M5491</guid>
      <dc:creator>Param_Upadhyay</dc:creator>
      <dc:date>2024-06-18T19:26:07Z</dc:date>
    </item>
    <item>
      <title>Re: FIDO2 support for GlobalProtect client</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/fido2-support-for-globalprotect-client/m-p/590060#M5494</link>
      <description>&lt;P&gt;Same here. GP 6.2.3 + embedded browser still no FIDO2 option. Default browser works as expected.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2024 06:35:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/fido2-support-for-globalprotect-client/m-p/590060#M5494</guid>
      <dc:creator>Neubauer</dc:creator>
      <dc:date>2024-06-21T06:35:04Z</dc:date>
    </item>
    <item>
      <title>Re: FIDO2 support for GlobalProtect client</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/fido2-support-for-globalprotect-client/m-p/592667#M5587</link>
      <description>&lt;P&gt;Can anyone please check and confirm if there has been a solution for this?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 19:24:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/fido2-support-for-globalprotect-client/m-p/592667#M5587</guid>
      <dc:creator>Param_Upadhyay</dc:creator>
      <dc:date>2024-07-22T19:24:40Z</dc:date>
    </item>
    <item>
      <title>Re: FIDO2 support for GlobalProtect client</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/fido2-support-for-globalprotect-client/m-p/594926#M5672</link>
      <description>&lt;P&gt;We got the security keys to work in the embedded browser with version 6.2.3 under Windows. It's not working for us in MacOS.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 14:57:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/fido2-support-for-globalprotect-client/m-p/594926#M5672</guid>
      <dc:creator>carias</dc:creator>
      <dc:date>2024-08-14T14:57:52Z</dc:date>
    </item>
    <item>
      <title>Re: FIDO2 support for GlobalProtect client</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/fido2-support-for-globalprotect-client/m-p/595930#M5727</link>
      <description>&lt;P&gt;We are experiencing the same thing for 6.2.4, is there any BUG ID open for this issue?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2024 14:35:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/fido2-support-for-globalprotect-client/m-p/595930#M5727</guid>
      <dc:creator>UtkarshKumar</dc:creator>
      <dc:date>2024-08-26T14:35:49Z</dc:date>
    </item>
    <item>
      <title>Re: FIDO2 support for GlobalProtect client</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/fido2-support-for-globalprotect-client/m-p/595931#M5728</link>
      <description>&lt;P&gt;Did you get FIDO2 working?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2024 14:36:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/fido2-support-for-globalprotect-client/m-p/595931#M5728</guid>
      <dc:creator>Param_Upadhyay</dc:creator>
      <dc:date>2024-08-26T14:36:07Z</dc:date>
    </item>
    <item>
      <title>Re: FIDO2 support for GlobalProtect client</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/fido2-support-for-globalprotect-client/m-p/595981#M5731</link>
      <description>&lt;P&gt;Yes, FIDO2 (Yubikey). We get the same options for authentication on embedded browser as the system browser. With version 6.2.3 using the&amp;nbsp;system browser we were getting a double window popping up, one that said auth failed and another auth successful. But that was a known issue they fixed in 6.2.4. In any case, we found the experience better with embedded browser so we're using that on 6.2.3. Both versions work with FIDO2 on Windows. We currently have a TSC case ongoing for the Mac FIDO2 support.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2024 19:50:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/fido2-support-for-globalprotect-client/m-p/595981#M5731</guid>
      <dc:creator>carias</dc:creator>
      <dc:date>2024-08-26T19:50:47Z</dc:date>
    </item>
    <item>
      <title>Re: FIDO2 support for GlobalProtect client</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/fido2-support-for-globalprotect-client/m-p/1218770#M6425</link>
      <description>&lt;P&gt;Has anyone seen this work yet? We have exclusively Mac clients, and our admins now need FIDO2 auth as a requirement for entra ID, which will force it on GP as well. Switching to default os browser is a no go as it would just confuse our users more.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 21:55:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/fido2-support-for-globalprotect-client/m-p/1218770#M6425</guid>
      <dc:creator>michael_hess</dc:creator>
      <dc:date>2025-01-30T21:55:08Z</dc:date>
    </item>
  </channel>
</rss>

