It is possible to send the configuration to the global protect agent, so that it only connects to a portal and no more options appear in the bottom bar.
I found this note, but I would like to do it from GP
https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-apps/deploy-app-settings-transparently/deploy-app-settings-to-windows-endpoints/deploy-app-settings-in-the-windows-regsitry.html#id3d8dee4d-b022-48b8-9877-ea42a06ed1e8
I would also suggest not allowing users to change the portal address, as well as stopping them from signing out.
Auto Enforcement and block local LAN access are other options worth enabling.
Hi Rodrigo! You can disable the systray icon from the agent>app configuration