Pre-logon connections occur before any user has authenticated to the endpoint, which means there is no logged-in user context or user certificate store available for GlobalProtect to draw from at that point in the boot sequence — authentication must instead rely on machine-level identity. For this reason, the certificate used to establish a pre-logon connection must reside in the Machine Certificate Store rather than a user-specific certificate store, since the machine store is accessible to system-level processes and services regardless of whether a user session has started, which is exactly what pre-logon requires. This makes option C the correct, foundational requirement for pre-logon certificate deployment. Option A is incorrect because Prisma Access and GlobalProtect fully support internally issued or enterprise CA-signed certificates for client authentication; there is no requirement that a public CA sign these certificates, and in most enterprise deployments an internal PKI is actually the norm for machine certificates used in pre-logon scenarios. Option B is not an accurate, distinguishing requirement specific to pre-logon; standard certificate practices around Subject and Subject Alternative Name fields apply broadly to certificate usage but are not framed in Palo Alto Networks documentation as a unique pre-logon-specific mandate. Option D is incorrect because pre-logon, by its very nature, occurs before the GlobalProtect agent has a fully interactive user session running; certificate distribution for pre-logon is handled through the machine ' s certificate deployment process (such as group policy or an enterprise PKI/MDM tool), not through the GlobalProtect agent itself pushing certificates.
[Reference:GlobalProtect – Pre-Logon Authentication and Machine Certificate Store Requirements.]
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit