<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect &amp;quot;Single Sign on&amp;quot; with Windows Hello on Windows 10 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-quot-single-sign-on-quot-with-windows-hello-on/m-p/176573#M55202</link>
    <description>&lt;P&gt;Hi Remo,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Potential workaround may be relying on Kerberos SSO. Users can perform Windows Hello to authenticate to the device (and AD/Kerberos), and then use Kerberos SSO to authenticate to GP. Some details are mentioned in the last comment of this post:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/SME-GlobalProtect-Discussions/Is-it-possible-to-use-Windows-10-quot-Windows-Hello-quot-for/m-p/124959/" target="_blank"&gt;https://live.paloaltonetworks.com/t5/SME-GlobalProtect-Discussions/Is-it-possible-to-use-Windows-10-quot-Windows-Hello-quot-for/m-p/124959/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nikola M&lt;/P&gt;</description>
    <pubDate>Thu, 14 Sep 2017 16:00:59 GMT</pubDate>
    <dc:creator>nimark</dc:creator>
    <dc:date>2017-09-14T16:00:59Z</dc:date>
    <item>
      <title>Global Protect "Single Sign on" with Windows Hello on Windows 10</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-quot-single-sign-on-quot-with-windows-hello-on/m-p/157569#M51667</link>
      <description>Hi everyone,&lt;BR /&gt;&lt;BR /&gt;I have a situation as described in the title of this post. As you probably know Global Protect installs his own Credential Provider in Windows which has to be chosen by the user. It is also possible to force the Global Protect Credential Provider, but the point is, it has to be used in order to enable single sign on for the user.&lt;BR /&gt;&lt;BR /&gt;This now breaks the whole thing when combined with Windows Hello (Iris Scan, Fingerprint), because Windows Hello has his own credential provider. So in a default Global Protect configuration with pre-logon enabled (certificate profile and LDAPs authentication profile), either Global Protect single sign on or Windows Hello is working as expected:&lt;BR /&gt;- log in with GP CP: VPN single sign on is working but not Windows Hello&lt;BR /&gt;- log in with WH CP: Windows Hello is working but the user has to enter his credentials manually to Global Protect&lt;BR /&gt;&lt;BR /&gt;To get the comfort of both worlds I was now thinking of a setup with the following requirements:&lt;BR /&gt;- Global Protect ONLY authenticates with a certificate profile&lt;BR /&gt;- User-ID Agents check Active Directory Logins for the VPN IP range&lt;BR /&gt;- Firewall is configured to get the User-to-IP mappings from the User-ID agent&lt;BR /&gt;- Firewall allows access to the AD (for logging in), antivirusupdates, windows updates to the pro-logon user&lt;BR /&gt;- all subsequent firewallrules are created for actual users, so they become "active" as soon the user-to-ip-mapping is known by the firewall&lt;BR /&gt;&lt;BR /&gt;I have already tested this solution and it works as expected. Users can log in simply by "looking at their laptops" and there is no need to bother for reentering the credentials or making sure that Global Protect is set as default Credential Provider.&lt;BR /&gt;&lt;BR /&gt;My question now for you all is: Am I missing some security issues with not using an authentication profile and relying on the login event in active directory?&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Remo</description>
      <pubDate>Sun, 21 May 2017 08:49:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-quot-single-sign-on-quot-with-windows-hello-on/m-p/157569#M51667</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-05-21T08:49:35Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect "Single Sign on" with Windows Hello on Windows 10</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-quot-single-sign-on-quot-with-windows-hello-on/m-p/176573#M55202</link>
      <description>&lt;P&gt;Hi Remo,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Potential workaround may be relying on Kerberos SSO. Users can perform Windows Hello to authenticate to the device (and AD/Kerberos), and then use Kerberos SSO to authenticate to GP. Some details are mentioned in the last comment of this post:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/SME-GlobalProtect-Discussions/Is-it-possible-to-use-Windows-10-quot-Windows-Hello-quot-for/m-p/124959/" target="_blank"&gt;https://live.paloaltonetworks.com/t5/SME-GlobalProtect-Discussions/Is-it-possible-to-use-Windows-10-quot-Windows-Hello-quot-for/m-p/124959/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nikola M&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2017 16:00:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-quot-single-sign-on-quot-with-windows-hello-on/m-p/176573#M55202</guid>
      <dc:creator>nimark</dc:creator>
      <dc:date>2017-09-14T16:00:59Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect "Single Sign on" with Windows Hello on Windows 10</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-quot-single-sign-on-quot-with-windows-hello-on/m-p/184053#M56480</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What did you end up doing? What authentcation profile did you use ldap or radius? Can I use radius?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2017 02:35:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-quot-single-sign-on-quot-with-windows-hello-on/m-p/184053#M56480</guid>
      <dc:creator>junior_r</dc:creator>
      <dc:date>2017-10-27T02:35:05Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect "Single Sign on" with Windows Hello on Windows 10</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-quot-single-sign-on-quot-with-windows-hello-on/m-p/448145#M100788</link>
      <description>&lt;P&gt;Hello Remo,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found what you have configured is very interesting, could you please&amp;nbsp; share how did you make all this configurations step by step with screenshot&amp;nbsp; ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 09:40:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-quot-single-sign-on-quot-with-windows-hello-on/m-p/448145#M100788</guid>
      <dc:creator>MoAlawad</dc:creator>
      <dc:date>2021-11-17T09:40:00Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect "Single Sign on" with Windows Hello on Windows 10</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-quot-single-sign-on-quot-with-windows-hello-on/m-p/589918#M117548</link>
      <description>&lt;P&gt;Hello Remo,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you willing to share your configuration with us?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jun 2024 17:38:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-quot-single-sign-on-quot-with-windows-hello-on/m-p/589918#M117548</guid>
      <dc:creator>Tom_Buscemi</dc:creator>
      <dc:date>2024-06-19T17:38:20Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect "Single Sign on" with Windows Hello on Windows 10</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-quot-single-sign-on-quot-with-windows-hello-on/m-p/589922#M117551</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/329170"&gt;@Tom_Buscemi&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Hello Remo,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you willing to share your configuration with us?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;BR /&gt;You're probably better off starting your own thread with a specific issue or question you might have.&amp;nbsp; This thread being almost 7 years old there is a tremendous difference in functionality between the GP client and the Windows OS.&amp;nbsp; Especially with Windows Hello For Business now existing and functioning differently than the legacy Windows Hello.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jun 2024 18:09:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-quot-single-sign-on-quot-with-windows-hello-on/m-p/589922#M117551</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2024-06-19T18:09:17Z</dc:date>
    </item>
  </channel>
</rss>

