To use Connect Before Logon, choose the authentication method.
| Where Can I Use This? | What Do I Need? |
|
|
- GlobalProtect app version 6.0 or later
|
You cannot use the Pre-logon and Pre-logon then On-demand connection methods simultaneously with
Connect Before Logon.
You cannot use Connect Before Logon to connect to an internal gateway.
To simplify the login process and improve your experience, GlobalProtect offers Connect Before
Logon to allow you to establish the VPN connection to the corporate network before
logging in to the Windows 10 endpoint using a Smart card, authentication service
such as LDAP, RADIUS, or Security Assertion Markup Language (SAML),
username/password-based authentication, or one-time password (OTP) authentication.
Your GlobalProtect administrator could have enabled Connect Before Logon to onboard
you as a new GlobalProtect user on an endpoint that does not yet have a local user
profile or user account. Connect Before Logon is disabled by default. When the
administrator enables Connect Before Logon, you can launch the GlobalProtect app
credential provider and connect to the corporate network before logging in to
Windows endpoint. After Connect Before Logon establishes a VPN connection, you can
use the Windows logon screen to log in to the Windows endpoint. GlobalProtect can
act as a Pre-Login Access Provider (PLAP) credential provider to provide access to
your organization before logging in to Windows.
Because Connect Before Logon prompts you to authenticate twice on the portal and gateway when
logging in to the Windows endpoint for the first time, the Authentication
Override cookie isn't working as expected.