03-11-2023 05:45 AM
Has anyone successfully implemented Windows Hello for Business with GlobalProtect in a Passwordless configuration. We in the middle of a Passwordless implementation. We are discovering that when you use your Biometric or PIN to authenticate, that GlobalProtect still relies on a password once signed into the PC. We have enabled Prelogon set up to use a machine certificate for GlobalProtect then on the User end we have Windows and SmartCard auth enabled. At Prelogon, the VPN connects with the machine cert, then the user enters their Biometric Gesture or PIN. We can see once in Windows; the portal is still authenticated with the Machine Cert and never hands off to the Logon which should use the User Cert with SmartCard Logon Purpose. We have Global Protect configured to use PINSSO, but it doesn't appear to work as the user still gets a password pop up in GlobalProtect. I am assuming it has something to do with the Credential Provider, the client, a config on the Portal, or a combination of all three. Please help if you have this implemented in your environment. Thank you in advance!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!