<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: auth override cookie in Globalprotect in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/auth-override-cookie-in-globalprotect/m-p/1255338#M7398</link>
    <description>&lt;P&gt;without the cookies the users will need to authenticate every time they make a connection. depending on the SAML conditional access, the authentication may remain valid for an amount of time, or they will need to re-authenticate for _every_ connection (hopping to a new wifi SSID may already be enough to trigger a re-auth with a very strict conditional access)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if both portal and gateway are set to not use cookies, users will also need to authenticate twice, once for the portal and once for the gateway&lt;/P&gt;</description>
    <pubDate>Wed, 03 Jun 2026 21:34:42 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2026-06-03T21:34:42Z</dc:date>
    <item>
      <title>auth override cookie in Globalprotect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/auth-override-cookie-in-globalprotect/m-p/1255157#M7395</link>
      <description>&lt;P&gt;The clients that connect to our&amp;nbsp; PanOS 11.1 GP gateway are Windows 11 corporate domain members. Currently, GP rarely prompts for a user auth. I gather it uses SAML from the users Windows login.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our gateway has&amp;nbsp;generate and accept cookie for authentication override set to yes.&amp;nbsp; If i was to disable these, what would the effect be?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2026 05:55:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/auth-override-cookie-in-globalprotect/m-p/1255157#M7395</guid>
      <dc:creator>JimMcGrady</dc:creator>
      <dc:date>2026-06-02T05:55:51Z</dc:date>
    </item>
    <item>
      <title>Re: auth override cookie in Globalprotect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/auth-override-cookie-in-globalprotect/m-p/1255338#M7398</link>
      <description>&lt;P&gt;without the cookies the users will need to authenticate every time they make a connection. depending on the SAML conditional access, the authentication may remain valid for an amount of time, or they will need to re-authenticate for _every_ connection (hopping to a new wifi SSID may already be enough to trigger a re-auth with a very strict conditional access)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if both portal and gateway are set to not use cookies, users will also need to authenticate twice, once for the portal and once for the gateway&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2026 21:34:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/auth-override-cookie-in-globalprotect/m-p/1255338#M7398</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2026-06-03T21:34:42Z</dc:date>
    </item>
  </channel>
</rss>

