Palo Alto GlobalProtect VPN Client Generates an Authentication Failed Error During Okta Login
Last Updated:
Overview
Users fail to authenticate into Okta via Security Assertion Markup Language (SAML) when using the Palo Alto GlobalProtect VPN client because the application configuration uses an embedded browser. Switching the configuration to use the default system browser resolves this issue. This situation occurs specifically within the VPN client application and does not apply to browser-based sessions.
The VPN client generates the following error:
Authentication Failed
Please contact the administrator for further assistance
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Palo Alto GlobalProtect VPN client
- Security Assertion Markup Language (SAML)
- SAML Authentication
Cause
The Palo Alto GlobalProtect VPN client configuration uses an internal embedded browser for SAML authentication, which fails to complete the authentication process.
Solution
How does an administrator resolve the Palo Alto GlobalProtect VPN client authentication failure?
Review the vendor documentation to switch the VPN client from the embedded browser to the default system browser.
