<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User/Group mapping with GP SAML (User-ID) in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/user-group-mapping-with-gp-saml-user-id/m-p/1225084#M6612</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've got GP configured with SAML authentication and it works great. However, I would need to get out User-ID or group so that I can use them in security policies to allow or deny specific rules and access to resources.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Is that possible and how?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Sat, 29 Mar 2025 16:59:01 GMT</pubDate>
    <dc:creator>GregorJus</dc:creator>
    <dc:date>2025-03-29T16:59:01Z</dc:date>
    <item>
      <title>User/Group mapping with GP SAML (User-ID)</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/user-group-mapping-with-gp-saml-user-id/m-p/1225084#M6612</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've got GP configured with SAML authentication and it works great. However, I would need to get out User-ID or group so that I can use them in security policies to allow or deny specific rules and access to resources.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Is that possible and how?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 29 Mar 2025 16:59:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/user-group-mapping-with-gp-saml-user-id/m-p/1225084#M6612</guid>
      <dc:creator>GregorJus</dc:creator>
      <dc:date>2025-03-29T16:59:01Z</dc:date>
    </item>
    <item>
      <title>Re: User/Group mapping with GP SAML (User-ID)</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/user-group-mapping-with-gp-saml-user-id/m-p/1225098#M6616</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/515434985"&gt;@GregorJus&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, it is possible.&amp;nbsp; All you need to do is enable User-ID on the GP zone in order to turn it on.&amp;nbsp; GP maps the username to IP address.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You have to use LDAP or Cloud Identity Engine (CIE) to map users to groups.&amp;nbsp; In order for group mapping to work, the username in the "show user ip-user-mapping all" command must match exactly with the username in the "show user group name "&amp;lt;group_name_from_show_user_group_list&amp;gt;" command.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/user-id/map-users-to-groups" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/user-id/map-users-to-groups&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cloud-identity/cloud-identity-engine-getting-started/authenticate-users-with-the-cloud-identity-engine/configure-the-cloud-identity-engine-as-a-mapping-source-on-the-firewall" target="_blank"&gt;https://docs.paloaltonetworks.com/cloud-identity/cloud-identity-engine-getting-started/authenticate-users-with-the-cloud-identity-engine/configure-the-cloud-identity-engine-as-a-mapping-source-on-the-firewall&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClpCCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClpCCAS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVcCAK&amp;amp;lang=en_US" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVcCAK&amp;amp;lang=en_US&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2025 02:22:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/user-group-mapping-with-gp-saml-user-id/m-p/1225098#M6616</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2025-03-31T02:22:50Z</dc:date>
    </item>
    <item>
      <title>Re: User/Group mapping with GP SAML (User-ID)</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/user-group-mapping-with-gp-saml-user-id/m-p/1225181#M6617</link>
      <description>&lt;P&gt;Hi, Tom,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your reply, however, it doesn't quite fulfil the requirements I have, just yet. User-ID is already enabled on the zone and I can see the user in the monitor logs. However, I still can't use those users (e.g. &lt;A href="mailto:name.lastname@domain.com" target="_blank"&gt;name.lastname@domain.com&lt;/A&gt;) in security policies, which is what I would need to do.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;LDAP is not an option here, sadly, because these are cloud only (Azure AD joined) machines only - there is no domain on-prem and no hybrid solution possible. I have already implemented CIE as well, however, the issue I am having with it is being unable to fully disable opening browser (even just one tab) with connection notification as users do not want that.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;G&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2025 08:22:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/user-group-mapping-with-gp-saml-user-id/m-p/1225181#M6617</guid>
      <dc:creator>GregorJus</dc:creator>
      <dc:date>2025-03-31T08:22:44Z</dc:date>
    </item>
    <item>
      <title>Re: User/Group mapping with GP SAML (User-ID)</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/user-group-mapping-with-gp-saml-user-id/m-p/1225195#M6618</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/515434985"&gt;@GregorJus&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does the command "show user ip-user-mapping all" show users?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does the command "show user group list" show groups?&amp;nbsp; If so, pick a group and run the "show user group name "&amp;lt;group_name&amp;gt;" command.&amp;nbsp; Do the usernames match the previous command exactly?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The browser (step 9 in the CIE URL I provided) is not needed if you are using GP for user/IP mapping.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Why can't you use the users in the security policy?&amp;nbsp; They will not automatically show up in the drop down list.&amp;nbsp; You have to start typing the name and they will show up.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2025 10:03:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/user-group-mapping-with-gp-saml-user-id/m-p/1225195#M6618</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2025-03-31T10:03:18Z</dc:date>
    </item>
  </channel>
</rss>

