What is the recommended procedure when SSO - Global Protect User Logon (Always On) not working after enabling Kaspersky Endpoint Security?

What is the recommended procedure when SSO - Global Protect User Logon (Always On) not working after enabling Kaspersky Endpoint Security?

19444
Created On 01/03/21 20:12 PM - Last Modified 01/19/21 21:25 PM


Question


What is the recommended procedure when SSO - Global Protect User Logon (Always On)  stops working after enabling Kaspersky Endpoint Security?

Environment


  • GlobalProtect Client versions:  5.1.x. 5.2.x.
  • Windows Client.


Answer


  1. Enable SSO Wrapping for Kaspersky's Credential with the Windows Registry. 
  2. If the issue remains, do the following:
By default, the GlobalProtect agent tries to be the selected (default) credential provider so users are NOT required to manually change over. If GlobalProtect is not the selected (default) credential provider, one can try to force GlobalProtect to be the default by following one of these 2 options:
  • Modify the value of this registry and set the value to 1
    HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\SetGPCPDefault
  • Disable or exclude other credential providers in the computer.


Additional Information


Enable SSO Wrapping for Third-Party Credentials with the Windows Registry

Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HC9QCAW&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language