GlobalProtect SAML SSO with Windows Hello for Business Prompts User to Select Account When Multiple Accounts Exist

GlobalProtect SAML SSO with Windows Hello for Business Prompts User to Select Account When Multiple Accounts Exist

455
Created On 07/28/26 19:28 PM - Last Modified 07/28/26 19:47 PM


Symptom


• GlobalProtect Windows Hello SSO authentication is prompting users to select an account
• GlobalProtect Windows Hello SSO authentication is not seamless
Manual account selection is required to complete authentication. 



Environment


  • GlobalProtect
  • Prisma Access
  • Microsoft Entra ID-joined Windows device
  • Windows Hello for Business (SAML-based authentication configured)
  • Multiple user accounts registered on the device (for example, a standard user account alongside a local or domain admin account)


Cause


This issue is caused by the Microsoft Entra ID authentication layer, which generates the account selection prompt when it detects multiple user accounts associated with the user or device. This is a behavior of Microsoft's authentication process and is not controlled by GlobalProtect.



Resolution


There are two options provided by Microsoft to resolve this issue

  • Option 1: Remove additional secondary user accounts from the Windows device.

    • Open Settings on your computer (or press Win + I).

    • Click on Accounts in the left sidebar.

    • Click on the dropdown arrow next to the account you want to remove (user@test.com or admin@test.com).

    • Click Disconnect.

    • Confirm by clicking Yes when prompted to complete the removal.

  • Option 2: Use separate, dedicated privileged workstations for each user account.



Additional Information


Seamless Single Sign-On with Palo Alto Networks GlobalProtect



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA1Ki000000kCAeKAM&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail