Enforce Default Browser for SAML Authentication in NetExtender 10.3.4

Description

During installation or upgrade of SonicWall NetExtender 10.3.4, the registry value that enables use of the default browser for SAML authentication (DefaultBrowser=1) does not persist. This causes NetExtender to fall back to its embedded browser, which fails Microsoft Entra ID Conditional Access policies that block embedded browsers. The issue occurs during deployments and upgrades performed through Intune or Patch My PC, including upgrades from NetExtender 10.3.2 to 10.3.4.

Resolution

1. Add the BROWSER=TRUE parameter to the NetExtender installer command line.
2. Deploy the installer with this parameter using your existing deployment tool (for example, Intune or Patch My PC).
3. After installation, verify that the "Use default browser for SAML" option is enabled and that SAML authentication completes using the system default browser rather than the embedded browser.

Note: Setting DefaultBrowser=1 directly in the registry (under HKLM or HKCU SonicWall keys) does not reliably persist across install or upgrade and is not a supported method for enforcing this setting.

Related Articles

  • GVC 2FA Not Working on NSA 2700 (Gen7)
    Read More
  • How to troubleshoot a "Login failed - HTTPS User login not allowed from here" Error?
    Read More
  • SonicOS 7.3.3 FAQ
    Read More
not finding your answers?