When connecting to the Cisco AnyConnect VPN (vpn.wfu.edu), the VPN client hands off single sign-on (SAML) authentication to your system's default browser. If your browser's active session is currently set to a personal Google account (@gmail.com) rather than your university account (@wfu.edu), Google will block the authentication request and display a 403 Error ("Access Denied" or "app_not_configured_for_user").
This guide provides steps to resolve this error on both Windows and macOS.
Primary fix: Focus your WFU browser session
Cisco AnyConnect routes authentication requests through the browser window or profile that was most recently active on your computer.
- Open your web browser and bring the window signed into your WFU Google account to the foreground.
- Click anywhere inside that window to ensure it is the active profile.
- Open Cisco AnyConnect and click Connect.
The SAML authentication prompt will now detect your active WFU session and complete the login smoothly.
Alternative fix: Change your system default browser
To prevent AnyConnect from launching an unintended browser, ensure your OS default browser is set to the one you use for WFU work.
macOS
- Open System Settings > Desktop & Dock.
- Scroll down to the Default web browser dropdown menu.
- Select the browser associated with your WFU account (e.g., Google Chrome).
Windows
- Open Settings (Win + I) > Apps > Default apps.
- Search for the browser associated with your WFU account (e.g., Google Chrome).
- Click Set default.
Alternative fix: Create a dedicated profile in your browser
Note:
On certain Windows builds, system security features (such as the UserChoice Protection Driver) may prevent Cisco AnyConnect from recognizing changes to your default browser choice. As a result, AnyConnect may continue launching a secondary browser (such as Microsoft Edge or Firefox) even after you updated your Windows settings.
Rather than modifying advanced Windows system drivers, the simplest fix is to add your WFU account to the browser that keeps launching. Creating a dedicated browser profile completely separates your work history, saved passwords, extension data, and active login sessions from your personal account.
Below are official instructions on creating a separate profile:
- Google Chrome: Follow the Google Chrome profile setup guide to create a dedicated profile for your @wfu.edu account.
- Microsoft Edge: Follow the Microsoft Edge profile management guide to set up a secondary Work profile.
- Mozilla Firefox: Follow the Firefox Profile Manager guide to create and isolate your WFU Firefox profile.
Once created, sign into your WFU Google account within that dedicated profile and make sure that profile window is active before clicking Connect in Cisco AnyConnect.
Yes No