<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to restrict access only to certified devices for users in an AD user group but not a different group in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-restrict-access-only-to-certified-devices-for-users-in-an/m-p/406841#M1290</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163815"&gt;@laurence64&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HIPS have predefined- and some custom checks you can look for on an endpoint.&amp;nbsp; &amp;nbsp;The firewall will enforce on those HIP checks if you have them in security policy&lt;/P&gt;</description>
    <pubDate>Fri, 14 May 2021 18:48:33 GMT</pubDate>
    <dc:creator>Sec101</dc:creator>
    <dc:date>2021-05-14T18:48:33Z</dc:date>
    <item>
      <title>How to restrict access only to certified devices for users in an AD user group but not a different group</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-restrict-access-only-to-certified-devices-for-users-in-an/m-p/403352#M1245</link>
      <description>&lt;P&gt;LDAP authentication is required for all the users. On top of that, we also want to restrict access to only certified devices for employees (must use company machines) but not contractors (can use private machines). Device certifications are pushed out through GPO to company devices. Employees and contractors belong to different AD user groups. How can it be done?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Apr 2021 16:22:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-restrict-access-only-to-certified-devices-for-users-in-an/m-p/403352#M1245</guid>
      <dc:creator>skuo2020</dc:creator>
      <dc:date>2021-04-28T16:22:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict access only to certified devices for users in an AD user group but not a different group</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-restrict-access-only-to-certified-devices-for-users-in-an/m-p/403642#M1246</link>
      <description>&lt;P&gt;HIP checks is what you need&lt;/P&gt;</description>
      <pubDate>Wed, 28 Apr 2021 21:45:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-restrict-access-only-to-certified-devices-for-users-in-an/m-p/403642#M1246</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2021-04-28T21:45:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict access only to certified devices for users in an AD user group but not a different group</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-restrict-access-only-to-certified-devices-for-users-in-an/m-p/404722#M1257</link>
      <description>&lt;P&gt;If I understand correctly, to use HIP we would have to plant a registry entry to identify those interested machines and then use security policy to control what they are allowed or not allowed to access. GP only collects HIP data but not doing any access controls which is not an ideal solution I am looking for.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Portal allows multiple Client Authentication and multiple Agent. Somewhere in there I believe can do what I am looking for somehow.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 14:25:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-restrict-access-only-to-certified-devices-for-users-in-an/m-p/404722#M1257</guid>
      <dc:creator>skuo2020</dc:creator>
      <dc:date>2021-05-04T14:25:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict access only to certified devices for users in an AD user group but not a different group</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-restrict-access-only-to-certified-devices-for-users-in-an/m-p/404886#M1259</link>
      <description>&lt;P&gt;Following on from&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/157358"&gt;@Sec101&lt;/a&gt;&amp;nbsp;it is true that GP only collects the HIP data, but that data can then be used in a security policy to allow or deny the traffic based on the information contained within, so for instance in this case I would check for the certificate and put a security policy that allows the traffic for that group including the HIP check in the policy, if the device fails the HIP check the firewall will fall through to a rule underneath that could pick up the remaining users and provide that connectivity.&lt;/P&gt;</description>
      <pubDate>Wed, 05 May 2021 09:17:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-restrict-access-only-to-certified-devices-for-users-in-an/m-p/404886#M1259</guid>
      <dc:creator>laurence64</dc:creator>
      <dc:date>2021-05-05T09:17:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict access only to certified devices for users in an AD user group but not a different group</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-restrict-access-only-to-certified-devices-for-users-in-an/m-p/406841#M1290</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163815"&gt;@laurence64&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HIPS have predefined- and some custom checks you can look for on an endpoint.&amp;nbsp; &amp;nbsp;The firewall will enforce on those HIP checks if you have them in security policy&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 18:48:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-restrict-access-only-to-certified-devices-for-users-in-an/m-p/406841#M1290</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2021-05-14T18:48:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict access only to certified devices for users in an AD user group but not a different group</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-restrict-access-only-to-certified-devices-for-users-in-an/m-p/407581#M1300</link>
      <description>&lt;P&gt;Isn't that what I said ?&lt;/P&gt;</description>
      <pubDate>Tue, 18 May 2021 16:04:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-restrict-access-only-to-certified-devices-for-users-in-an/m-p/407581#M1300</guid>
      <dc:creator>laurence64</dc:creator>
      <dc:date>2021-05-18T16:04:28Z</dc:date>
    </item>
  </channel>
</rss>

