With Cloud Identity Engine multi-authentication, you can enable the end
user to bypass the SSO hub page (which prompts the user for their SAML username)
on Windows endpoints by pre-deploying the following registry key:
CASSKIPHUBPAGE using the following
syntax:
msiexec.exe /i globalprotect64.msi CASSKIPHUBPAGE=yes
The registry key is displayed in the Windows registry path
\HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto
Networks\GlobalProtect\Settings.
This feature is supported on the default browser and embedded web-view
for the following actions:
- User unlocks the device
- Device wakes up from sleep mode
- After a system reboot
For the GlobalProtect app with Connect Before
Logon (CBL) installed on Windows endpoints, you must use the default browser
for Cloud Identity Engine SAML authentication.
Before enabling this feature, ensure the following:
- Username is configured in UPN format in CIE or the Windows endpoints are
joined to Azure domain (AAD or Active Directory).
- The cloud identity engine is configured without the Force authentication
option in the authentication profile.
- IDP/SAML session is active.