- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-30-2025 04:33 AM
Hey there,
I have an issue trying to implement Globalprotect authentification via Azure MFA SAML. Our goal is that the user is asked to login with MFA everytime he tries to connect to our portal, which doesn't work. Basically the first time the user is trying to connect to our portal the user get's redirected over his browser to the Microsoft login page and asked to login with his user and MFA, which works fine like expected.
But when the user disconnects from Globalprotect, logsoff his user in Windows or even restarts the computer the user is not prompted anymore when he is connecting to our portal, meaning there is no authentication prompt whatsoever for an infinitive time, which is a security risk for us. The only way the user is redirected to Microsoft again to authenticate if the user has connected to another portal between.
Things i tried:
I turned of any authentication cookie override settings on the firewall
set condition access policy sign in frequency (under session) to everytime in Azure
deleted browser caches
But nothing seems to work! So checking in the Azure-SignIn-Logs I found out that the second login is satisified with "Primary Refresh Token". So it seems like even after disconnecting from GlobalProtect the Token is somewhere saved and used for all further logins. Reading on the internet it seems like this token is valid for weeks or even months? Furthermore there is no way to set ForceAuth=true to force reauthentification from our firewall to Microsoft, because there is no checkbox or field i can see in the authentication profile.
Has anyone an idea how in the world I'm able to force users to use their Microsoft login with MFA everytime they are trying to connect to our portal via Globalprotect?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!