- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-28-2025 11:21 PM - edited 09-28-2025 11:38 PM
Hi guys,
we`ve just extended our platform sso for macOS compareable to bestpractise from microsoft (or even linked here in the forum to set up psso with intune)
The goal was to have a more seamlessly user experience and on the other hand let Entra receive the device state from apps like GlobalProtect so that we can enable Compliance based access to Entra ressources.
However it appears, that the login behaviors are completly different when in private network (like someones home network) and when sitting inside an office.
The Home network behavior is as expected: As soon as you start your mac, GP connects seamlessly, just like a charm. This is new and has never worked so far without having platform sso extended to 3rd vendor apps. You can also press reconnect, its connecting seamlessly every time, as long as you are in private network.
When beeing in an office location its something completly different. When connecting to GP the internal browser gets opened, a user account from entra can get selected and you can login, but not as seamlessly as if in private network ( as described above). That behavior is reproduceable everytime you would click on reconnect, a browser opens and asks you to login to your entra account before fullfilling the login.
Honestly i have no clue why that is. We are using macOS 14.7 and GlobalProtect 6.3.3 c676. Can anyone give me a clue where i could start digging?
09-30-2025 01:48 AM
Are you intending to set up a VPN connection when you're inside of the office?
That may cause routing, NATing or security rule issues you weren't expecting (you are now behind the firewall on the far side of the gateway interface)
- make sure you are not applying NAT to gateway connections, or have a specific NAT rule to properly accomodate for these connections
- make sure you accounted for these connections in your virtual router
- make sure you set up security rules to allow all these connections, there may also be connections out to EntraID you may now be blocking
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!