<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Microsoft Self-Service Password Reset (SSPR) / GP VPN with User Authentication in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-self-service-password-reset-sspr-gp-vpn-with-user/m-p/1223158#M123552</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/291074"&gt;@KrisPamphilon&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;Did you manage to get a working resolution, have just come across the same issue.&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/291074"&gt;@KrisPamphilon&lt;/a&gt;&amp;nbsp;sorry I missed your question.&amp;nbsp; Yes we did get this solved.&amp;nbsp; Although doing so in other customer configs/deployments might not be a viable option.&amp;nbsp; We ended up needing to allow the traffic to bypass the VPN / tunnel all together.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's been a while so I'm not super sure on the specifics, and suggest conferring with TAC, but the SSPR MSFT domain (&lt;SPAN&gt;passwordreset.microsoftonline.com -- there might be others) needs to be allowed to bypass the VPN.&amp;nbsp; We accomplished this from the "enforcer" app/config described here:&amp;nbsp;&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/5-1/globalprotect-app-new-features/new-features-released-in-gp-app/enforce-globalprotect-exclusions" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/5-1/globalprotect-app-new-features/new-features-released-in-gp-app/enforce-globalprotect-exclusions&lt;/A&gt;&amp;nbsp;in step 2:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Brandon_Wertz_0-1741370956444.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66463iF9A997FCE9560A79/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Brandon_Wertz_0-1741370956444.png" alt="Brandon_Wertz_0-1741370956444.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Of note, doing this presupposes having enforcer turned on, which might be a change to yours or another customer environment itself.&amp;nbsp; So step 1 could be you need to turn enforcer on with a second step being allowing IPs/domains to bypass VPN (which is described in step 2.)&amp;nbsp; This is what we did and it got SSPR working for us.&lt;/P&gt;</description>
    <pubDate>Fri, 07 Mar 2025 18:12:21 GMT</pubDate>
    <dc:creator>Brandon_Wertz</dc:creator>
    <dc:date>2025-03-07T18:12:21Z</dc:date>
    <item>
      <title>Microsoft Self-Service Password Reset (SSPR) / GP VPN with User Authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-self-service-password-reset-sspr-gp-vpn-with-user/m-p/573671#M115332</link>
      <description>&lt;P&gt;Just wanted to share in case others run into this.&amp;nbsp; My company has recently started to use Microsoft's SSPR process which is embedded into the Windows 10/11 OS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Specifics on how it works here:&amp;nbsp;&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/authentication/howto-sspr-windows" target="_blank"&gt;Self-service password reset for Windows devices - Microsoft Entra ID | Microsoft Learn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This specific section is going to be an issue for GP VPN environments with always on VPN with user authentication enforcement for the VPN tunnel:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"When users reset their password from the sign-in screen of a Windows 11 or 10 device, a low-privilege temporary account called&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;defaultuser1&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is created. This account is used to keep the password reset process secure.&lt;/P&gt;
&lt;P&gt;The account itself has a randomly generated password, which is validated against an organizations password policy, doesn't show up for device sign-in, and is automatically removed after the user resets their password. Multiple&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;defaultuser&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;profiles may exist but can be safely ignored."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With this action the GP client sees this user account logging into the OS.&amp;nbsp; Since this user is a local machine user and isn't a known user to GP's auth profile the user tunnel on VPN will fail which means the VPN is disconnected with no way for the user to complete the SSPR process.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Right now we're exploring creating a secondary authentication profile (Creating this account as local to the firewall/PAN) for GP which will include this user somehow in the hopes that the SSPR process doesn't break the VPN connectivity.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When we get this figured out I'll post the technical solution.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 18:30:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/microsoft-self-service-password-reset-sspr-gp-vpn-with-user/m-p/573671#M115332</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2024-01-19T18:30:50Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Self-Service Password Reset (SSPR) / GP VPN with User Authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-self-service-password-reset-sspr-gp-vpn-with-user/m-p/573733#M115345</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt;&amp;nbsp;, looking forward to your next post!&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 23:00:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/microsoft-self-service-password-reset-sspr-gp-vpn-with-user/m-p/573733#M115345</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2024-01-19T23:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Self-Service Password Reset (SSPR) / GP VPN with User Authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-self-service-password-reset-sspr-gp-vpn-with-user/m-p/581169#M116338</link>
      <description>Did you manage to get a working resolution, have just come across the same issue.</description>
      <pubDate>Thu, 21 Mar 2024 09:50:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/microsoft-self-service-password-reset-sspr-gp-vpn-with-user/m-p/581169#M116338</guid>
      <dc:creator>KrisPamphilon</dc:creator>
      <dc:date>2024-03-21T09:50:27Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Self-Service Password Reset (SSPR) / GP VPN with User Authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-self-service-password-reset-sspr-gp-vpn-with-user/m-p/1223158#M123552</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/291074"&gt;@KrisPamphilon&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;Did you manage to get a working resolution, have just come across the same issue.&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/291074"&gt;@KrisPamphilon&lt;/a&gt;&amp;nbsp;sorry I missed your question.&amp;nbsp; Yes we did get this solved.&amp;nbsp; Although doing so in other customer configs/deployments might not be a viable option.&amp;nbsp; We ended up needing to allow the traffic to bypass the VPN / tunnel all together.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's been a while so I'm not super sure on the specifics, and suggest conferring with TAC, but the SSPR MSFT domain (&lt;SPAN&gt;passwordreset.microsoftonline.com -- there might be others) needs to be allowed to bypass the VPN.&amp;nbsp; We accomplished this from the "enforcer" app/config described here:&amp;nbsp;&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/5-1/globalprotect-app-new-features/new-features-released-in-gp-app/enforce-globalprotect-exclusions" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/5-1/globalprotect-app-new-features/new-features-released-in-gp-app/enforce-globalprotect-exclusions&lt;/A&gt;&amp;nbsp;in step 2:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Brandon_Wertz_0-1741370956444.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66463iF9A997FCE9560A79/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Brandon_Wertz_0-1741370956444.png" alt="Brandon_Wertz_0-1741370956444.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Of note, doing this presupposes having enforcer turned on, which might be a change to yours or another customer environment itself.&amp;nbsp; So step 1 could be you need to turn enforcer on with a second step being allowing IPs/domains to bypass VPN (which is described in step 2.)&amp;nbsp; This is what we did and it got SSPR working for us.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 18:12:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/microsoft-self-service-password-reset-sspr-gp-vpn-with-user/m-p/1223158#M123552</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2025-03-07T18:12:21Z</dc:date>
    </item>
  </channel>
</rss>

