Enable end users to initiate the GlobalProtect pre-logon connection manually on Windows
10 endpoints.
| Where Can I Use This? | What Do I Need? |
- NGFW (managed by Panorama or Strata Cloud Manager)
- Prisma Access (managed by Panorama or Strata Cloud
Manager)
|
- Windows 10 or later endpoints
- GlobalProtect Gateway license or Prisma Access license with
the Mobile User subscription
|
Enable end users to initiate the GlobalProtect
Remote Access VPN with Pre-Logon connection manually on Windows 10
endpoints. User-initiated pre-logon requires that you
Use Single
Sign-On in your portal configuration. In this deployment, users can
initiate the pre-logon connection only when their endpoint requires access to the
corporate network before login, such as when new employees connect to the network
remotely for the first time or when administrators must remotely connect and
troubleshoot issues on the endpoint. To initiate the pre-logon connection, users
must
Start GlobalProtect Connection from the GlobalProtect
credential provider logon screen after the endpoint boots up.
If users are
unable to establish the pre-logon connection using this option,
the pre-logon connection status remains Disconnected.
When
users log out of their endpoint, the VPN tunnel is not renamed from
the user tunnel back to the pre-logon tunnel. Instead, the tunnel
disconnects.
Use the following steps to enable users
to initiate the pre-logon connection manually:
You can
configure this option only in the Windows Registry. This configuration
can be done either manually after GlobalProtect is installed or
pre-deployed as part of the Windows image that includes the GlobalProtect
software.