Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Windows 10 - Allow Pre-Logon, Windows Hello sign-ins and SSO

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Windows 10 - Allow Pre-Logon, Windows Hello sign-ins and SSO

L2 Linker

I'm unable to get the Windows Hello credentials (such as fingerprint/face ID) to passthrough to Global Protect at logon.

 

We have our computer tunnel configured to handoff to the user tunnel 60 seconds after logon, so during the logon process, the connection isn't dropped and re-established.  

 

However, if a user uses face id or fingerprint to logon, global protect will not re-connect with the user tunnel.  I've read through all the command line switches on the agent to install, but I'm still lost.  

 

Would someone be able to assist or point me in the right direction?

1 REPLY 1

Hi @TANielsenBest ,

I have recently researched the same question. My understanding is unfortunately it is not possible to have Fingerprint,  Face recognition and GlobalProtect SSO.

 

The reason for that is when GP is configured to use SSO it will introduce its own Credential Provider, so when user enter his credentials on logon they will be passed to GP first. If you choose to use fingerprint or face you are choosing different credential provider and GP will not "see" the credentials and will SSO will fail, resulting in GP prompting the user for credentials.

Some details here - https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-apps/deploy-a...

 

On the following is described how GP can "wrap" other credential providers so and I was wondering if this also could be achieved for Windows Hello, but I haven't been able to test it - https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-apps/deploy-ap...

  • 2290 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!