<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GP -&amp;gt; SAML -&amp;gt; EntraID Windows users vs Mac user experience issues in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/gp-gt-saml-gt-entraid-windows-users-vs-mac-user-experience/m-p/586656#M2339</link>
    <description>&lt;P&gt;Apologies for that missing bit of information!&lt;BR /&gt;&lt;BR /&gt;We enabled default browser to support Yubikey as it seems the GP embedded is not compatible.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Appreciate the suggestions!&lt;/P&gt;</description>
    <pubDate>Tue, 14 May 2024 13:47:32 GMT</pubDate>
    <dc:creator>plupini</dc:creator>
    <dc:date>2024-05-14T13:47:32Z</dc:date>
    <item>
      <title>GP -&gt; SAML -&gt; EntraID Windows users vs Mac user experience issues</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/gp-gt-saml-gt-entraid-windows-users-vs-mac-user-experience/m-p/586383#M2334</link>
      <description>&lt;P&gt;Got a weird one and I'm on Mac so short of pestering my colleagues reaching out to the greater community while I wait on support to attempt to triage.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;GP client 6.2.3 - PAN 11.1.2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;GP setup;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;using default browser to support our yubikey users&lt;/LI&gt;
&lt;LI&gt;using auth override cookies
&lt;UL&gt;
&lt;LI&gt;portal creates&lt;/LI&gt;
&lt;LI&gt;gateway accepts&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Problem comes with a super annoying user experience issue on windows and end-users hate it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Windows client:&amp;nbsp; two tabs open in their browser when connecting. One says auth completed (yay) the other says auth failed (boo) - however users are connected fine. In the firewall monitor tab i see two outlier messages compared to our Mac users. An saml-out-of-band log and two logs that reflect the double browser. An auth success (fine great) and an auth failure with an empty username ( '').&lt;BR /&gt;&lt;BR /&gt;Mac just works w/o issue. No dual tabs and neither of the two logs mentioned.&lt;BR /&gt;&lt;BR /&gt;Anyone seen or experienced this? Were you able to resolve this?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2024 14:23:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/gp-gt-saml-gt-entraid-windows-users-vs-mac-user-experience/m-p/586383#M2334</guid>
      <dc:creator>plupini</dc:creator>
      <dc:date>2024-05-10T14:23:07Z</dc:date>
    </item>
    <item>
      <title>Re: GP -&gt; SAML -&gt; EntraID Windows users vs Mac user experience issues</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/gp-gt-saml-gt-entraid-windows-users-vs-mac-user-experience/m-p/586646#M2335</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/218799"&gt;@plupini&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One thing that is different about Entra SAML is that it already uses authentication cookies.&amp;nbsp; So, you do not need to configure Authentication Override on the NGFWs in order to avoid 2 MFA prompts like many other MFA configurations.&amp;nbsp; I would clear all of those check boxes on the portal and gateway and see what the behavior looks like.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On a similar note, the default cookie lifetime for Entra is 90 days.&amp;nbsp; I logged in once when we 1st set it up, and I didn't have to log in for days!&amp;nbsp; We later changed the lifetime for the Entra GP MFA app to 1 hour.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2024 12:25:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/gp-gt-saml-gt-entraid-windows-users-vs-mac-user-experience/m-p/586646#M2335</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-05-14T12:25:18Z</dc:date>
    </item>
    <item>
      <title>Re: GP -&gt; SAML -&gt; EntraID Windows users vs Mac user experience issues</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/gp-gt-saml-gt-entraid-windows-users-vs-mac-user-experience/m-p/586651#M2336</link>
      <description>&lt;P&gt;I'd be happy to try this change but what's odd is doesn't really explain why the experience changes simply from moving from embedded browser to the user's default browser. The embedded browser does not display this same behavior - neither in the logs or visibly to the end user.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's also impacting Windows machines solely. Mac users have no issues with default browser.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm doing this in an enterprise environment without much of a testing gateway to pound on (although maybe I can get support to).&lt;BR /&gt;&lt;BR /&gt;I'm likely going to be forced to roll back to embedded browser until support can confirm or deny this is a bug or something wrong with the configuration.&lt;BR /&gt;&lt;BR /&gt;Prior to switching to SAML we were using LDAP+Radius for auth+mfa. Overrides were needed for Yubikeys so admittedly some carryover but I'm going off a knowledge based article (will dig up and link once i find it again)&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2024 13:02:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/gp-gt-saml-gt-entraid-windows-users-vs-mac-user-experience/m-p/586651#M2336</guid>
