palo alto globalprotect hip check failing on macos
Resolves Palo Alto GlobalProtect HIP check failures on macOS that block VPN access or drop users into quarantine. Covers updating the client, granting system extensions and full disk access, reading the local HIP report, and matching the gateway's OS requirements. Use when GlobalProtect connects but the HIP check fails or the portal shows the device as non-compliant. Not for gateway or certificate errors.
TL;DR
The HIP check fails because the GlobalProtect agent cannot read the Mac's patch and security status, usually after a macOS upgrade or when system extensions were never approved. Update the GlobalProtect client to the version your gateway requires, approve the system extension in System Settings > Privacy and Security, grant full disk access, then reconnect. Check the local HIP report to see exactly which check is failing before escalating.
The error
Users typically see the portal or gateway response rather than a client dialog:
HIP check failed. Your device does not meet the security requirements.Steps
- In GlobalProtect, open Settings > Troubleshooting > HIP Report. Expected: the report lists each check (OS version, disk encryption, antivirus) with pass or fail. Fix only what fails; the rest is noise.
- Update the GlobalProtect client to the minimum version the gateway policy requires. Ask the network team for the required version if the portal does not say. Expected: client version matches or exceeds it. macOS major upgrades regularly break older agents.
- On the Mac: System Settings > Privacy and Security, look for a blocked system extension from Palo Alto Networks and allow it. Expected: the allow button appears and the extension loads after a restart. Without this, the agent cannot collect HIP details at all.
- Grant Full Disk Access to the GlobalProtect agent in System Settings > Privacy and Security > Full Disk Access. Expected: the agent appears in the list and is toggled on. Missing access fails the encryption and patch checks silently.
- Reconnect GlobalProtect and re-run the HIP check from the portal. Expected: the gateway reports the device compliant within a minute or two. If one check still fails, escalate to the network team with the HIP report attached.
Use this when
- GlobalProtect connects but the user lands in quarantine or gets "HIP check failed"
- The failure started right after a macOS upgrade
- The HIP report shows failures on patch level, disk encryption, or antivirus
Not for this skill when
- The client will not install at all (installer or MDM issue)
- The gateway itself is unreachable (network or certificate problem)
- The user's OS is simply too old for policy (needs an upgrade decision, not a client fix)
Compatibility
- GlobalProtect 6.x on macOS 13+ (Ventura and newer); gateway policy set on PAN-OS
Variants
HIP passes on the portal but the gateway still quarantines
The portal and gateway can enforce different HIP profiles. Ask the network team which profile the gateway applies; the client report only shows the portal's view.
Everything passes locally but the check still fails
Stale HIP results cached on the gateway. Disconnect, wait a few minutes, and reconnect so the gateway pulls a fresh report.
Why it happens
HIP is the client reporting its own security posture. macOS sandboxing means the agent needs explicit approvals to read that posture. After upgrades or fresh installs those approvals are missing, so the agent reports nothing, and "nothing" fails every check.
Edge cases
- MDM-managed Macs: the MDM should push the system extension approval and full disk access via PPPC profile. If the user approves manually, the MDM may revert it.
- Beta macOS versions are often blocked by policy outright. No client fix helps; the user needs a supported release.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_zzvgcsCoT9YxPpbnH8Camg
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.