When SAML authentication is enabled, Okta push notification showing incorrect WindowsOS
1295
Created On 12/12/24 05:55 AM - Last Modified 10/28/25 19:50 PM
Symptom
- Okta push notification showing incorrect browser and OS for GlobalProtect SAML authentication.
- In the notification, "Windows 8" is displayed even though it's actually Windows 10 client.
- It happens when embedded browser for SAML is used.
Environment
- Any PAN-OS Firewall model
- Any PAN-OS release
- GlobalProtect App 6.2.6 or older
- Embedded browser for SAML is enabled
Cause
- GlobalProtect agent use "Windows NT 6.2" in User-Agent string.
- Okta detect "Windows NT 6.2" sent by the GlobalProtect embedded browser, then decodes to "Windows 8", it leading to an inaccurate OS display in the push notification.
Resolution
- The issue is fixed under GPC-22043.
- Upgrade GlobalProtect App to 6.3.3, 6.2.8 or later to address the issue.