      <dc:creator>plupini</dc:creator>
      <dc:date>2024-05-14T13:02:14Z</dc:date>
    </item>
    <item>
      <title>Re: GP -&gt; SAML -&gt; EntraID Windows users vs Mac user experience issues</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/gp-gt-saml-gt-entraid-windows-users-vs-mac-user-experience/m-p/586653#M2337</link>
      <description>&lt;P&gt;Step 2 :&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/5-2/globalprotect-app-new-features/new-features-released-in-gp-app/default-browser-for-saml-authentication" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/5-2/globalprotect-app-new-features/new-features-released-in-gp-app/default-browser-for-saml-authentication&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;In order for the default system browser for SAML authentication to not open multiple tabs for each connection, we recommend that you configure an authentication override. For more information, see&amp;nbsp;&lt;A class="xref" title="" href="https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-user-authentication/how-does-the-app-know-what-credentials-to-supply/cookie-authentication-on-the-portal-or-gateway" target="_blank" rel="noopener" data-scope="external" data-format="html" data-type=""&gt;Cookie Authentication on the Portal or Gateway&lt;/A&gt;.&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When in fact it does not seem to make difference on Windows. I'm wondering if a GP bug? Still dealing with tier1 support triaging questions sadly &lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2024 13:09:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/gp-gt-saml-gt-entraid-windows-users-vs-mac-user-experience/m-p/586653#M2337</guid>
      <dc:creator>plupini</dc:creator>
      <dc:date>2024-05-14T13:09:30Z</dc:date>
    </item>
    <item>
      <title>Re: GP -&gt; SAML -&gt; EntraID Windows users vs Mac user experience issues</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/gp-gt-saml-gt-entraid-windows-users-vs-mac-user-experience/m-p/586655#M2338</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/218799"&gt;@plupini&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I currently use Entra SAML for GP.&amp;nbsp; I do not have Authentication Override configured.&amp;nbsp; I do not get 2 login prompts.&amp;nbsp; I understand that for most MFA configurations you should configure Authentication Override in order to not get prompted twice.&amp;nbsp; As I mentioned, because Entra SAML uses its own authentication cookies, configuring Authentication Override is not needed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You didn't mention before that the embedded browser does not have the issue.&amp;nbsp; Like you, I have seen issues with the default browser and GP.&amp;nbsp; I would definitely switch to the embedded browser.&amp;nbsp; I have also seen the browser issues go away with a GP upgrade.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The current recommended version of GP for 6.2 is 6.2.2.&amp;nbsp; &lt;A href="https://live.paloaltonetworks.com/t5/customer-resources/support-pan-os-software-release-guidance/ta-p/258304" target="_blank"&gt;https://live.paloaltonetworks.com/t5/customer-resources/support-pan-os-software-release-guidance/ta-p/258304&lt;/A&gt;&amp;nbsp; It's generally best to stay with the recommended versions.&amp;nbsp; In this case, a downgrade may possibly help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2024 13:33:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/gp-gt-saml-gt-entraid-windows-users-vs-mac-user-experience/m-p/586655#M2338</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-05-14T13:33:42Z</dc:date>
    </item>
    <item>
      <title>Re: GP -&gt; SAML -&gt; EntraID Windows users vs Mac user experience issues</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/gp-gt-saml-gt-entraid-windows-users-vs-mac-user-experience/m-p/586656#M2339</link>
      <description>&lt;P&gt;Apologies for that missing bit of information!&lt;BR /&gt;&lt;BR /&gt;We enabled default browser to support Yubikey as it seems the GP embedded is not compatible.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Appreciate the suggestions!&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2024 13:47:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/gp-gt-saml-gt-entraid-windows-users-vs-mac-user-experience/m-p/586656#M2339</guid>
      <dc:creator>plupini</dc:creator>
      <dc:date>2024-05-14T13:47:32Z</dc:date>
    </item>
    <item>
      <title>Re: GP -&gt; SAML -&gt; EntraID Windows users vs Mac user experience issues</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/gp-gt-saml-gt-entraid-windows-users-vs-mac-user-experience/m-p/586676#M2340</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/218799"&gt;@plupini&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you!&amp;nbsp; It is just a suggestion.&amp;nbsp; Maybe it will help. It really does seem like a default browser issue as you say.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2024 16:17:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/gp-gt-saml-gt-entraid-windows-users-vs-mac-user-experience/m-p/586676#M2340</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-05-14T16:17:25Z</dc:date>
    </item>
  </channel>
</rss>

