Just one portal GP
It is possible to send the configuration to the global protect agent, so that it only connects to a portal and no more options appear in the bottom bar.
I found this note, but I would like to do it from GP
https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-apps/deploy-app-settings-transparently/deploy-app-settings-to-windows-endpoints/deploy-app-settings-in-the-windows-regsitry.html#id3d8dee4d-b022-48b8-9877-ea42a06ed1e8
15 Views


I would also suggest not allowing users to change the portal address, as well as stopping them from signing out.
Auto Enforcement and block local LAN access are other options worth enabling.