<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Pre-Logon Behavior with SAML Login in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pre-logon-behavior-with-saml-login/m-p/1265137#M7562</link>
    <description>&lt;P&gt;I recently found interesting behavior in GlobalProtect with pre-logon when using SAML. I started off by following these instructions:&amp;nbsp;&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/administration/globalprotect-quick-configs/remote-access-vpn-with-pre-logon?utm_source=chatgpt.com" target="_self" rel="nofollow noreferrer"&gt;Remote Access VPN with Pre-Logon&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The customer I was working with had certificates in the user-store they did not want to access during pre-logon or user login. We specified "Machine" in the "Client Certificate Store Lookup" App setting for both the pre-logon and user login app configs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Despite setting this, the GlobalProtect gateway connection still attempted to access the user-store. I was able to test this by importing&amp;nbsp;the user certificate with Windows strong private key protection enabled, causing Windows to require interactive user approval whenever an application attempted to use the certificate’s private key.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my setup, I had only one gateway for both the pre-logon and user login. The authentication method was Microsoft Entra as a SAML Identity Provider. The Client Authentication setting "Allow Authentication with User Credentials OR Client Certificate" was set to "Yes." Therefore, the login phase itself does not need access to a certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To solve this, I separated out the gateways into two. The pre-logon gateway had no Client Authentication set. The Certificate Profile set in the Global Protect Gateway's Authentication tab was the profile with the Certificate Authority that signed the machine certificates in the machine store. The user login gateway had Client Authentication with the SAML Identity Provider Authentication Profile and "none" set for the Certificate Profile.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This means, when the login flow accessed the gateway during user login, it would search the user-store despite having "Machine" set in "Client Certificate Store Lookup" for both Portal Agent App configurations. I began to suspect this was due to the Embedded Browser (Microsoft WebView2). To explore this I changed the Client Authentication method in both the Portal and Gateway to a Local Database Authentication Profile. This change, indeed, stopped the flow from looking in the user-store.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Based on my investigation, the Embedded Browser will look into the user-store of a Windows machine during user logon if a Certificate Profile is set in the Gateway's Authentication tab. This will happen even if Machine is set in the "Client Certificate Store Lookup" of the corresponding Agent App configuration. The only way to resolve this is to separate the pre-logon gateway from the user login gateway when setting up GlobalProtect with Pre-Logon.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I completed this entire setup and show the pop-up indicating searches through the user-store here:&amp;nbsp;&lt;A href="https://youtu.be/6KHkkMr0SCI" target="_blank"&gt;https://youtu.be/6KHkkMr0SCI&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2026 16:43:22 GMT</pubDate>
    <dc:creator>WBelleman1</dc:creator>
    <dc:date>2026-09-28T16:43:22Z</dc:date>
    <item>
      <title>Pre-Logon Behavior with SAML Login</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pre-logon-behavior-with-saml-login/m-p/1265137#M7562</link>
      <description>&lt;P&gt;I recently found interesting behavior in GlobalProtect with pre-logon when using SAML. I started off by following these instructions:&amp;nbsp;&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/administration/globalprotect-quick-configs/remote-access-vpn-with-pre-logon?utm_source=chatgpt.com" target="_self" rel="nofollow noreferrer"&gt;Remote Access VPN with Pre-Logon&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The customer I was working with had certificates in the user-store they did not want to access during pre-logon or user login. We specified "Machine" in the "Client Certificate Store Lookup" App setting for both the pre-logon and user login app configs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Despite setting this, the GlobalProtect gateway connection still attempted to access the user-store. I was able to test this by importing&amp;nbsp;the user certificate with Windows strong private key protection enabled, causing Windows to require interactive user approval whenever an application attempted to use the certificate’s private key.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my setup, I had only one gateway for both the pre-logon and user login. The authentication method was Microsoft Entra as a SAML Identity Provider. The Client Authentication setting "Allow Authentication with User Credentials OR Client Certificate" was set to "Yes." Therefore, the login phase itself does not need access to a certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To solve this, I separated out the gateways into two. The pre-logon gateway had no Client Authentication set. The Certificate Profile set in the Global Protect Gateway's Authentication tab was the profile with the Certificate Authority that signed the machine certificates in the machine store. The user login gateway had Client Authentication with the SAML Identity Provider Authentication Profile and "none" set for the Certificate Profile.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This means, when the login flow accessed the gateway during user login, it would search the user-store despite having "Machine" set in "Client Certificate Store Lookup" for both Portal Agent App configurations. I began to suspect this was due to the Embedded Browser (Microsoft WebView2). To explore this I changed the Client Authentication method in both the Portal and Gateway to a Local Database Authentication Profile. This change, indeed, stopped the flow from looking in the user-store.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Based on my investigation, the Embedded Browser will look into the user-store of a Windows machine during user logon if a Certificate Profile is set in the Gateway's Authentication tab. This will happen even if Machine is set in the "Client Certificate Store Lookup" of the corresponding Agent App configuration. The only way to resolve this is to separate the pre-logon gateway from the user login gateway when setting up GlobalProtect with Pre-Logon.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I completed this entire setup and show the pop-up indicating searches through the user-store here:&amp;nbsp;&lt;A href="https://youtu.be/6KHkkMr0SCI" target="_blank"&gt;https://youtu.be/6KHkkMr0SCI&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2026 16:43:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pre-logon-behavior-with-saml-login/m-p/1265137#M7562</guid>
      <dc:creator>WBelleman1</dc:creator>
      <dc:date>2026-09-28T16:43:22Z</dc:date>
    </item>
    <item>
      <title>Re: Pre-Logon Behavior with SAML Login</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pre-logon-behavior-with-saml-login/m-p/1265169#M7564</link>
      <description>&lt;P&gt;Which versions do you use?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2026 04:14:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pre-logon-behavior-with-saml-login/m-p/1265169#M7564</guid>
      <dc:creator>M.Falk310364</dc:creator>
      <dc:date>2026-09-29T04:14:16Z</dc:date>
    </item>
    <item>
      <title>Re: Pre-Logon Behavior with SAML Login</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pre-logon-behavior-with-saml-login/m-p/1265299#M7569</link>
      <description>&lt;P&gt;Thank you for your response. In this setup it was PAN-OS: 11.1.10-h30 and GlobalProtect: 6.2.8-1045.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2026 20:20:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/pre-logon-behavior-with-saml-login/m-p/1265299#M7569</guid>
      <dc:creator>WBelleman1</dc:creator>
      <dc:date>2026-09-29T20:20:49Z</dc:date>
    </item>
  </channel>
</rss>

