What is the recommended procedure when SSO - Global Protect User Logon (Always On) not working after enabling Kaspersky Endpoint Security?
19444
Created On 01/03/21 20:12 PM - Last Modified 01/19/21 21:25 PM
Question
What is the recommended procedure when SSO - Global Protect User Logon (Always On) stops working after enabling Kaspersky Endpoint Security?
Environment
- GlobalProtect Client versions: 5.1.x. 5.2.x.
- Windows Client.
Answer
- Enable SSO Wrapping for Kaspersky's Credential with the Windows Registry.
- If the issue remains, do the following:
By default, the GlobalProtect agent tries to be the selected (default) credential provider so users are NOT required to manually change over. If GlobalProtect is not the selected (default) credential provider, one can try to force GlobalProtect to be the default by following one of these 2 options:
- Modify the value of this registry and set the value to 1
HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\SetGPCPDefault
- Disable or exclude other credential providers in the computer.
Additional Information
Enable SSO Wrapping for Third-Party Credentials with the Windows Registry