Changes to Default Behavior
Focus
Focus
GlobalProtect

Changes to Default Behavior

Table of Contents

Changes to Default Behavior

Changes to default behavior in GlobalProtect app 6.3.
The following topics describe changes to default behavior in GlobalProtect app 6.2:

Changes to Default Behavior in GlobalProtect App 6.2.8-h10 (6.2.8-948)

This hotfix includes performance and bug fixes for GlobalProtect app 6.2.8-h10 (6.2.8-948) for Windows and macOS.

Changes to Default Behavior in GlobalProtect App 6.2.8-h7 (6.2.8-c471)

Clicking the GlobalProtect icon in the Finder or Applications folder on macOS clients now opens the GlobalProtect client, mirroring the taskbar behavior. This change provides a consistent user experience by ensuring the interface is immediately visible regardless of the launch method. Previously, launching the app via the Applications folder or Spotlight provided no visual feedback if the GlobalProtect app was already running in the background.

Changes to Default Behavior in GlobalProtect App 6.2.8 (Windows)

(Windows endpoints only; Requires GlobalProtect release 6.2.8-c223 or later or 6.3.3 or later and content version 8966-9398) GlobalProtect now uses an embedded browser for captive portal authentication instead of the system default browser. This change provides improved security and a better user experience:
  • Improved Security: When captive portal is detected, the Enforce GlobalProtect Connection for Network Access setting no longer needs to be disabled. Embedded browser captive portal traffic is implicitly allowed because the embedded browser runs as a GlobalProtect process. Only GlobalProtect embedded browser traffic is permitted during captive portal authentication, resulting in improved security.
  • Optimized Configuration: You do not need to define Enforce GlobalProtect Connection for Network Access exceptions (IP-based or FQDN-based) for embedded browser captive portal traffic or associated pages. This preserves the limited number of available exception entries.
  • Better User Experience: The embedded browser launches as a foreground window, immediately prompting users for authentication. When Captive Portal Exception Timeout (sec) is set to 0 (recommended), there is no risk of timeout expiry because embedded browser traffic is implicitly allowed. If the timeout is set to a value greater than 0 and expires while the embedded browser is open, the embedded browser displays a Refresh GlobalProtect option to reset the timeout and restart captive portal detection.
To use the GlobalProtect embedded browser for captive portal authentication, set Use Default Browser for Captive Portal to No, set Display Captive Portal Detection Message to Yes, and set Captive Portal Exception Timeout (sec) to 0 in the GlobalProtect portal agent configuration. For more information, see Customize the GlobalProtect App.

Changes to Default Behavior in GlobalProtect App 6.2.6

You can now use the new system extension type Non-removable system extensions from UI introduced by Jamf Pro for the devices running on macOS 15 Sequoia or later versions to prevent the end users from disabling the GlobalProtect system extensions on the endpoints. GlobalProtect app version 6.2.6 and later supports macOS 15 Sequoia. This functionality is available only for the devices running on macOS 15 Sequoia or later versions.
You can configure this feature to prevent the end users from disabling GlobalProtect system extensions on their endpoints thereby reducing the risks associated with disabled system extensions.
Previously, end users could disable the GlobalProtect system extension through the MDM settings (GeneralSettingsNetwork Extensions.) However, with this new feature, the Non-removable system extensions from UI system extension type in Jamf Pro restricts users from disabling the GlobalProtect system extension.
To enable this functionality, you must perform the following procedures:
  1. Upgrade the GlobalProtect app to version 6.2.6 or later
  2. Upgrade the macOS to version 15 Sequoia or later
  3. In the mobile device management (MDM), Jamf Pro, set the System Extension Type as Non-removable system extensions from UI while configuring Configuration Profile.
If the GlobalProtect system extensions are disabled by the end-user, the following GlobalProtect features do not work:
  • Split-tunnel by domain
  • Split-tunnel by app
  • Enforcer
  • Split-DNS
  • Traffic Enforcement

Changes to Default Behavior in GlobalProtect App 6.2.5

The following topics describe changes to default behavior in GlobalProtect app 6.2.5:
  • Starting with GlobalProtect 6.2.5, if the saml-browser-order pre-deployment key is not set or set to yes, the user will not be able to bring other windows in front of the saml embedded browser. If the saml-browser-order pre-deployment key is set to no, the user will be able to bring other windows in front of the saml embedded browser.
  • When a captive portal is detected on Windows computers, GlobalProtect launches the system default browser (Chrome, Safari, or Firefox).

Changes to Default Behavior in GlobalProtect App 6.2.4

There are no changes to default behavior in GlobalProtect app 6.2.4.

Changes to Default Behavior in GlobalProtect App 6.2.2

If your Prisma Access tenant is IP Optimization enabled (available starting in Prisma Access 5.0.1), the minimum required GlobalProtect app versions are 6.1.4 and later, 6.2.3 and later, or 6.3 and later.

Changes to Default Behavior in GlobalProtect App 6.2.1

  • If your Prisma Access tenant is IP Optimization enabled (available starting in Prisma Access 5.0.1), the minimum required GlobalProtect app versions are 6.1.4 and later, 6.2.3 and later, or 6.3 and later.
  • Starting from GlobalProtect Linux version 6.2.1, you must use the following commands to install the CLI or GUI versions of the app.
    • To install the GlobalProtect UI package- $ ./gp_install.sh
    • To install the GlobalProtect CLI package- $ ./gp_install.sh --cli-only
    You don't need to run the ./gp_install.sh with sudo for GlobalProtect app Linux 6.2.1 and later versions. As the script executes, users will be prompted to enter the sudo password.

Changes to Default Behavior in GlobalProtect App 6.2.0

If you are using PAN-OS 10.x.x or 11.0.x and the Use Default Browser for SAML Authentication option is selected in any of the portal agent configurations, the Use Default Browser option on the Client Authentication window will be automatically enabled after you upgrade to PAN-OS 11.1.0 or later. Starting from PAN-OS 11.1.0, the default browser behavior is controlled by the client authentication setting. For more information about this feature and upgrade considerations, see Manage Browser Selection for SAML Authentication.