- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-13-2026 07:24 AM
Hi everyone,
we are currently facing a strange issue with GlobalProtect + Duo MFA and have been able to narrow it down quite a bit.
I wanted to check if anyone has already seen this behavior.
The authentication flow is:
GlobalProtect / Prisma Access
→ Cisco Duo SAML
→ Microsoft Entra ID
We are getting an MFA/SAML authentication loop, but only under specific conditions.
If the user authenticates via the GlobalProtect icon / Credential Provider on the Windows login screen and enters username/password there.
Result:
If the user logs into Windows normally first and GP connects afterward automatically.
It does not matter whether Windows login is done via:
Behavior:
In PanGPA.log we consistently see:
RetrieveGPCred failed. hr = 1168
=> no difference
=> no difference
=> no difference
=> no difference
The problem does NOT occur when the full authentication flow is handled through the GP Credential Provider at the Windows login screen.
The issue only happens with:
This makes us suspect:
Has anyone seen similar issues with:
RetrieveGPCred failed. hr = 1168Particularly interested in:
Thanks in advance!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

