<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GlobalProtect 6.3.3 + Duo SAML MFA loop after normal Windows login (works only via GP Credential Provider at Windows logon) in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-6-3-3-duo-saml-mfa-loop-after-normal-windows-login/m-p/1253925#M7377</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="155" data-start="143"&gt;Hi everyone,&lt;/P&gt;
&lt;P data-end="275" data-start="157"&gt;we are currently facing a strange issue with GlobalProtect + Duo MFA and have been able to narrow it down quite a bit.&lt;/P&gt;
&lt;P data-end="336" data-start="277"&gt;I wanted to check if anyone has already seen this behavior.&lt;/P&gt;
&lt;H1 data-end="351" data-start="338" data-section-id="12hwy1f"&gt;Environment&lt;/H1&gt;
&lt;UL data-end="745" data-start="353"&gt;
&lt;LI data-end="387" data-start="353" data-section-id="6dpsh6"&gt;GlobalProtect Client: 6.3.3-c876&lt;/LI&gt;
&lt;LI data-end="416" data-start="388" data-section-id="krtj16"&gt;Prisma Access Mobile Users&lt;/LI&gt;
&lt;LI data-end="444" data-start="417" data-section-id="1vt30p"&gt;Dataplane Version: 10.2.4&lt;/LI&gt;
&lt;LI data-end="481" data-start="445" data-section-id="10oq190"&gt;Authentication: SAML via Cisco Duo&lt;/LI&gt;
&lt;LI data-end="525" data-start="482" data-section-id="56d5m1"&gt;Cisco Duo federated to Microsoft Entra ID&lt;/LI&gt;
&lt;LI data-end="562" data-start="526" data-section-id="ywbnzh"&gt;Windows Hello for Business enabled&lt;/LI&gt;
&lt;LI data-end="577" data-start="563" data-section-id="1sob5k6"&gt;No Pre-Logon&lt;/LI&gt;
&lt;LI data-end="603" data-start="578" data-section-id="yb3bcb"&gt;No Connect Before Logon&lt;/LI&gt;
&lt;LI data-end="645" data-start="604" data-section-id="yxuepa"&gt;Authentication Override Cookies enabled&lt;/LI&gt;
&lt;LI data-end="694" data-start="646" data-section-id="2d4fjh"&gt;Tested with Save User Credentials = Yes and No&lt;/LI&gt;
&lt;LI data-end="745" data-start="695" data-section-id="1cfv3eb"&gt;Tested with Default Browser and Embedded Browser&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR data-end="750" data-start="747" /&gt;
&lt;H1 data-end="773" data-start="752" data-section-id="uezodw"&gt;Authentication Flow&lt;/H1&gt;
&lt;P data-end="802" data-start="775"&gt;The authentication flow is:&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN&gt;GlobalProtect / Prisma Access&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;→ Cisco Duo SAML&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;→ Microsoft Entra ID&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&lt;SPAN&gt;So the direct IdP configured in Prisma Access is Cisco Duo, while Duo itself is federated with Entra ID.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;HR data-end="1006" data-start="1003" /&gt;
&lt;H1 data-end="1017" data-start="1008" data-section-id="1303e6l"&gt;Problem&lt;/H1&gt;
&lt;P data-end="1102" data-start="1019"&gt;We are getting an MFA/SAML authentication loop, but only under specific conditions.&lt;/P&gt;
&lt;H2 data-end="1122" data-start="1104" data-section-id="v8r1lo"&gt;Works correctly&lt;/H2&gt;
&lt;P data-end="1265" data-start="1123"&gt;If the user authenticates via the &lt;STRONG data-end="1229" data-start="1157"&gt;GlobalProtect icon / Credential Provider on the Windows login screen&lt;/STRONG&gt; and enters username/password there.&lt;/P&gt;
&lt;P data-end="1274" data-start="1267"&gt;Result:&lt;/P&gt;
&lt;UL data-end="1342" data-start="1275"&gt;
&lt;LI data-end="1293" data-start="1275" data-section-id="17vvru5"&gt;Duo MFA succeeds&lt;/LI&gt;
&lt;LI data-end="1317" data-start="1294" data-section-id="108dtwr"&gt;VPN connects normally&lt;/LI&gt;
