<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Silent deployment of GlobalProtect without auto launch? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/silent-deployment-of-globalprotect-without-auto-launch/m-p/159307#M52098</link>
    <description>&lt;P&gt;Under macOS, I have two&amp;nbsp;options. Either remove the KeepAlive and RunAtLoad keys&amp;nbsp;from the ...pangpa.plist LaunchAgent (essentially disabling the auto launch, but leaving the enabled plist in place), or removing that LaunchAgent entirely.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since it does not auto launch until login, then deployment scripting can handle that fairly easily.&lt;/P&gt;&lt;P&gt;Issuing two defaults commands to remove the keys, or replace the keys, is quick and seemingly painless.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As the prepopulation of the server address is actually working under macOS, this is acceptable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not so easy on the Windows side though, as it both fails to prepopulate the server address from the registry on first launch, but it also auto launches upon successful install. &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 02 Jun 2017 22:47:41 GMT</pubDate>
    <dc:creator>mwineke</dc:creator>
    <dc:date>2017-06-02T22:47:41Z</dc:date>
    <item>
      <title>Silent deployment of GlobalProtect without auto launch?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/silent-deployment-of-globalprotect-without-auto-launch/m-p/159234#M52075</link>
      <description>&lt;P&gt;I am deploying Global Protect agent 4.0.0-90, but it auto launches after installation.&lt;/P&gt;&lt;P&gt;I'd like it to be entirely silent. No auto launch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a flag I've not seen for this?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2017 17:45:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/silent-deployment-of-globalprotect-without-auto-launch/m-p/159234#M52075</guid>
      <dc:creator>mwineke</dc:creator>
      <dc:date>2017-06-02T17:45:45Z</dc:date>
    </item>
    <item>
      <title>Re: Silent deployment of GlobalProtect without auto launch?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/silent-deployment-of-globalprotect-without-auto-launch/m-p/159307#M52098</link>
      <description>&lt;P&gt;Under macOS, I have two&amp;nbsp;options. Either remove the KeepAlive and RunAtLoad keys&amp;nbsp;from the ...pangpa.plist LaunchAgent (essentially disabling the auto launch, but leaving the enabled plist in place), or removing that LaunchAgent entirely.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since it does not auto launch until login, then deployment scripting can handle that fairly easily.&lt;/P&gt;&lt;P&gt;Issuing two defaults commands to remove the keys, or replace the keys, is quick and seemingly painless.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As the prepopulation of the server address is actually working under macOS, this is acceptable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not so easy on the Windows side though, as it both fails to prepopulate the server address from the registry on first launch, but it also auto launches upon successful install. &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2017 22:47:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/silent-deployment-of-globalprotect-without-auto-launch/m-p/159307#M52098</guid>
      <dc:creator>mwineke</dc:creator>
      <dc:date>2017-06-02T22:47:41Z</dc:date>
    </item>
    <item>
      <title>Re: Silent deployment of GlobalProtect without auto launch?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/silent-deployment-of-globalprotect-without-auto-launch/m-p/159515#M52131</link>
      <description>&lt;P&gt;Short of input from fellow Global Protect deployment techs, I've found one way to pre-populate the portal field, though quite a bit more involved and resource intensive, it "looks" fairly straight forward:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-predefine-Global-Protect-portal-address-using-Microsoft/ta-p/149512" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-predefine-Global-Protect-portal-address-using-Microsoft/ta-p/149512&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone have any experience otherwise?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2017 18:59:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/silent-deployment-of-globalprotect-without-auto-launch/m-p/159515#M52131</guid>
      <dc:creator>mwineke</dc:creator>
      <dc:date>2017-06-05T18:59:12Z</dc:date>
    </item>
    <item>
      <title>Re: Silent deployment of GlobalProtect without auto launch?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/silent-deployment-of-globalprotect-without-auto-launch/m-p/159557#M52133</link>
      <description>&lt;P&gt;Do you need to do this on corporate computers or for external BYOD computers?&lt;BR /&gt;I assume this autostart is to get all the additional configurations from the portal right at the beginning ... but I understand your problem. We now simply live with this login window after installation. Because we use SSO this login is not that big an issue.&lt;BR /&gt;&lt;BR /&gt;I have now read again the documentation and found something what's may be worth a try (requires the use of GP SSO on computers where you/your comany controlls the software installations):&lt;BR /&gt;With the msiexec insallation method try to set SSO to enabled and in addition set the option for prompting for credentials when SSO fails to false.&lt;BR /&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/globalprotect-clients/deploy-agent-settings-transparently/customizable-agent-settings/agent-behavior-options#id51e0e000-9cce-425d-a4fd-e7fe51e1c8fb" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/globalprotect-clients/deploy-agent-settings-transparently/customizable-agent-settings/agent-behavior-options#id51e0e000-9cce-425d-a4fd-e7fe51e1c8fb&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2017 22:30:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/silent-deployment-of-globalprotect-without-auto-launch/m-p/159557#M52133</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-06-05T22:30:05Z</dc:date>
    </item>
    <item>
      <title>Re: Silent deployment of GlobalProtect without auto launch?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/silent-deployment-of-globalprotect-without-auto-launch/m-p/159569#M52136</link>
      <description>&lt;P&gt;Nope. My found solution didn't work. Still comes up blank after push install. &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2017 20:48:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/silent-deployment-of-globalprotect-without-auto-launch/m-p/159569#M52136</guid>
      <dc:creator>mwineke</dc:creator>
      <dc:date>2017-06-05T20:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: Silent deployment of GlobalProtect without auto launch?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/silent-deployment-of-globalprotect-without-auto-launch/m-p/159570#M52137</link>
