<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why is Connect Before Logon hidden behind a manual PanGPS -registerplap command? in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/why-is-connect-before-logon-hidden-behind-a-manual-pangps/m-p/1263697#M7527</link>
    <description>&lt;P&gt;Can someone at PAN explain the design decision here?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The GlobalProtect portal exposes an impressive collection of settings—some useful, some spectacularly niche. The MSI also accepts enough properties to make deployment engineering its own part-time job. Yet enabling Connect Before Logon/PLAP somehow requires administrators to run this separately on every endpoint:&lt;/P&gt;
&lt;P&gt;PanGPS.exe -registerplap&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is apparently no documented MSI property, no portal Agent setting, and no checkbox during installation. Just a privileged, post-install command that customers are expected to discover and then deploy separately.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is especially baffling because PLAP is precisely the kind of feature enterprises need to deploy centrally. Its entire purpose is to help remote users establish connectivity from the Windows sign-in screen—often because they changed their domain password elsewhere and can no longer sign in with cached credentials. At that point, asking us to bolt a custom registration script onto the installation feels less like enterprise management and more like an Easter egg hunt.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Meanwhile, the installer has historically been quite enthusiastic about installing the regular SSO credential provider unless explicitly told not to. So the component we don’t want touching the Windows sign-in experience gets an MSI option, while the narrowly scoped Network Sign-In provider we do want requires an undocumented-looking command-line ritual afterward.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For 2000+ endpoints, “just run -registerplap” is not a deployment strategy. Yes, we can build a SYSTEM-context remediation script, check the registry, run the command, verify it, log the result, and wait for a reboot. We can also write our own installer if sufficiently provoked. The question is why customers should need to manufacture lifecycle management for a supported GlobalProtect feature.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could PAN please add at least one of the following?&lt;/P&gt;
&lt;P&gt;A documented MSI property such as REGISTERPLAP=YES.&lt;BR /&gt;A Portal Agent setting that instructs PanGPS to register PLAP locally.&lt;BR /&gt;A supported deployment option that registers PLAP while explicitly leaving the standard SSO credential provider disabled.&lt;BR /&gt;Proper detection, remediation, and removal documentation for enterprise deployments.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;GlobalProtect already has centralized configuration and an enterprise installer. Making PLAP centrally deployable seems like it should have been part of the feature—not a scavenger hunt left to every customer with more than one computer.&lt;/P&gt;</description>
    <pubDate>Sat, 05 Sep 2026 01:26:57 GMT</pubDate>
    <dc:creator>NickAssar</dc:creator>
    <dc:date>2026-09-05T01:26:57Z</dc:date>
    <item>
      <title>Why is Connect Before Logon hidden behind a manual PanGPS -registerplap command?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/why-is-connect-before-logon-hidden-behind-a-manual-pangps/m-p/1263697#M7527</link>
      <description>&lt;P&gt;Can someone at PAN explain the design decision here?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The GlobalProtect portal exposes an impressive collection of settings—some useful, some spectacularly niche. The MSI also accepts enough properties to make deployment engineering its own part-time job. Yet enabling Connect Before Logon/PLAP somehow requires administrators to run this separately on every endpoint:&lt;/P&gt;
&lt;P&gt;PanGPS.exe -registerplap&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is apparently no documented MSI property, no portal Agent setting, and no checkbox during installation. Just a privileged, post-install command that customers are expected to discover and then deploy separately.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is especially baffling because PLAP is precisely the kind of feature enterprises need to deploy centrally. Its entire purpose is to help remote users establish connectivity from the Windows sign-in screen—often because they changed their domain password elsewhere and can no longer sign in with cached credentials. At that point, asking us to bolt a custom registration script onto the installation feels less like enterprise management and more like an Easter egg hunt.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Meanwhile, the installer has historically been quite enthusiastic about installing the regular SSO credential provider unless explicitly told not to. So the component we don’t want touching the Windows sign-in experience gets an MSI option, while the narrowly scoped Network Sign-In provider we do want requires an undocumented-looking command-line ritual afterward.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For 2000+ endpoints, “just run -registerplap” is not a deployment strategy. Yes, we can build a SYSTEM-context remediation script, check the registry, run the command, verify it, log the result, and wait for a reboot. We can also write our own installer if sufficiently provoked. The question is why customers should need to manufacture lifecycle management for a supported GlobalProtect feature.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could PAN please add at least one of the following?&lt;/P&gt;
&lt;P&gt;A documented MSI property such as REGISTERPLAP=YES.&lt;BR /&gt;A Portal Agent setting that instructs PanGPS to register PLAP locally.&lt;BR /&gt;A supported deployment option that registers PLAP while explicitly leaving the standard SSO credential provider disabled.&lt;BR /&gt;Proper detection, remediation, and removal documentation for enterprise deployments.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;GlobalProtect already has centralized configuration and an enterprise installer. Making PLAP centrally deployable seems like it should have been part of the feature—not a scavenger hunt left to every customer with more than one computer.&lt;/P&gt;</description>
      <pubDate>Sat, 05 Sep 2026 01:26:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/why-is-connect-before-logon-hidden-behind-a-manual-pangps/m-p/1263697#M7527</guid>
      <dc:creator>NickAssar</dc:creator>
      <dc:date>2026-09-05T01:26:57Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Connect Before Logon hidden behind a manual PanGPS -registerplap command?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/why-is-connect-before-logon-hidden-behind-a-manual-pangps/m-p/1263709#M7529</link>
      <description>&lt;P&gt;My 2 cents:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The always-on (pre-logon) option is very easy to deploy and makes sure the device is _always_ connected without user interaction. PLAP on the other hand keeps the laptops disconnected until the user either uses 'connect before logon' manually, or logs in. both of these options are incompatible with eachother so it may be by choice that PLAP has been given a backseat: available but only to the specialists that actually want/need it for a specific purpose over pre-logon&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In regards to your request list, I'd recommend reaching out to your sales team to open a feature request. That way they'll actually be reviewed.&lt;/P&gt;</description>
      <pubDate>Sun, 06 Sep 2026 08:44:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/why-is-connect-before-logon-hidden-behind-a-manual-pangps/m-p/1263709#M7529</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2026-09-06T08:44:43Z</dc:date>
    </item>
  </channel>
</rss>