&lt;LI data-end="1342" data-start="1318" data-section-id="honhp1"&gt;no authentication loop&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR data-end="1347" data-start="1344" /&gt;
&lt;H2 data-end="1365" data-start="1349" data-section-id="giy4gc"&gt;Does NOT work&lt;/H2&gt;
&lt;P data-end="1451" data-start="1366"&gt;If the user logs into Windows normally first and GP connects afterward automatically.&lt;/P&gt;
&lt;P data-end="1506" data-start="1453"&gt;It does not matter whether Windows login is done via:&lt;/P&gt;
&lt;UL data-end="1566" data-start="1507"&gt;
&lt;LI data-end="1526" data-start="1507" data-section-id="o49f4y"&gt;Windows Hello PIN&lt;/LI&gt;
&lt;LI data-end="1553" data-start="1527" data-section-id="qvr7f6"&gt;regular Windows password&lt;/LI&gt;
&lt;LI data-end="1566" data-start="1554" data-section-id="1j1pqmz"&gt;biometrics&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="1577" data-start="1568"&gt;Behavior:&lt;/P&gt;
&lt;OL data-end="1719" data-start="1578"&gt;
&lt;LI data-end="1597" data-start="1578" data-section-id="1dik3xb"&gt;Duo MFA succeeds&lt;/LI&gt;
&lt;LI data-end="1631" data-start="1598" data-section-id="s6hveb"&gt;Redirect back to GlobalProtect&lt;/LI&gt;
&lt;LI data-end="1675" data-start="1632" data-section-id="1tfoa4c"&gt;GP immediately starts a new auth request&lt;/LI&gt;
&lt;LI data-end="1703" data-start="1676" data-section-id="y2bl2t"&gt;MFA prompt appears again&lt;/LI&gt;
&lt;LI data-end="1719" data-start="1704" data-section-id="gi0ix0"&gt;endless loop&lt;/LI&gt;
&lt;/OL&gt;
&lt;HR data-end="1724" data-start="1721" /&gt;
&lt;H1 data-end="1753" data-start="1726" data-section-id="ic9d4s"&gt;Relevant client log entry&lt;/H1&gt;
&lt;P data-end="1791" data-start="1755"&gt;In &lt;CODE data-end="1770" data-start="1758"&gt;PanGPA.log&lt;/CODE&gt; we consistently see:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN&gt;RetrieveGPCred failed. hr = 1168&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&lt;SPAN&gt;This seems directly related to the issue.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;HR data-end="1897" data-start="1894" /&gt;
&lt;H1 data-end="1915" data-start="1899" data-section-id="lf2n7b"&gt;Already tested&lt;/H1&gt;
&lt;H2 data-end="1932" data-start="1917" data-section-id="1mjfrvu"&gt;Browser mode&lt;/H2&gt;
&lt;UL data-end="1969" data-start="1933"&gt;
&lt;LI data-end="1950" data-start="1933" data-section-id="xkhej3"&gt;Default Browser&lt;/LI&gt;
&lt;LI data-end="1969" data-start="1951" data-section-id="1ob6vvu"&gt;Embedded Browser&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="1987" data-start="1971"&gt;=&amp;gt; no difference&lt;/P&gt;
&lt;HR data-end="1992" data-start="1989" /&gt;
&lt;H2 data-end="2000" data-start="1994" data-section-id="1hryx2i"&gt;SSO&lt;/H2&gt;
&lt;UL data-end="2053" data-start="2001"&gt;
&lt;LI data-end="2027" data-start="2001" data-section-id="hjqg64"&gt;Use Single Sign-On = Yes&lt;/LI&gt;
&lt;LI data-end="2053" data-start="2028" data-section-id="4u4c1e"&gt;Use Single Sign-On = No&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="2071" data-start="2055"&gt;=&amp;gt; no difference&lt;/P&gt;
&lt;HR data-end="2076" data-start="2073" /&gt;
&lt;H2 data-end="2102" data-start="2078" data-section-id="p5kbot"&gt;Save User Credentials&lt;/H2&gt;
&lt;UL data-end="2113" data-start="2103"&gt;
&lt;LI data-end="2108" data-start="2103" data-section-id="1o4mtj"&gt;Yes&lt;/LI&gt;
&lt;LI data-end="2113" data-start="2109" data-section-id="yhmtop"&gt;No&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="2131" data-start="2115"&gt;=&amp;gt; no difference&lt;/P&gt;
&lt;HR data-end="2136" data-start="2133" /&gt;