      <description>&lt;P&gt;Will give it a try. Thanks vsys_remo. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2017 20:49:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/silent-deployment-of-globalprotect-without-auto-launch/m-p/159570#M52137</guid>
      <dc:creator>mwineke</dc:creator>
      <dc:date>2017-06-05T20:49:43Z</dc:date>
    </item>
    <item>
      <title>Re: Silent deployment of GlobalProtect without auto launch?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/silent-deployment-of-globalprotect-without-auto-launch/m-p/159580#M52139</link>
      <description>&lt;P&gt;Still no luck. Came up blank.&lt;/P&gt;&lt;P&gt;&amp;lt;Edit: Bah! I set the use-sso to yes in the msi. I did not try using the msiexec command. Will try...&amp;gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is for enterprise deployment to the organization owned and managed endpoints.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our end users don't want to be notified of anything that doesn't specifically pertain to them, and they also freak out when something unusual happens (like an unknown software product demands their attention).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Typically, our deployments are entirely silent. Nothing pops up on their screens unexpectedly telling them something is going to happen, or has happened. An unknown (to them) software product popping up asking for an unknown portal address, to connect to who knows what for an unknown purpose is likely to generate many Help Desk calls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ideally, the software is deployed silently, and it's there waiting for them to either use it, or not. We're actually fine with the portal address not being populated, but the autolaunch is more problematic.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2017 21:20:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/silent-deployment-of-globalprotect-without-auto-launch/m-p/159580#M52139</guid>
      <dc:creator>mwineke</dc:creator>
      <dc:date>2017-06-05T21:20:52Z</dc:date>
    </item>
    <item>
      <title>Re: Silent deployment of GlobalProtect without auto launch?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/silent-deployment-of-globalprotect-without-auto-launch/m-p/159855#M52178</link>
      <description>&lt;P&gt;Okay. I was able to pre-populate the Portal address (using the MSI editor Orca instructions I posted previously), and in combination with CANCHANGEPORTAL="no", it now pops up with the login window (which has a "Cancel" button. Yay!).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The autolaunch is still undesirable, but at least it's not asking for a portal address the user would not necessarily know, with only a "Connect" button.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Progress!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did try pushing a reg delete for the auto launch, but that does not appear to work.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 18:31:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/silent-deployment-of-globalprotect-without-auto-launch/m-p/159855#M52178</guid>
      <dc:creator>mwineke</dc:creator>
      <dc:date>2017-06-06T18:31:01Z</dc:date>
    </item>
    <item>
      <title>Re: Silent deployment of GlobalProtect without auto launch?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/silent-deployment-of-globalprotect-without-auto-launch/m-p/159867#M52181</link>
      <description>&lt;P&gt;Did you try with the options I mentionned?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 19:16:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/silent-deployment-of-globalprotect-without-auto-launch/m-p/159867#M52181</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-06-06T19:16:56Z</dc:date>
    </item>
    <item>
      <title>Re: Silent deployment of GlobalProtect without auto launch?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/silent-deployment-of-globalprotect-without-auto-launch/m-p/159920#M52191</link>
      <description>&lt;P&gt;Yep. Still auto launches after install.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2017 00:26:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/silent-deployment-of-globalprotect-without-auto-launch/m-p/159920#M52191</guid>
      <dc:creator>mwineke</dc:creator>
      <dc:date>2017-06-07T00:26:07Z</dc:date>
    </item>
    <item>
      <title>Re: Silent deployment of GlobalProtect without auto launch?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/silent-deployment-of-globalprotect-without-auto-launch/m-p/160099#M52218</link>
      <description>&lt;P&gt;It does work! I had a typo in the "&lt;SPAN&gt;prompting for credentials" bit. Whew! Thanks, vsys_remo!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 00:05:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/silent-deployment-of-globalprotect-without-auto-launch/m-p/160099#M52218</guid>
      <dc:creator>mwineke</dc:creator>
      <dc:date>2017-06-08T00:05:15Z</dc:date>
    </item>
    <item>
      <title>Re: Silent deployment of GlobalProtect without auto launch?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/silent-deployment-of-globalprotect-without-auto-launch/m-p/170096#M53981</link>
      <description>&lt;P&gt;Turning off prompting for credentials when SSO fails seems really problematic to me.&amp;nbsp; It is not uncommon for the default credential provider to get switched from GP back to Windows, in which case GP will just fail to bring up the VPN if prompting is turned off.&amp;nbsp; I guess I can kludge a way to turn it off for installation, then turn it back on again afterward, but it would really be better if there were just an MSI property that would stop the Agent from launching on installation.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Aug 2017 17:19:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/silent-deployment-of-globalprotect-without-auto-launch/m-p/170096#M53981</guid>
      <dc:creator>JerrySully</dc:creator>
      <dc:date>2017-08-04T17:19:40Z</dc:date>
    </item>
    <item>
      <title>Re: Silent deployment of GlobalProtect without auto launch?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/silent-deployment-of-globalprotect-without-auto-launch/m-p/229022#M65831</link>
      <description>&lt;P&gt;Combination of PORTAL and CONNECTMETHOD public properties worked for me with a GlobalProtect 4.1 install.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;msiexec.exe /i GlobalProtect-4.1.4.msi /quiet PORTAL="vpn.acme.com" CONNECTMETHOD="on-demand"&lt;/PRE&gt;&lt;P&gt;Installs silently, does &lt;U&gt;not&lt;/U&gt; auto-launch/auto-connect to the defined portal after silent install. Tested against GlobalProtect 4.1.4.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Aug 2018 14:13:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/silent-deployment-of-globalprotect-without-auto-launch/m-p/229022#M65831</guid>
      <dc:creator>JohnUrbanek</dc:creator>
      <dc:date>2018-08-31T14:13:39Z</dc:date>
    </item>
  </channel>
</rss>

