<html><body><div dir="ltr">We’re using Palo Alto's Global Protect VPN with the client’s default browser rather than PA’s embedded browser (just now confirmed with them that there is a configuration setting on the GPN side enabling that switch). The primary motivator for them was to be able to use hardware tokens for MFA, but it has the advantages of avoiding the issue being discussed here with the embedded browser, plus of course, establishing a useful SSO session in the default browser, potentially avoiding additional prompt for credentials. Isn’t that a win-win-win - or am I missing something?</div><div dir="ltr"><br></div><div dir="ltr">David St Pierre Bantz</div><div dir="ltr">U Alaska IAM</div>
<div class="gmail_quote"><br>
</div></body></html>