SEP mobile setup on IOS devices to integrate with Cloud SWG using a SEP Web and Cloud access policy.
Users authenticate using SAML, via a Microsoft Entra IdP server.
When users initially connect to Cloud SWG, a popup is triggered on the SEP mobile device where the user enters credentials. After successfully authenticating the IdP server, the users can browse to all allowed sites.
When users re-connect, they are not prompted for authentication despite the session expiring (which occurs 24 hours after initial login) - there are no banners or challenges anywhere on the mobile device.
As a result the traffic is considered unauthenticated and no SWG policies are applied resulting in no ZTNA service.
SEP Mobile.
SAML Authentication.
Bug with SEP mobile client.
Apply SEP mobile 6.26.0 (May '26) to address this issue.