<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Globalprotect VPN with SAML Azure + MFA - no login prompt after disconnecting! in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-vpn-with-saml-azure-mfa-no-login-prompt-after/m-p/1235028#M6936</link>
    <description>&lt;DIV class="text-neutral-content"&gt;
&lt;DIV class="mb-sm  mb-xs px-md xs:px-0 overflow-hidden" data-post-click-location="text-body"&gt;
&lt;DIV id="t3_1md41rt-post-rtjson-content" class="md text-14-scalable" style="--emote-size: 20px;"&gt;
&lt;P&gt;Hey there,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;I have an issue trying to implement Globalprotect authentification via Azure MFA SAML. Our goal is that the user is asked to login with MFA everytime he tries to connect to our portal, which doesn't work. Basically the first time the user is trying to connect to our portal the user get's redirected over his browser to the Microsoft login page and asked to login with his user and MFA, which works fine like expected. &lt;BR /&gt;&lt;BR /&gt;But when the user disconnects from Globalprotect, logsoff his user in Windows or even restarts the computer the user is not prompted anymore when he is connecting to our portal, meaning there is no authentication prompt whatsoever for an infinitive time, which is a security risk for us. The only way the user is redirected to Microsoft again to authenticate if the user has connected to another portal between.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Things i tried:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;I turned of any authentication cookie override settings on the firewall&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;set condition access policy sign in frequency (under session) to everytime in Azure&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;deleted browser caches&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;But nothing seems to work! So checking in the Azure-SignIn-Logs I found out that the second login is satisified with &lt;STRONG&gt;"Primary Refresh Token"&lt;/STRONG&gt;. So it seems like even after disconnecting from GlobalProtect the Token is somewhere saved and used for all further logins. Reading on the internet it seems like this token is valid for weeks or even months? Furthermore there is no way to set ForceAuth=true to force reauthentification from our firewall to Microsoft, because there is no checkbox or field i can see in the authentication profile.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Has anyone an idea how in the world I'm able to force users to use their Microsoft login with MFA everytime they are trying to connect to our portal via Globalprotect?&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
    <pubDate>Wed, 30 Jul 2025 11:33:29 GMT</pubDate>
    <dc:creator>Wimazal</dc:creator>
    <dc:date>2025-07-30T11:33:29Z</dc:date>
    <item>
      <title>Globalprotect VPN with SAML Azure + MFA - no login prompt after disconnecting!</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-vpn-with-saml-azure-mfa-no-login-prompt-after/m-p/1235028#M6936</link>
      <description>&lt;DIV class="text-neutral-content"&gt;
&lt;DIV class="mb-sm  mb-xs px-md xs:px-0 overflow-hidden" data-post-click-location="text-body"&gt;
&lt;DIV id="t3_1md41rt-post-rtjson-content" class="md text-14-scalable" style="--emote-size: 20px;"&gt;
&lt;P&gt;Hey there,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;I have an issue trying to implement Globalprotect authentification via Azure MFA SAML. Our goal is that the user is asked to login with MFA everytime he tries to connect to our portal, which doesn't work. Basically the first time the user is trying to connect to our portal the user get's redirected over his browser to the Microsoft login page and asked to login with his user and MFA, which works fine like expected. &lt;BR /&gt;&lt;BR /&gt;But when the user disconnects from Globalprotect, logsoff his user in Windows or even restarts the computer the user is not prompted anymore when he is connecting to our portal, meaning there is no authentication prompt whatsoever for an infinitive time, which is a security risk for us. The only way the user is redirected to Microsoft again to authenticate if the user has connected to another portal between.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Things i tried:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;I turned of any authentication cookie override settings on the firewall&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;set condition access policy sign in frequency (under session) to everytime in Azure&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;deleted browser caches&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;But nothing seems to work! So checking in the Azure-SignIn-Logs I found out that the second login is satisified with &lt;STRONG&gt;"Primary Refresh Token"&lt;/STRONG&gt;. So it seems like even after disconnecting from GlobalProtect the Token is somewhere saved and used for all further logins. Reading on the internet it seems like this token is valid for weeks or even months? Furthermore there is no way to set ForceAuth=true to force reauthentification from our firewall to Microsoft, because there is no checkbox or field i can see in the authentication profile.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Has anyone an idea how in the world I'm able to force users to use their Microsoft login with MFA everytime they are trying to connect to our portal via Globalprotect?&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 30 Jul 2025 11:33:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-vpn-with-saml-azure-mfa-no-login-prompt-after/m-p/1235028#M6936</guid>
      <dc:creator>Wimazal</dc:creator>
      <dc:date>2025-07-30T11:33:29Z</dc:date>
    </item>
  </channel>
</rss>

