Portal Setup for Managed VPN Access
GlobalProtect starts with a focused onboarding workflow for organization-managed VPN access. Users acknowledge the information disclosure, then enter the portal address supplied by their administrator. That address points the app toward the company’s GlobalProtect gateway instead of a public consumer VPN directory, giving the deployment a clear connection path for remote work and protected resource access.
The portal field is useful when moving between managed networks or setting up a new Android device. Administrators can provide an IP address or fully qualified domain name, together with the sign-in details and policy choices that govern the connection. The result is a straightforward first task: identify the organization’s gateway, authenticate when required, and continue into the configured VPN experience.
Secure Remote and Per-App Connections
GlobalProtect can be configured for several enterprise connection styles, so the same Android client can fit different work policies. Always-On VPN keeps the managed tunnel available according to the organization’s rules, Remote Access VPN lets a user start a protected connection away from the office, and Per-App VPN focuses the tunnel on selected applications. This flexibility helps IT teams align access with the way employees actually work.
The app supports both IPSec and SSL connection methods, while administrator policies determine which mode and traffic rules apply. For a BYOD phone, that can mean reaching company resources without treating every personal application as part of the work tunnel. For a corporate device, the same controls can provide a more consistent route into private networks and approved services.
Gateway Selection and Connection Monitoring
Gateway handling is designed to reduce the amount of connection management required from the end user. GlobalProtect can automatically adapt to the user’s location and select the best available gateway, while deployments that need more control can expose a manual gateway selection path. This is useful for organizations with several gateways, changing office locations, or remote staff who need the app to keep finding an appropriate entry point.
The Android experience also uses native notifications to keep the user informed about the secure connection, including a background failure that needs attention. That makes the VPN easier to monitor during normal work: users can leave the app in the background, notice a connection problem, and return to the client instead of repeatedly opening it just to check status.
Enterprise Authentication and Device Provisioning
GlobalProtect is built for managed identity and device-provisioning workflows rather than anonymous browsing. Depending on the organization’s setup, authentication can use domain credentials, SAML, RADIUS one-time passwords, LDAP, client certificates, or a local user database. The app can also support password changes for an expired Active Directory password when a remote user reconnects, keeping the sign-in path tied to existing enterprise access rules.
Mobile-device-management integration gives administrators another way to provision the client and apply connection settings across a fleet. That makes the app suitable for company-owned devices as well as BYOD programs where the security team needs a repeatable policy, an approved gateway, and a defined set of applications or traffic to protect.