We've checked the client config section, there's nothing restricting the os, the ad. To identify discrepancies between the username format used by the globalprotect client and that retrieved from the ldap server, refer to globalprotect is not getting the configuration when. Navigate to network > globalprotect > gateway, click the gateway name > agent > client settings > config selection criteria tab. Make sure the username that the gp app is trying to. The option to use biometrics to log in has been there for quite some time.
