Palo Alto Networks Knowledgebase: Duplicate Windows Logon Entries (Tiles) Following GP Client Install
Duplicate Windows Logon Entries (Tiles) Following GP Client Install
Created On 02/07/19 23:39 PM - Last Updated 02/07/19 23:39 PM
GlobalProtect clients installed on Windows 7/8 machines.
Following the install, there are multiple login tiles for the same user account. Issues are present regardless as to whether the screen is locked, account is logged off or if the workstation is rebooted.
Issues were isolated to the workstation in question which utilizes a Fingerprint Logon CP (Credential Provider). End result in certain scenarios is duplicate SSO Logon tiles as seen above.
Workarounds in this case would be as follows:
DISABLE the Fingerprint Logon CP as the GP client will utilize it's own built-in CP. Conflict would be removed & issues should no longer be present (though obviously customers may wish to utilize this functionality).
DISABLE Our Logon CP which should still allow full functionality of the GP client, while allowing the use of the 3rd Party Fingerprint CP. Workaround requires issuing the following commands via CLI:
Via command prompt, run the following: "c:\program files\Palo alto networks\globalprotect\PanGPUpdater.exe" -u
Restart PC & verify whether duplicate login options are still present. If duplicate tiles are no longer present, proceed with step 3.
Via command prompt, run the following: "c:\program files\Palo alto networks\globalprotect\PanGPUpdater.exe" –c