Cloud SWG Captive Portal showing credentials are missing for explicit proxy
search cancel

Cloud SWG Captive Portal showing credentials are missing for explicit proxy

book

Article ID: 454366

calendar_today

Updated On:

Products

Cloud Secure Web Gateway - Cloud SWG

Issue/Introduction

Users are unable to authenticate through the Cloud SWG (Captive Portal), encountering errors such as "Credentials are Missing" or "Invalid Authentication Form." Authentication policies appear to be enforced, but requests are not being handled correctly 

Symptoms:

  • Users see the "Credentials are Missing" message in the browser.
  • "Invalid Authentication Form" error is displayed when accessing the captive portal link.
  • Auth connector logs show: GroupsOfInterestList::Check_goi_ready() entries indicating a group lookup failure (goi 0).

 

Environment

  • Cloud SWG (WSS)
  • Auth Connector / Captive Portal enabled

Cause

Cloud SWG requires a policy rule that references the Active Directory (AD) groups. Without a matching rule (even one with "no action"), the Groups of Interest (GOI) are not looked up or assigned by the Auth Connector, resulting in authentication failures.

Resolution


To fix the issue, Create AD Group Policy Rules:

    1. Navigate to Policy > Threat Protection or Content Filtering.
    2. Create a new rule.
    3. Under Source, select the specific Active Directory group.
    4. Save and Activate the policy.