<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect and Windows Hello for Business in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-and-windows-hello-for-business/m-p/1240855#M7100</link>
    <description>&lt;P&gt;Hi there, do you have any news on this subject ?&lt;/P&gt;</description>
    <pubDate>Tue, 28 Oct 2025 15:52:53 GMT</pubDate>
    <dc:creator>amiladi</dc:creator>
    <dc:date>2025-10-28T15:52:53Z</dc:date>
    <item>
      <title>GlobalProtect and Windows Hello for Business</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-and-windows-hello-for-business/m-p/534095#M3788</link>
      <description>&lt;P&gt;Has anyone successfully implemented Windows Hello for Business with GlobalProtect in a Passwordless configuration. We in the middle of a Passwordless implementation. We are discovering that when you use your Biometric or PIN to authenticate, that GlobalProtect still relies on a password once signed into the PC. We have enabled Prelogon set up to use a machine certificate for GlobalProtect then on the User end we have Windows and SmartCard auth enabled. At Prelogon, the VPN connects with the machine cert, then the user enters their Biometric Gesture or PIN. We can see once in Windows; the portal is still authenticated with the Machine Cert and never hands off to the Logon which should use the User Cert with SmartCard Logon Purpose. We have Global Protect configured to use PINSSO, but it doesn't appear to work as the user still gets a password pop up in GlobalProtect. I am assuming it has something to do with the Credential Provider, the client, a config on the Portal, or a combination of all three. Please help if you have this implemented in your environment. Thank you in advance!&lt;/P&gt;</description>
      <pubDate>Sat, 11 Mar 2023 13:45:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-and-windows-hello-for-business/m-p/534095#M3788</guid>
      <dc:creator>rheinrich</dc:creator>
      <dc:date>2023-03-11T13:45:31Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect and Windows Hello for Business</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-and-windows-hello-for-business/m-p/545049#M4097</link>
      <description>&lt;P&gt;We were trying to get this working and hit the same issue. Logged a support case, and it turns out the behaviour is expected with the current agent version.&lt;/P&gt;
&lt;P&gt;However, I was informed that there's a feature request to add this functionality:&lt;/P&gt;
&lt;P&gt;FR ID: 8639 - Global Protect client support of Windows Hello authentication&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 06:13:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-and-windows-hello-for-business/m-p/545049#M4097</guid>
      <dc:creator>Shannon_Parkes</dc:creator>
      <dc:date>2023-06-07T06:13:34Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect and Windows Hello for Business</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-and-windows-hello-for-business/m-p/545088#M4099</link>
      <description>&lt;P&gt;Thanks you Shannon_Parks, we found out the hard way that this is not supported. Even though they do have a Biometric setting for the Global Protect client, Windows Hello PIN, Fingerprint, and Face are not supported at this time. This is something that should absolutely be supported as organizations transiton from passwords into passwordless implementations. Our goal is for employees to never know their passwords, but we find in the current set up with Global Protect 6.1.1-5 employees have to recache their passwords in the Agent as they expire. We don't want to go to Cetrificate Based Authentication only, so we are looking into alternatives like SAML SSO, but at this time there&amp;nbsp; is not a direct path to passwordless as far as I can find in documentation, through the Live Community, and through the TAC.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 12:31:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-and-windows-hello-for-business/m-p/545088#M4099</guid>
      <dc:creator>rheinrich</dc:creator>
      <dc:date>2023-06-07T12:31:54Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect and Windows Hello for Business</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-and-windows-hello-for-business/m-p/545194#M4101</link>
      <description>&lt;P&gt;I completely agree that this functionality is needed. Windows Hello for Business has been around for ages..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We've somewhat hacked around the limitation by running a script at boot and shutdown to change the credential provider to GlobalProtect. Users log in with their password, GlobalProtect SSO works and users can then use Hello to unlock their device.&lt;/P&gt;
&lt;P&gt;We also had to force ctrl+alt+delete before login, otherwise devices with Hello face would always default to that credential provider and (as expected) GP SSO wouldn't occur.&lt;/P&gt;
&lt;P&gt;We're in pilot with the above.. though I must say that since upgrading to GP Agent 6.0.5 it's less reliable. Our portal config doesn't permit cached passwords.. so we may consider that but as you note that isn't a silver bullet either.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a subset of our devices Azure AD joined using SAML SSO for GP, though from memory it invokes a browser for the login. I'm not sure why it didn't seamlessly SSO.. I wasn't involved in that implementation, but it's worth keeping in mind.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If we don't get GP Hello support, we may need to look into moving away from always-on to on-demand VPNs.. though our Cyber team may not like that idea!&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 00:16:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-and-windows-hello-for-business/m-p/545194#M4101</guid>
      <dc:creator>Shannon_Parkes</dc:creator>
      <dc:date>2023-06-08T00:16:25Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect and Windows Hello for Business</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-and-windows-hello-for-business/m-p/562960#M4557</link>
      <description>&lt;P&gt;I too, wish these two features would communicate the login credentials to one another...&amp;nbsp; Windows Hello for Business -&amp;gt; GP&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 15:43:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-and-windows-hello-for-business/m-p/562960#M4557</guid>
      <dc:creator>TANielsenBest</dc:creator>
      <dc:date>2023-10-24T15:43:56Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect and Windows Hello for Business</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-and-windows-hello-for-business/m-p/1240855#M7100</link>
      <description>&lt;P&gt;Hi there, do you have any news on this subject ?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Oct 2025 15:52:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-and-windows-hello-for-business/m-p/1240855#M7100</guid>
      <dc:creator>amiladi</dc:creator>
      <dc:date>2025-10-28T15:52:53Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect and Windows Hello for Business</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-and-windows-hello-for-business/m-p/1240872#M7106</link>
      <description>&lt;P&gt;Kind of. We have another portal for a different environment which uses SAML auth. Since our devices are hybrid joined, I've tested one device with Windows Hello enabled and GP pointing to that portal. Logging on with the Hello credential provider, GP then seamlessly SSO's to that portal post logon. No prompts or anything.&lt;/P&gt;
&lt;P&gt;Now, the "kind of" part is that the SAML portal has pre-logon auth disabled, so I haven't been able to test that out (which we need for our corporate fleet).&lt;/P&gt;
&lt;P&gt;It'd be worthwhile giving it a test though!&lt;/P&gt;</description>
      <pubDate>Wed, 29 Oct 2025 00:16:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-and-windows-hello-for-business/m-p/1240872#M7106</guid>
      <dc:creator>Shannon_Parkes</dc:creator>
      <dc:date>2025-10-29T00:16:06Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect and Windows Hello for Business</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-and-windows-hello-for-business/m-p/1243502#M7163</link>
      <description>&lt;P&gt;Hi Shanon, what GP version are u running?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2025 18:55:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-and-windows-hello-for-business/m-p/1243502#M7163</guid>
      <dc:creator>colascoaga</dc:creator>
      <dc:date>2025-12-09T18:55:08Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect and Windows Hello for Business</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-and-windows-hello-for-business/m-p/1243879#M7174</link>
      <description>&lt;P&gt;Heya. It was probably&amp;nbsp;6.2.8-c223&lt;/P&gt;</description>
      <pubDate>Mon, 15 Dec 2025 06:16:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-and-windows-hello-for-business/m-p/1243879#M7174</guid>
      <dc:creator>Shannon_Parkes</dc:creator>
      <dc:date>2025-12-15T06:16:45Z</dc:date>
    </item>
  </channel>
</rss>

