<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Force GlobalProtect client logout in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/force-globalprotect-client-logout/m-p/518105#M419</link>
    <description>&lt;DIV class="" style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: #000000;"&gt;Warning, this is a first post from a newbie user!&amp;nbsp; We are using cloud-managed Prisma Access and have GlobalProtect configured to use machine certificate and Azure SAML authentication for our users.&amp;nbsp; We configured the GlobalProtect App to use pre-logon, always-on access.&amp;nbsp; For most of our users this has worked with no issues.&amp;nbsp; There is one Windows laptop in a weird situation.&amp;nbsp; This client shows two different connections active at the same time in the Insights &amp;gt; Mobile Users - GlobalProtect &amp;gt; Devices of Connected Users list.&amp;nbsp; One of the logged-on users is the actual user's account, the other is pre-logon.&amp;nbsp; We think the way this happened is that last week the user established a GP session with his normal account and then, to test what happens when a new user logs in for the first time, did a switch-user logon on the laptop and logged on with a different account.&amp;nbsp; After doing so the user discovered that when he switched back to his normal account session on the laptop, he wasn't able to connect to connect to any internet resources.&amp;nbsp; Neither logging the test user account out of the laptop, refreshing the GP connection from his normal user account, signing out of GP from his normal user account, nor rebooting the laptop fixed his connection problem or removed the duplicate GP connections from the list on Prisma.&amp;nbsp;&amp;nbsp; He left his laptop powered off over the weekend and tried again this morning.&amp;nbsp; After his first logon using his normal account he experienced the same issue, but then tried a reboot and after that was able to login and access resources as expected.&amp;nbsp; Prisma still shows two different connections for this laptop.
&lt;DIV class="" style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: #000000;"&gt;&amp;nbsp;
&lt;DIV class="" style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: #000000;"&gt;All of that leads to my question.&amp;nbsp; I figured there has to be a way to force a specific client to disconnect/logout of GlobalProtect from cloud-managed Prisma, but I can't find it.&amp;nbsp; There are documents describing how to do that from Panorama-managed Prisma, but when I look at the equivalent location in the cloud-managed UI there is no logout option.&amp;nbsp; Is it hidden somewhere else, am I (a superuser) lacking some permission, or is forcing GP logouts not possible in cloud-managed Prisma at this time?&amp;nbsp;
&lt;DIV&gt;
&lt;DIV class="" style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: #000000;"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
    <pubDate>Mon, 17 Oct 2022 14:26:24 GMT</pubDate>
    <dc:creator>dintymoore</dc:creator>
    <dc:date>2022-10-17T14:26:24Z</dc:date>
    <item>
      <title>Force GlobalProtect client logout</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/force-globalprotect-client-logout/m-p/518105#M419</link>
      <description>&lt;DIV class="" style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: #000000;"&gt;Warning, this is a first post from a newbie user!&amp;nbsp; We are using cloud-managed Prisma Access and have GlobalProtect configured to use machine certificate and Azure SAML authentication for our users.&amp;nbsp; We configured the GlobalProtect App to use pre-logon, always-on access.&amp;nbsp; For most of our users this has worked with no issues.&amp;nbsp; There is one Windows laptop in a weird situation.&amp;nbsp; This client shows two different connections active at the same time in the Insights &amp;gt; Mobile Users - GlobalProtect &amp;gt; Devices of Connected Users list.&amp;nbsp; One of the logged-on users is the actual user's account, the other is pre-logon.&amp;nbsp; We think the way this happened is that last week the user established a GP session with his normal account and then, to test what happens when a new user logs in for the first time, did a switch-user logon on the laptop and logged on with a different account.&amp;nbsp; After doing so the user discovered that when he switched back to his normal account session on the laptop, he wasn't able to connect to connect to any internet resources.&amp;nbsp; Neither logging the test user account out of the laptop, refreshing the GP connection from his normal user account, signing out of GP from his normal user account, nor rebooting the laptop fixed his connection problem or removed the duplicate GP connections from the list on Prisma.&amp;nbsp;&amp;nbsp; He left his laptop powered off over the weekend and tried again this morning.&amp;nbsp; After his first logon using his normal account he experienced the same issue, but then tried a reboot and after that was able to login and access resources as expected.&amp;nbsp; Prisma still shows two different connections for this laptop.
&lt;DIV class="" style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: #000000;"&gt;&amp;nbsp;
&lt;DIV class="" style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: #000000;"&gt;All of that leads to my question.&amp;nbsp; I figured there has to be a way to force a specific client to disconnect/logout of GlobalProtect from cloud-managed Prisma, but I can't find it.&amp;nbsp; There are documents describing how to do that from Panorama-managed Prisma, but when I look at the equivalent location in the cloud-managed UI there is no logout option.&amp;nbsp; Is it hidden somewhere else, am I (a superuser) lacking some permission, or is forcing GP logouts not possible in cloud-managed Prisma at this time?&amp;nbsp;
&lt;DIV&gt;
&lt;DIV class="" style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: #000000;"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 17 Oct 2022 14:26:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/force-globalprotect-client-logout/m-p/518105#M419</guid>
      <dc:creator>dintymoore</dc:creator>
      <dc:date>2022-10-17T14:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: Force GlobalProtect client logout</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/force-globalprotect-client-logout/m-p/520070#M425</link>
      <description>&lt;P&gt;This sound like a RFE as Palo Alto may have just forgoten to expose this option in the cloud only managment interface. Please see:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/blogs/how-to-use-palo-alto-networks-new-feature-request/ba-p/409590" target="_blank"&gt;https://live.paloaltonetworks.com/t5/blogs/how-to-use-palo-alto-networks-new-feature-request/ba-p/409590&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Outside of that it sounds like your pre-logon window is not terminated right after the user logs in&amp;nbsp; as if &lt;SPAN&gt;&lt;SPAN class="richTextArea slds-text-longform tile__title red-txt"&gt;&lt;I&gt;"Pre-Logon Tunnel Rename Timeout (sec) (Windows Only)"&lt;/I&gt; to be a value of "0"&lt;/SPAN&gt;&lt;/SPAN&gt; this may fix the issue as mentioned in the official aricle below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H1 class="slds-text-heading_large"&gt;The gateway client settings is not properly selected when switching from pre-logon user to the logged on user&lt;/H1&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HBx0CAG&amp;amp;lang=en_US%E2%80%A9&amp;amp;refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HBx0CAG&amp;amp;lang=en_US%E2%80%A9&amp;amp;refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 21:03:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/force-globalprotect-client-logout/m-p/520070#M425</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2022-11-02T21:03:38Z</dc:date>
    </item>
  </channel>
</rss>