&lt;H2 data-end="2164" data-start="2138" data-section-id="1ilgi5t"&gt;Authentication Override&lt;/H2&gt;
&lt;UL data-end="2249" data-start="2165"&gt;
&lt;LI data-end="2190" data-start="2165" data-section-id="drru9u"&gt;Generate Cookie enabled&lt;/LI&gt;
&lt;LI data-end="2214" data-start="2191" data-section-id="prm2bt"&gt;Accept Cookie enabled&lt;/LI&gt;
&lt;LI data-end="2233" data-start="2215" data-section-id="u82eef"&gt;same certificate&lt;/LI&gt;
&lt;LI data-end="2249" data-start="2234" data-section-id="1vkhq8x"&gt;same lifetime&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="2267" data-start="2251"&gt;=&amp;gt; no difference&lt;/P&gt;
&lt;HR data-end="2272" data-start="2269" /&gt;
&lt;H1 data-end="2299" data-start="2274" data-section-id="ius7aa"&gt;Interesting observation&lt;/H1&gt;
&lt;P data-end="2436" data-start="2301"&gt;The problem does NOT occur when the full authentication flow is handled through the GP Credential Provider at the Windows login screen.&lt;/P&gt;
&lt;P data-end="2466" data-start="2438"&gt;The issue only happens with:&lt;/P&gt;
&lt;UL data-end="2537" data-start="2467"&gt;
&lt;LI data-end="2489" data-start="2467" data-section-id="6r8td3"&gt;normal Windows login&lt;/LI&gt;
&lt;LI data-end="2537" data-start="2490" data-section-id="1efnyuz"&gt;followed by automatic GP connection afterward&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="2561" data-start="2539"&gt;This makes us suspect:&lt;/P&gt;
&lt;UL data-end="2676" data-start="2562"&gt;
&lt;LI data-end="2590" data-start="2562" data-section-id="1iy48m4"&gt;credential retrieval issue&lt;/LI&gt;
&lt;LI data-end="2622" data-start="2591" data-section-id="br844w"&gt;WAM/PRT/WHfB-related behavior&lt;/LI&gt;
&lt;LI data-end="2676" data-start="2623" data-section-id="1x0m3yu"&gt;or possibly a bug in post-logon credential handling&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR data-end="2681" data-start="2678" /&gt;
&lt;H1 data-end="2693" data-start="2683" data-section-id="hh93l4"&gt;Question&lt;/H1&gt;
&lt;P data-end="2731" data-start="2695"&gt;Has anyone seen similar issues with:&lt;/P&gt;
&lt;UL data-end="2857" data-start="2732"&gt;
&lt;LI data-end="2742" data-start="2732" data-section-id="6w4a82"&gt;GP 6.3.x&lt;/LI&gt;
&lt;LI data-end="2771" data-start="2743" data-section-id="1m5mih4"&gt;Windows Hello for Business&lt;/LI&gt;
&lt;LI data-end="2804" data-start="2772" data-section-id="1ucwaqj"&gt;Duo SAML federated to Entra ID&lt;/LI&gt;
&lt;LI data-end="2820" data-start="2805" data-section-id="13zqozc"&gt;Prisma Access&lt;/LI&gt;
&lt;LI data-end="2857" data-start="2821" data-section-id="1i4a12d"&gt;&lt;CODE data-end="2857" data-start="2823"&gt;RetrieveGPCred failed. hr = 1168&lt;/CODE&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="2886" data-start="2859"&gt;Particularly interested in:&lt;/P&gt;
&lt;UL data-end="2965" data-start="2887"&gt;
&lt;LI data-end="2899" data-start="2887" data-section-id="8tgys8"&gt;known bugs&lt;/LI&gt;
&lt;LI data-end="2925" data-start="2900" data-section-id="cux1b7"&gt;recommended GP versions&lt;/LI&gt;
&lt;LI data-end="2939" data-start="2926" data-section-id="14npn09"&gt;workarounds&lt;/LI&gt;
&lt;LI data-end="2965" data-start="2940" data-section-id="rf9pby"&gt;known WAM / WHfB issues&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-is-only-node="" data-is-last-node="" data-end="2985" data-start="2967"&gt;Thanks in advance!&lt;/P&gt;</description>
    <pubDate>Wed, 13 May 2026 14:24:32 GMT</pubDate>
    <dc:creator>Marco_DiFrancesco</dc:creator>
    <dc:date>2026-05-13T14:24:32Z</dc:date>
    <item>
