## TL;DR
Portal authentication failed on a managed Mac usually means the portal address is wrong, the machine certificate is missing or expired, or the SSO flow is blocked. Verify the portal config the MDM pushed, check the certificate, then test SSO in a browser.

## The query
```text
globalprotect portal "authentication failed" on managed mac
```

## Use this when
- GlobalProtect portal rejects authentication on managed Macs
- works on Windows but fails on Mac
- failure started after a certificate renewal

## Not for
- tunnel fails after successful portal auth (check the gateway)
- always-on VPN captive portal issues
- unmanaged personal Macs (different enrollment)

## Steps
1. Confirm the portal address in the GlobalProtect settings matches the published portal. Expected output: the correct portal address configured
2. Check the machine certificate in Keychain Access: present, valid, and issued by the right CA. Expected output: a valid machine certificate
3. If the certificate is missing or expired, trigger a re-enrollment from the MDM. Expected output: a fresh certificate installed
4. Test the portal URL in Safari to see whether SSO itself works outside the client. Expected output: you know whether the client or SSO is at fault
5. Check that the MDM-pushed GlobalProtect configuration profile is installed and not conflicting with a manual install. Expected output: one clean configuration active
6. Collect GlobalProtect logs from the Mac for escalation to the network team. Expected output: logs showing the exact auth failure

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_EuG3NzelWtU6yy3_nivNaw
