<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article LocalDB User Can't Change Password in General Articles</title>
    <link>https://live.paloaltonetworks.com/t5/general-articles/localdb-user-can-t-change-password/ta-p/523788</link>
    <description>&lt;P&gt;This article is based on the discussion "&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/unable-to-change-password-on-localdb-user-when-added-to/m-p/511451" target="_blank" rel="noopener"&gt; Unable to change password on LocalDB user, when added to AuthProfile&lt;/A&gt;" by&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/146258"&gt;@TorokAdam&lt;/a&gt;&amp;nbsp;&amp;nbsp; and answered by&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;. Read on to see the discussion and solution!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Using PAN-OS 10.2.2 on a PA-440.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have created a few LocalDB users and added them to a group. Then I've created an authentication profile and added this group to the allow list (also tried with "all"). Since these local users are also the FW-administrators, I've created the same users under Device/Administrators and linked the appropriate Authentication Profile to them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After this, the administrators are unable to change their passwords on the Device/Local users page with the error message:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;"Admin user &amp;amp;quot;USERNAME&amp;amp;quot; is defined with authentication profile, cannot set password".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The same error message pops up when I try to change the password in CLI. I am unable to change the Auth Profile to none on the Administrator page with the same error message.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Workaround is creating user, change pw and then add it to Auth Profile.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have the same setup working on another PA-440 but with PanOS 10.1.x&lt;/P&gt;
&lt;P&gt;Could you guys advise? I haven't found this on the support portal under 10.2.2 known issues.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This behavior isn't there on PAN-OS 10.1 but starts popping up on PAN-OS 10.2.x&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiwi_0-1660224954718.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43109iC5F6FF2AF32A2819/image-size/large?v=v2&amp;amp;px=999" role="button" title="kiwi_0-1660224954718.png" alt="kiwi_0-1660224954718.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;TAC recognized the behavior and a fix is coming in an upcoming release.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;MARK&gt;NOTE: At the moment of writing this, PAN-OS 10.2.3 is the recommended release for 10.2.x and it's still showing the same behavior.&lt;/MARK&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Fri, 16 Dec 2022 14:09:20 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2022-12-16T14:09:20Z</dc:date>
    <item>
      <title>LocalDB User Can't Change Password</title>
      <link>https://live.paloaltonetworks.com/t5/general-articles/localdb-user-can-t-change-password/ta-p/523788</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Fri, 16 Dec 2022 14:09:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-articles/localdb-user-can-t-change-password/ta-p/523788</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2022-12-16T14:09:20Z</dc:date>
    </item>
  </channel>
</rss>

