<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is there a way to accept both SAMAccountName AND UserPrincipalName for user authentication? in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/is-there-a-way-to-accept-both-samaccountname-and/m-p/517968#M3297</link>
    <description>&lt;P&gt;Bottom line I would like my user to be able to authenticate using either "MyUserID" or "MyUserID@MyDomain.com".&amp;nbsp; Can this be done?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Right now, my users authenticate using their SAMAccountName/userID.&amp;nbsp; As we move toward x.509 Personal Certificate authentication, the user certs provide a UPN (email address).&amp;nbsp; Given a user who has a&amp;nbsp;SAMAccountName of "MyUserID" and UserPrincipalName of "MyUserID@MyDomain.COM"; is there a way to setup Authentication Profiles to strip off the "@mydomain.com" and thus always send the radius server just "MyUserID" for account matching?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've been looking at Authentication Profile -&amp;gt; Username Modifier but I don't yet see a way to accomplish what I am looking for.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any suggestions?&lt;/P&gt;</description>
    <pubDate>Fri, 14 Oct 2022 15:56:37 GMT</pubDate>
    <dc:creator>Will_Baldwin</dc:creator>
    <dc:date>2022-10-14T15:56:37Z</dc:date>
    <item>
      <title>Is there a way to accept both SAMAccountName AND UserPrincipalName for user authentication?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/is-there-a-way-to-accept-both-samaccountname-and/m-p/517968#M3297</link>
      <description>&lt;P&gt;Bottom line I would like my user to be able to authenticate using either "MyUserID" or "MyUserID@MyDomain.com".&amp;nbsp; Can this be done?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Right now, my users authenticate using their SAMAccountName/userID.&amp;nbsp; As we move toward x.509 Personal Certificate authentication, the user certs provide a UPN (email address).&amp;nbsp; Given a user who has a&amp;nbsp;SAMAccountName of "MyUserID" and UserPrincipalName of "MyUserID@MyDomain.COM"; is there a way to setup Authentication Profiles to strip off the "@mydomain.com" and thus always send the radius server just "MyUserID" for account matching?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've been looking at Authentication Profile -&amp;gt; Username Modifier but I don't yet see a way to accomplish what I am looking for.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any suggestions?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 15:56:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/is-there-a-way-to-accept-both-samaccountname-and/m-p/517968#M3297</guid>
      <dc:creator>Will_Baldwin</dc:creator>
      <dc:date>2022-10-14T15:56:37Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to accept both SAMAccountName AND UserPrincipalName for user authentication?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/is-there-a-way-to-accept-both-samaccountname-and/m-p/518007#M3306</link>
      <description>&lt;P&gt;I think you were looking in the right place, the username modifier is explained here and seems to be what you want:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-web-interface-help/device/device-authentication-profile/configure-an-authentication-profile" target="_blank"&gt;Authentication Profile (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;If you specify the %USERDOMAIN% variable and leave the&amp;nbsp;User Domain&lt;/EM&gt;&lt;LI-WRAPPER&gt;&lt;SPAN&gt;&lt;EM&gt;&amp;nbsp;blank, the firewall removes any user-entered domain string.&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;EM&gt;- DM&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Oct 2022 21:10:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/is-there-a-way-to-accept-both-samaccountname-and/m-p/518007#M3306</guid>
      <dc:creator>dmifsud</dc:creator>
      <dc:date>2022-10-15T21:10:45Z</dc:date>
    </item>
  </channel>
</rss>

