Prisma Access - "Authentication Failed" error on GlobalProtect agent when using CAS SSO

Prisma Access - "Authentication Failed" error on GlobalProtect agent when using CAS SSO

3483
Created On 11/30/22 03:15 AM - Last Modified 05/06/25 03:51 AM


Symptom


  • After initial GlobalProtect agent installation, you will get an "Authentication Failed" error on the browser.
  • The issue is resolved after disconnect and reconnect the GlobalProtect agent and issue will not reappear.
     


Environment


  • Prisma Access
  • Cloud Authentication Service (CAS) authentication
  • GlobalProtect agent installation, default browser set to 'NO'


Cause


  • GlobalProtect with CAS requires GlobalProtect agent to be installed with default browser.
  • If default browser is set to 'NO' CAS will not be able to complete the authentication.


Resolution


  1. Install GlobalProtect agent with default browser option is set to 'YES'.
  2. Refer the example below:
msiexec.exe /i GlobalProtect64.msi PORTAL="example.gpcloudservice.com" DEFAULTBROWSER="YES" 


Additional Information


SAML Authentication with Cloud Authentication Service.



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000kFPJCA2&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language