When SAML authentication is enabled, Okta push notification showing incorrect WindowsOS

When SAML authentication is enabled, Okta push notification showing incorrect WindowsOS

1295
Created On 12/12/24 05:55 AM - Last Modified 10/28/25 19:50 PM


Symptom


  • Okta push notification showing incorrect browser and OS for GlobalProtect SAML authentication.
  • In the notification, "Windows 8" is displayed even though it's actually Windows 10 client.
    Okta_notification.png 
  • It happens when embedded browser for SAML is used.





Environment


  • Any PAN-OS Firewall model
  • Any PAN-OS release
  • GlobalProtect App 6.2.6 or older
  • Embedded browser for SAML is enabled


Cause


  • GlobalProtect agent use "Windows NT 6.2" in User-Agent string.
  • Okta detect "Windows NT 6.2" sent by the GlobalProtect embedded browser, then decodes to "Windows 8", it leading to an inaccurate OS display in the push notification.


Resolution


  1. The issue is fixed under GPC-22043
  2. Upgrade GlobalProtect App to 6.3.3, 6.2.8 or later to address the issue.


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000TpPICA0&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language