12-02-2021 06:43 AM
The issue we are having is with Connect BEFORE Logon. With GlobalProtect 5.2.8, the browser window appears to be stuck between Azure AD and Duo MFA. We see the Azure AD credentials authenticate succesfully and the Microsoft prompt goes away (so that must be working), and we briefly see the Duo MFA Universal Prompt attempt to open, but it flashes on the screen for a second and then the GP window just shows a blank window. In the logs, the last thing we see GP do is open two Duo web service URLs. Then nothing until we cancel GlobalProtect. NOTE: I just tried 5.2.9 and it actually gets stuck earlier in the process, just after the user enters their Azure AD password. It just hands on the "enter password" screen like it never gets back a "succesful". In the 5.2.9 logs, i see the URL for the Azure AD login page, with the word BLOCK in front of it. Does that make any sense?
Any suggestions on how to troubleshoot this? Is it the cookies maybe?
09-22-2022 08:42 AM
This worked for me. Add your Duo API hostname into the registry key.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!