GlobalProtect SAML SSO with Windows Hello for Business Prompts User to Select Account When Multiple Accounts Exist
Symptom
• GlobalProtect Windows Hello SSO authentication is prompting users to select an account
• GlobalProtect Windows Hello SSO authentication is not seamless
• Manual account selection is required to complete authentication.
Environment
- GlobalProtect
- Prisma Access
- Microsoft Entra ID-joined Windows device
- Windows Hello for Business (SAML-based authentication configured)
- Multiple user accounts registered on the device (for example, a standard user account alongside a local or domain admin account)
Cause
This issue is caused by the Microsoft Entra ID authentication layer, which generates the account selection prompt when it detects multiple user accounts associated with the user or device. This is a behavior of Microsoft's authentication process and is not controlled by GlobalProtect.
Resolution
There are two options provided by Microsoft to resolve this issue
-
Option 1: Remove additional secondary user accounts from the Windows device.
-
Open Settings on your computer (or press
Win + I). -
Click on Accounts in the left sidebar.
-
Click on the dropdown arrow next to the account you want to remove (
user@test.comoradmin@test.com). -
Click Disconnect.
-
Confirm by clicking Yes when prompted to complete the removal.
-
-
Option 2: Use separate, dedicated privileged workstations for each user account.
Additional Information
Seamless Single Sign-On with Palo Alto Networks GlobalProtect