      <title>GlobalProtect 6.3.3 + Duo SAML MFA loop after normal Windows login (works only via GP Credential Provider at Windows logon)</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-6-3-3-duo-saml-mfa-loop-after-normal-windows-login/m-p/1253925#M7377</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="155" data-start="143"&gt;Hi everyone,&lt;/P&gt;
&lt;P data-end="275" data-start="157"&gt;we are currently facing a strange issue with GlobalProtect + Duo MFA and have been able to narrow it down quite a bit.&lt;/P&gt;
&lt;P data-end="336" data-start="277"&gt;I wanted to check if anyone has already seen this behavior.&lt;/P&gt;
&lt;H1 data-end="351" data-start="338" data-section-id="12hwy1f"&gt;Environment&lt;/H1&gt;
&lt;UL data-end="745" data-start="353"&gt;
&lt;LI data-end="387" data-start="353" data-section-id="6dpsh6"&gt;GlobalProtect Client: 6.3.3-c876&lt;/LI&gt;
&lt;LI data-end="416" data-start="388" data-section-id="krtj16"&gt;Prisma Access Mobile Users&lt;/LI&gt;
&lt;LI data-end="444" data-start="417" data-section-id="1vt30p"&gt;Dataplane Version: 10.2.4&lt;/LI&gt;
&lt;LI data-end="481" data-start="445" data-section-id="10oq190"&gt;Authentication: SAML via Cisco Duo&lt;/LI&gt;
&lt;LI data-end="525" data-start="482" data-section-id="56d5m1"&gt;Cisco Duo federated to Microsoft Entra ID&lt;/LI&gt;
&lt;LI data-end="562" data-start="526" data-section-id="ywbnzh"&gt;Windows Hello for Business enabled&lt;/LI&gt;
&lt;LI data-end="577" data-start="563" data-section-id="1sob5k6"&gt;No Pre-Logon&lt;/LI&gt;
&lt;LI data-end="603" data-start="578" data-section-id="yb3bcb"&gt;No Connect Before Logon&lt;/LI&gt;
&lt;LI data-end="645" data-start="604" data-section-id="yxuepa"&gt;Authentication Override Cookies enabled&lt;/LI&gt;
&lt;LI data-end="694" data-start="646" data-section-id="2d4fjh"&gt;Tested with Save User Credentials = Yes and No&lt;/LI&gt;
&lt;LI data-end="745" data-start="695" data-section-id="1cfv3eb"&gt;Tested with Default Browser and Embedded Browser&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR data-end="750" data-start="747" /&gt;
&lt;H1 data-end="773" data-start="752" data-section-id="uezodw"&gt;Authentication Flow&lt;/H1&gt;
&lt;P data-end="802" data-start="775"&gt;The authentication flow is:&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN&gt;GlobalProtect / Prisma Access&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;→ Cisco Duo SAML&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;→ Microsoft Entra ID&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&lt;SPAN&gt;So the direct IdP configured in Prisma Access is Cisco Duo, while Duo itself is federated with Entra ID.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;HR data-end="1006" data-start="1003" /&gt;
&lt;H1 data-end="1017" data-start="1008" data-section-id="1303e6l"&gt;Problem&lt;/H1&gt;
&lt;P data-end="1102" data-start="1019"&gt;We are getting an MFA/SAML authentication loop, but only under specific conditions.&lt;/P&gt;
&lt;H2 data-end="1122" data-start="1104" data-section-id="v8r1lo"&gt;Works correctly&lt;/H2&gt;
&lt;P data-end="1265" data-start="1123"&gt;If the user authenticates via the &lt;STRONG data-end="1229" data-start="1157"&gt;GlobalProtect icon / Credential Provider on the Windows login screen&lt;/STRONG&gt; and enters username/password there.&lt;/P&gt;
&lt;P data-end="1274" data-start="1267"&gt;Result:&lt;/P&gt;
&lt;UL data-end="1342" data-start="1275"&gt;
&lt;LI data-end="1293" data-start="1275" data-section-id="17vvru5"&gt;Duo MFA succeeds&lt;/LI&gt;
&lt;LI data-end="1317" data-start="1294" data-section-id="108dtwr"&gt;VPN connects normally&lt;/LI&gt;
&lt;LI data-end="1342" data-start="1318" data-section-id="honhp1"&gt;no authentication loop&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR data-end="1347" data-start="1344" /&gt;
&lt;H2 data-end="1365" data-start="1349" data-section-id="giy4gc"&gt;Does NOT work&lt;/H2&gt;
&lt;P data-end="1451" data-start="1366"&gt;If the user logs into Windows normally first and GP connects afterward automatically.&lt;/P&gt;
&lt;P data-end="1506" data-start="1453"&gt;It does not matter whether Windows login is done via:&lt;/P&gt;
&lt;UL data-end="1566" data-start="1507"&gt;
&lt;LI data-end="1526" data-start="1507" data-section-id="o49f4y"&gt;Windows Hello PIN&lt;/LI&gt;
&lt;LI data-end="1553" data-start="1527" data-section-id="qvr7f6"&gt;regular Windows password&lt;/LI&gt;
&lt;LI data-end="1566" data-start="1554" data-section-id="1j1pqmz"&gt;biometrics&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="1577" data-start="1568"&gt;Behavior:&lt;/P&gt;
&lt;OL data-end="1719" data-start="1578"&gt;
&lt;LI data-end="1597" data-start="1578" data-section-id="1dik3xb"&gt;Duo MFA succeeds&lt;/LI&gt;
&lt;LI data-end="1631" data-start="1598" data-section-id="s6hveb"&gt;Redirect back to GlobalProtect&lt;/LI&gt;
&lt;LI data-end="1675" data-start="1632" data-section-id="1tfoa4c"&gt;GP immediately starts a new auth request&lt;/LI&gt;
&lt;LI data-end="1703" data-start="1676" data-section-id="y2bl2t"&gt;MFA prompt appears again&lt;/LI&gt;
&lt;LI data-end="1719" data-start="1704" data-section-id="gi0ix0"&gt;endless loop&lt;/LI&gt;
&lt;/OL&gt;
&lt;HR data-end="1724" data-start="1721" /&gt;
&lt;H1 data-end="1753" data-start="1726" data-section-id="ic9d4s"&gt;Relevant client log entry&lt;/H1&gt;
&lt;P data-end="1791" data-start="1755"&gt;In &lt;CODE data-end="1770" data-start="1758"&gt;PanGPA.log&lt;/CODE&gt; we consistently see:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="pe-11 pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼs ͼ16" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;PRE class="cm-content q9tKkq_readonly m-0"&gt;&lt;CODE&gt;&lt;SPAN&gt;RetrieveGPCred failed. hr = 1168&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&lt;SPAN&gt;This seems directly related to the issue.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;HR data-end="1897" data-start="1894" /&gt;
&lt;H1 data-end="1915" data-start="1899" data-section-id="lf2n7b"&gt;Already tested&lt;/H1&gt;
&lt;H2 data-end="1932" data-start="1917" data-section-id="1mjfrvu"&gt;Browser mode&lt;/H2&gt;
&lt;UL data-end="1969" data-start="1933"&gt;
&lt;LI data-end="1950" data-start="1933" data-section-id="xkhej3"&gt;Default Browser&lt;/LI&gt;
&lt;LI data-end="1969" data-start="1951" data-section-id="1ob6vvu"&gt;Embedded Browser&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="1987" data-start="1971"&gt;=&amp;gt; no difference&lt;/P&gt;
&lt;HR data-end="1992" data-start="1989" /&gt;
&lt;H2 data-end="2000" data-start="1994" data-section-id="1hryx2i"&gt;SSO&lt;/H2&gt;
&lt;UL data-end="2053" data-start="2001"&gt;
&lt;LI data-end="2027" data-start="2001" data-section-id="hjqg64"&gt;Use Single Sign-On = Yes&lt;/LI&gt;
&lt;LI data-end="2053" data-start="2028" data-section-id="4u4c1e"&gt;Use Single Sign-On = No&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="2071" data-start="2055"&gt;=&amp;gt; no difference&lt;/P&gt;
&lt;HR data-end="2076" data-start="2073" /&gt;
&lt;H2 data-end="2102" data-start="2078" data-section-id="p5kbot"&gt;Save User Credentials&lt;/H2&gt;
&lt;UL data-end="2113" data-start="2103"&gt;
&lt;LI data-end="2108" data-start="2103" data-section-id="1o4mtj"&gt;Yes&lt;/LI&gt;
&lt;LI data-end="2113" data-start="2109" data-section-id="yhmtop"&gt;No&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="2131" data-start="2115"&gt;=&amp;gt; no difference&lt;/P&gt;
&lt;HR data-end="2136" data-start="2133" /&gt;
