The GlobalProtect default browser fails to load if it's configured under the Portal's App tab but not under the Portal's Authentication tab
2489
Created On 09/25/25 22:46 PM - Last Modified 10/07/25 01:53 AM
Symptom
- When 'Use Default Browser for SAML Authentication' is enabled under the GlobalProtect agent configuration, the embedded browser is still used if the setting is not enabled under the Portal's authentication tab
- The default browser is used when 'Use Default Browser' is enabled under the Portal Client Authentication.
Environment
- Palo Alto Firewalls
- PANOS-11.1.1
- GlobalProtect App version 6.3.3
Cause
- The Portal's authentication tab settings take precedence over the App tab settings.
- This is because the application can't access or apply the App tab settings until the user has successfully completed authentication.
Resolution
Ensure that the 'Use Default Browser' option is enabled under the Authentication profile in the GlobalProtect Portal configuration by completing the steps below. These setting ensures that SAML authentication launches in the system’s default browser.
- Log in to the Palo Alto Networks Firewall GUI.
- Navigate to the 'Network' tab.
- Under 'GlobalProtect', click 'Portals'.
- Select the Portal you have configured.
- Go to the 'Authentication' tab.
- Under 'Client Authentication', select the configured profile.
- Check the box for 'Use Default Browser'.
- Commit the configuration changes.
- Reconnect GlobalProtect to verify that authentication occurs using the system’s default browser.