In
Connect Before Logon mode,
the GlobalProtect app acts as a Pre-Login Access Provider (PLAP)
credential provider to provide access to your corporate network
before the user logs in to the Windows device, allowing users on
an endpoint that is not yet set up with a local profile, certificates,
or user accounts to gain the access needed to reach the domain controller
and join the domain. This deployment does not require a PKI environment
and instead uses a user-based logon sequence (LDAP, RADIUS, SAML,
username/password-based authentication, smart cards, or OTP authentication
are supported). In this deployment, the end user device is provisioned
as follows: