<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Filtering by a Azure AD user  does not work in Gateway--&amp;gt;Agent--&amp;gt;Client Settings in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/filtering-by-a-azure-ad-user-does-not-work-in-gateway-gt-agent/m-p/542764#M4029</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/128897"&gt;@pkumar2&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;I afraid that that simple solution does not work. That was my first attempt indeed.&lt;/P&gt;
&lt;P&gt;Following your advice I checked the Globalprotect authentication logs and I saw&amp;nbsp;&lt;A href="mailto:username@domain.com" target="_blank" rel="noopener"&gt;username@domain.com&lt;/A&gt;&amp;nbsp;as source user. &lt;BR /&gt;I added domain\useraccount and even the email address but there is still no match with the rule.&lt;/P&gt;
&lt;P&gt;I am getting the client settings with the "any" as a filter.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A technician from a local partner told me that I might have an issue with the group mapping settings. The email should be mapped with the LDAP information stored in PA. I checked that as well but I did not see anything wrong.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 19 May 2023 16:47:21 GMT</pubDate>
    <dc:creator>JoseCortijo</dc:creator>
    <dc:date>2023-05-19T16:47:21Z</dc:date>
    <item>
      <title>Filtering by a Azure AD user  does not work in Gateway--&gt;Agent--&gt;Client Settings</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/filtering-by-a-azure-ad-user-does-not-work-in-gateway-gt-agent/m-p/522259#M3451</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;we currently have global protect integrated with Azure MFA using SAML and it works flawless.&lt;BR /&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/active-directory/saas-apps/palo-alto-networks-globalprotect-tutorial" target="_self"&gt;https://learn.microsoft.com/en-us/azure/active-directory/saas-apps/palo-alto-networks-globalprotect-tutorial&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now, we would like to offer a different IP Pool depending on the user account. when I check in the MONITOR for connections using that VPN gateway, I see the different corporate email addresses in the SOURCE USER column. this email address is the one used to make the authentication via Azure MFA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At this point, my approach was to create a new Agent--&amp;gt;client setting in the gateway portal . In the 'Config Selection Criteria' I included my corporate email addreass as SOURCE USER. No errors were shown so I clicked OK and commit. I also included a different IP pool range to filter conenctions later on with dedicated policies.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Surprisingly, afte the change was applied and I reconnect, I still get an IP address from the old IP pool, the one with 'any' on its client settings. it seems like my user name did not match for some reason. (see attachement)&lt;/P&gt;
&lt;P&gt;we have a PA-850 running version 10.1.3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BR /&gt;&lt;BR /&gt;Please note you are posting a public message where community members and experts can provide assistance. Sharing private information such as serial numbers or company information is not recommended.</description>
      <pubDate>Wed, 23 Nov 2022 15:38:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/filtering-by-a-azure-ad-user-does-not-work-in-gateway-gt-agent/m-p/522259#M3451</guid>
      <dc:creator>JoseCortijo</dc:creator>
      <dc:date>2022-11-23T15:38:33Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering by a Azure AD user  does not work in Gateway--&gt;Agent--&gt;Client Settings</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/filtering-by-a-azure-ad-user-does-not-work-in-gateway-gt-agent/m-p/522263#M3452</link>
      <description>&lt;P&gt;According to the official documentation the source user in the client setting tab must be configured via User Identification.&lt;/P&gt;
&lt;P&gt;In our case we only have the internal Active Directory and checking its settings I saw an option that called my attention, Alternate Username 1.&lt;/P&gt;
&lt;P&gt;I wonder if I put "mail" in that field, it might be used in the filtering as a username. (see attachment) &lt;BR /&gt;&lt;BR /&gt;Does anyone used that before for a similar purpose?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 15:52:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/filtering-by-a-azure-ad-user-does-not-work-in-gateway-gt-agent/m-p/522263#M3452</guid>
      <dc:creator>JoseCortijo</dc:creator>
      <dc:date>2022-11-23T15:52:36Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering by a Azure AD user  does not work in Gateway--&gt;Agent--&gt;Client Settings</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/filtering-by-a-azure-ad-user-does-not-work-in-gateway-gt-agent/m-p/536659#M3841</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/244719"&gt;@JoseCortijo&lt;/a&gt; - did you ever figure this out?&amp;nbsp; I am having a similar issue.&amp;nbsp; I am using SAML and I have an "any" user config which works fine.&amp;nbsp; But I am trying to add a more restrictive config above that one, which contains specific users or groups, and cannot get it to work. All users keep matching the "any" rule.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 20:30:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/filtering-by-a-azure-ad-user-does-not-work-in-gateway-gt-agent/m-p/536659#M3841</guid>
      <dc:creator>tamerfahmy</dc:creator>
      <dc:date>2023-03-27T20:30:11Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering by a Azure AD user  does not work in Gateway--&gt;Agent--&gt;Client Settings</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/filtering-by-a-azure-ad-user-does-not-work-in-gateway-gt-agent/m-p/542367#M4022</link>
      <description>&lt;P&gt;We don't need user-id enabled for this.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;If you are using a username to filter, check the Globalprotect/authd.logs to see what username is passed to the firewall.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;use domain\username format to filter the config.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;E.g&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="mailto:username@domain.com," target="_blank"&gt;username@domain.com,&lt;/A&gt;&amp;nbsp;then use domain.com\username as the source user.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 May 2023 20:50:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/filtering-by-a-azure-ad-user-does-not-work-in-gateway-gt-agent/m-p/542367#M4022</guid>
      <dc:creator>pkumar2</dc:creator>
      <dc:date>2023-05-16T20:50:04Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering by a Azure AD user  does not work in Gateway--&gt;Agent--&gt;Client Settings</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/filtering-by-a-azure-ad-user-does-not-work-in-gateway-gt-agent/m-p/542764#M4029</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/128897"&gt;@pkumar2&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;I afraid that that simple solution does not work. That was my first attempt indeed.&lt;/P&gt;
&lt;P&gt;Following your advice I checked the Globalprotect authentication logs and I saw&amp;nbsp;&lt;A href="mailto:username@domain.com" target="_blank" rel="noopener"&gt;username@domain.com&lt;/A&gt;&amp;nbsp;as source user. &lt;BR /&gt;I added domain\useraccount and even the email address but there is still no match with the rule.&lt;/P&gt;
&lt;P&gt;I am getting the client settings with the "any" as a filter.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A technician from a local partner told me that I might have an issue with the group mapping settings. The email should be mapped with the LDAP information stored in PA. I checked that as well but I did not see anything wrong.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 16:47:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/filtering-by-a-azure-ad-user-does-not-work-in-gateway-gt-agent/m-p/542764#M4029</guid>
      <dc:creator>JoseCortijo</dc:creator>
      <dc:date>2023-05-19T16:47:21Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering by a Azure AD user  does not work in Gateway--&gt;Agent--&gt;Client Settings</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/filtering-by-a-azure-ad-user-does-not-work-in-gateway-gt-agent/m-p/542768#M4030</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/244719"&gt;@JoseCortijo&lt;/a&gt; - I got my issue resolved with the help of PAN support, figured I'd share it here in case it helps you.&amp;nbsp; For my two LDAP server profiles, i&lt;SPAN&gt;nstead of using LDAP/636 to each of my AD domains (root and child), I switched to GlobalCatalog/3269 to the root domain as well as LDAP/636 to the root domain. I then changed User ID group mapping to use the GlobalCatalog server profile, so that it could read all domains, and blanked the User Domain field in the group mapping config.&amp;nbsp; Next, I added the relevant AD groups to the Group Mapping Group Include list and also to the SAML Authentication Profile Allow List under Advanced.&amp;nbsp; Now in my Agent Client Settings, I add the relevant groups to the Source User list.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Here is the doc that helped me, as it recommends using Global Catalog if you have Universal AD Groups, and also mentions that the User Domain field can usually be left blank in the Group Mapping config: &lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/user-id/map-users-to-groups" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/user-id/map-users-to-groups&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;HTH!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 17:24:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/filtering-by-a-azure-ad-user-does-not-work-in-gateway-gt-agent/m-p/542768#M4030</guid>
      <dc:creator>tamerfahmy</dc:creator>
      <dc:date>2023-05-19T17:24:12Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering by a Azure AD user  does not work in Gateway--&gt;Agent--&gt;Client Settings</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/filtering-by-a-azure-ad-user-does-not-work-in-gateway-gt-agent/m-p/546476#M4144</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/101882"&gt;@tamerfahmy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks a lot for your reply and the link. Not sure if my issue was the same as yours. The AD groups got already populated and I could select the target AD group in the Agent Client Settings, my issue was that it didn't seem to match the condition so the different settings based on AD membership never applied.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I followed your instructions and I created an additional LDAP server profile for the global catalog and then, a new group mapping configuration using that new ldap server profile. Not sure if I should keep both group mappings enabled or not.&lt;/P&gt;
&lt;P&gt;the result keeps the same, I can select the ad group in the Agent Client settings but it is never taken into account.&lt;/P&gt;
&lt;P&gt;I attach some screenshots, maybe you could see where could be my issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks once again for your reply.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 11:57:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/filtering-by-a-azure-ad-user-does-not-work-in-gateway-gt-agent/m-p/546476#M4144</guid>
      <dc:creator>JoseCortijo</dc:creator>
      <dc:date>2023-06-20T11:57:47Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering by a Azure AD user  does not work in Gateway--&gt;Agent--&gt;Client Settings</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/filtering-by-a-azure-ad-user-does-not-work-in-gateway-gt-agent/m-p/562793#M4554</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/244719"&gt;@JoseCortijo&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Yes, I have both group mappings enabled.&lt;/P&gt;
&lt;P&gt;Did you add the relevant AD groups to the Group Include list in the global catalog Group Mapping?&lt;/P&gt;
&lt;P&gt;Also, in the SAML Authentication Profile &amp;gt; Advanced &amp;gt; Allow List, you can try adding the groups explicitly instead of using "all".&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 18:49:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/filtering-by-a-azure-ad-user-does-not-work-in-gateway-gt-agent/m-p/562793#M4554</guid>
      <dc:creator>tamerfahmy</dc:creator>
      <dc:date>2023-10-23T18:49:40Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering by a Azure AD user  does not work in Gateway--&gt;Agent--&gt;Client Settings</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/filtering-by-a-azure-ad-user-does-not-work-in-gateway-gt-agent/m-p/600217#M5926</link>
      <description>&lt;P&gt;Hey &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/244719"&gt;@JoseCortijo&lt;/a&gt;&amp;nbsp;did you find solution for this problem?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2024 09:12:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/filtering-by-a-azure-ad-user-does-not-work-in-gateway-gt-agent/m-p/600217#M5926</guid>
      <dc:creator>nemanja_miloj</dc:creator>
      <dc:date>2024-10-11T09:12:10Z</dc:date>
    </item>
  </channel>
</rss>