&lt;H2 data-end="2164" data-start="2138" data-section-id="1ilgi5t"&gt;Authentication Override&lt;/H2&gt;
&lt;UL data-end="2249" data-start="2165"&gt;
&lt;LI data-end="2190" data-start="2165" data-section-id="drru9u"&gt;Generate Cookie enabled&lt;/LI&gt;
&lt;LI data-end="2214" data-start="2191" data-section-id="prm2bt"&gt;Accept Cookie enabled&lt;/LI&gt;
&lt;LI data-end="2233" data-start="2215" data-section-id="u82eef"&gt;same certificate&lt;/LI&gt;
&lt;LI data-end="2249" data-start="2234" data-section-id="1vkhq8x"&gt;same lifetime&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="2267" data-start="2251"&gt;=&amp;gt; no difference&lt;/P&gt;
&lt;HR data-end="2272" data-start="2269" /&gt;
&lt;H1 data-end="2299" data-start="2274" data-section-id="ius7aa"&gt;Interesting observation&lt;/H1&gt;
&lt;P data-end="2436" data-start="2301"&gt;The problem does NOT occur when the full authentication flow is handled through the GP Credential Provider at the Windows login screen.&lt;/P&gt;
&lt;P data-end="2466" data-start="2438"&gt;The issue only happens with:&lt;/P&gt;
&lt;UL data-end="2537" data-start="2467"&gt;
&lt;LI data-end="2489" data-start="2467" data-section-id="6r8td3"&gt;normal Windows login&lt;/LI&gt;
&lt;LI data-end="2537" data-start="2490" data-section-id="1efnyuz"&gt;followed by automatic GP connection afterward&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="2561" data-start="2539"&gt;This makes us suspect:&lt;/P&gt;
&lt;UL data-end="2676" data-start="2562"&gt;
&lt;LI data-end="2590" data-start="2562" data-section-id="1iy48m4"&gt;credential retrieval issue&lt;/LI&gt;
&lt;LI data-end="2622" data-start="2591" data-section-id="br844w"&gt;WAM/PRT/WHfB-related behavior&lt;/LI&gt;
&lt;LI data-end="2676" data-start="2623" data-section-id="1x0m3yu"&gt;or possibly a bug in post-logon credential handling&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR data-end="2681" data-start="2678" /&gt;
&lt;H1 data-end="2693" data-start="2683" data-section-id="hh93l4"&gt;Question&lt;/H1&gt;
&lt;P data-end="2731" data-start="2695"&gt;Has anyone seen similar issues with:&lt;/P&gt;
&lt;UL data-end="2857" data-start="2732"&gt;
&lt;LI data-end="2742" data-start="2732" data-section-id="6w4a82"&gt;GP 6.3.x&lt;/LI&gt;
&lt;LI data-end="2771" data-start="2743" data-section-id="1m5mih4"&gt;Windows Hello for Business&lt;/LI&gt;
&lt;LI data-end="2804" data-start="2772" data-section-id="1ucwaqj"&gt;Duo SAML federated to Entra ID&lt;/LI&gt;
&lt;LI data-end="2820" data-start="2805" data-section-id="13zqozc"&gt;Prisma Access&lt;/LI&gt;
&lt;LI data-end="2857" data-start="2821" data-section-id="1i4a12d"&gt;&lt;CODE data-end="2857" data-start="2823"&gt;RetrieveGPCred failed. hr = 1168&lt;/CODE&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="2886" data-start="2859"&gt;Particularly interested in:&lt;/P&gt;
&lt;UL data-end="2965" data-start="2887"&gt;
&lt;LI data-end="2899" data-start="2887" data-section-id="8tgys8"&gt;known bugs&lt;/LI&gt;
&lt;LI data-end="2925" data-start="2900" data-section-id="cux1b7"&gt;recommended GP versions&lt;/LI&gt;
&lt;LI data-end="2939" data-start="2926" data-section-id="14npn09"&gt;workarounds&lt;/LI&gt;
&lt;LI data-end="2965" data-start="2940" data-section-id="rf9pby"&gt;known WAM / WHfB issues&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-is-only-node="" data-is-last-node="" data-end="2985" data-start="2967"&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2026 14:24:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-6-3-3-duo-saml-mfa-loop-after-normal-windows-login/m-p/1253925#M7377</guid>
      <dc:creator>Marco_DiFrancesco</dc:creator>
      <dc:date>2026-05-13T14:24:32Z</dc:date>
    </item>
  </channel>
</rss>

