<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Nominated Discussion: Global Admin Account Lockout Settings vs Authentication Profile Settings in General Articles</title>
    <link>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-global-admin-account-lockout-settings-vs/ta-p/519341</link>
    <description>&lt;P&gt;This article is based on a discussion, &lt;A title="Global Device/Setup Authentication Settings vs Device/Setup/Authentication Profile" href="https://live.paloaltonetworks.com/t5/general-topics/global-device-setup-authentication-settings-vs-device-setup/m-p/517898" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Global Device/Setup Authentication Settings vs Device/Setup/Authentication Profile&lt;/STRONG&gt;&lt;/A&gt;, posted by &lt;STRONG&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179185"&gt;@Metgatz&lt;/a&gt;&lt;/STRONG&gt;&amp;nbsp;and answered by &lt;STRONG&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;.&lt;/STRONG&gt; Read on to see the discussion and solution!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Global Device/Setup Authentication Settings vs Device/Setup/Authentication Profile&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;FONT size="3"&gt;At Global level in &lt;STRONG&gt;Device &amp;gt; Setup &amp;gt; Authentication Settings&lt;/STRONG&gt; there are parameters such as: &lt;STRONG&gt;Failed Attempts&lt;/STRONG&gt; and &lt;STRONG&gt;Lockout Time&lt;/STRONG&gt;. &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3"&gt;At the same time, if I create an &lt;STRONG&gt;Authentication profile&lt;/STRONG&gt; I see the same settings under the &lt;STRONG&gt;Account Lockout&lt;/STRONG&gt; section.&lt;/FONT&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3"&gt;Now I create a local account called:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3"&gt;testadmin01&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Local User created under Device &amp;gt; Local User Database &amp;gt; Users" style="width: 509px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44912i38676B7D7D05D461/image-size/large?v=v2&amp;amp;px=999" role="button" title="kiwi_2-1666855148223.png" alt="Local User created under Device &amp;gt; Local User Database &amp;gt; Users" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Local User created under Device &amp;gt; Local User Database &amp;gt; Users&lt;/span&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then I use the same account as an administrator in &lt;STRONG&gt;Device &amp;gt; Setup &amp;gt; Administrators&lt;/STRONG&gt; and I associate it to an &lt;STRONG&gt;Authentication profile&lt;/STRONG&gt;.&amp;nbsp; In this profile I have &lt;STRONG&gt;Account Lockout&lt;/STRONG&gt; settings configured &lt;STRONG&gt;Failed Attempts&lt;/STRONG&gt; with value 3 and &lt;STRONG&gt;Lockout Time&lt;/STRONG&gt; at 30 minutes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Administrator tied to Authentication Profile" style="width: 969px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44913i652E9E88495F5A6F/image-size/large?v=v2&amp;amp;px=999" role="button" title="kiwi_3-1666855450055.png" alt="Administrator tied to Authentication Profile" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Administrator tied to Authentication Profile&lt;/span&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However at a global level (&lt;STRONG&gt;Device &amp;gt; Setup &amp;gt; Authentication Settings&lt;/STRONG&gt;) I have &lt;STRONG&gt;Failed Attempts&lt;/STRONG&gt; configured with value 5 and &lt;STRONG&gt;Lockout Time&lt;/STRONG&gt; at 30 minutes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Failed Attempts and Lockout Time in Authentication Settings" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44910i228E0D83A6B7F1EA/image-size/large?v=v2&amp;amp;px=999" role="button" title="kiwi_0-1666854863562.png" alt="Failed Attempts and Lockout Time in Authentication Settings" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Failed Attempts and Lockout Time in Authentication Settings&lt;/span&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Which settings are getting priority in this case ? The global level settings or the custom authentication profile settings ? Which of the two is valid, which one has real practical validity?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you use the local user configured with Authentication Profile, then the user will be locked out after reaching the number of Failed Attempts which was configured on the Authentication Profile.&amp;nbsp; In that case, it will totally ignore my global lockout settings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tested on LAB environment running PAN-OS 10.1.x&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Thu, 27 Oct 2022 13:46:18 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2022-10-27T13:46:18Z</dc:date>
    <item>
      <title>Nominated Discussion: Global Admin Account Lockout Settings vs Authentication Profile Settings</title>
      <link>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-global-admin-account-lockout-settings-vs/ta-p/519341</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 27 Oct 2022 13:46:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-global-admin-account-lockout-settings-vs/ta-p/519341</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2022-10-27T13:46:18Z</dc:date>
    </item>
  </channel>
</rss>

