GlobalProtect VPN Okta Login Shows Blank Window Until Maximized
Last Updated:
Overview
When authenticating to the Palo Alto GlobalProtect Virtual Private Network (VPN) client using Okta, the embedded browser window displays a blank screen. Microsoft Windows updates cause this behavior by affecting the embedded browser's ability to render web content. Upgrading the GlobalProtect client to version 6.2.8 or later resolves the issue. The embedded browser window that appears for credentials remains blank or empty until a user resizes or maximizes the window, which forces the content to appear and allows the sign-in process to complete.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Palo Alto GlobalProtect VPN Client (Versions 6.2.7, 6.3.2, 6.1.5, 6.0.12 and earlier)
- Windows 11
Cause
Microsoft Windows updates (KB5051987 and KB5051989) cause this behavior. These updates impact the ability of the GlobalProtect embedded browser to reliably render web content (GPC-22542), which prevents the Okta sign-in widget from displaying correctly.
Solution
How can an administrator permanently resolve the blank window issue?
Upgrade the GlobalProtect client to version 6.2.8 or later to permanently resolve the blank window issue.
- Upgrade the GlobalProtect client to version 6.2.8 or later.
NOTE: Fixes for other release trains (6.0.13, 6.1.6, and 6.3.3) are pending release. Check the GlobalProtect release notes for availability.
Resizing the window forces the Okta sign-in widget to render.
Resize the window manually to trigger a re-render of the Okta sign-in widget.
- Click the Maximize icon in the top right corner when the blank window appears.
- Alternatively, click and drag a window corner to resize it manually.
Uninstalling the affected Windows updates restores normal rendering behavior.
Remove the specific Windows updates that cause the rendering issue if organization security policies allow.
- Navigate to Settings > Windows Update > Update History > Uninstall Updates.
- Uninstall the affected Windows updates (KB5051987 or KB5051989).
Contact Palo Alto Support for further troubleshooting if the issue persists.
