<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo Alto user account in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-user-account/m-p/586793#M3199</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1545369061"&gt;@Abdelhak&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Yes, but what &lt;EM&gt;exactly &lt;/EM&gt;are you trying to give them permission to do? Do you want to have them have the ability to make changes to the configuration &lt;EM&gt;outside &lt;/EM&gt;of modifying other administrators or do they just need to read the configuration?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If it's just reading the configuration then grant a read-only role that meets what you want them to do, otherwise you'll need to build a custom role and ensure that administrators and admin roles are read-only and set the XML, CLI, and REST access appropriately. If they only need GUI access just disable access to everything else.&lt;/P&gt;</description>
    <pubDate>Wed, 15 May 2024 13:31:42 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2024-05-15T13:31:42Z</dc:date>
    <item>
      <title>Palo Alto user account</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-user-account/m-p/586786#M3196</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our customer has a PA-440 firewall deployed with HA and we have a request about the creation of a user account that has a full access to the device over Web UI but it can't change delete or change password of admin account&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is it possible ? and how we can do that ?&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 13:01:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-user-account/m-p/586786#M3196</guid>
      <dc:creator>Abdelhak</dc:creator>
      <dc:date>2024-05-15T13:01:04Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto user account</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-user-account/m-p/586788#M3197</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1545369061"&gt;@Abdelhak&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can create a new administrator account.&amp;nbsp; &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewall-administration/manage-firewall-administrators/configure-administrative-accounts-and-authentication/configure-a-firewall-administrator-account" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewall-administration/manage-firewall-administrators/configure-administrative-accounts-and-authentication/configure-a-firewall-administrator-account&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;While you are logged in as admin&lt;/EM&gt;, you cannot modify the admin account.&amp;nbsp; You will have to create a new administrator account, log in with it, and then you will be able to change or delete the default admin account.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 13:17:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-user-account/m-p/586788#M3197</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-05-15T13:17:11Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto user account</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-user-account/m-p/586790#M3198</link>
      <description>&lt;P&gt;Hi Tom,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our need is to created a new admin account other then the default, but when we sign in using it we should not be able to delete or modify the password of the default admin account&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is it possible ?&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 13:23:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-user-account/m-p/586790#M3198</guid>
      <dc:creator>Abdelhak</dc:creator>
      <dc:date>2024-05-15T13:23:57Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto user account</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-user-account/m-p/586793#M3199</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1545369061"&gt;@Abdelhak&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Yes, but what &lt;EM&gt;exactly &lt;/EM&gt;are you trying to give them permission to do? Do you want to have them have the ability to make changes to the configuration &lt;EM&gt;outside &lt;/EM&gt;of modifying other administrators or do they just need to read the configuration?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If it's just reading the configuration then grant a read-only role that meets what you want them to do, otherwise you'll need to build a custom role and ensure that administrators and admin roles are read-only and set the XML, CLI, and REST access appropriately. If they only need GUI access just disable access to everything else.&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 13:31:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-user-account/m-p/586793#M3199</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-05-15T13:31:42Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto user account</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-user-account/m-p/586794#M3200</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;Our customer need to create another admin account that has the same rights as the default one to give it to other administrators for managing the device but they can't modify or change the password of the default admin account actually used by the main administrator of the site.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is it possible? and how we can do that ?&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 13:40:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-user-account/m-p/586794#M3200</guid>
      <dc:creator>Abdelhak</dc:creator>
      <dc:date>2024-05-15T13:40:47Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto user account</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-user-account/m-p/586797#M3201</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1545369061"&gt;@Abdelhak&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;So with those requirements a custom role assigned to the user is the only way. Build out a custom role and assign it to the created administrator account. The role will need to have 'Administrators' and 'Admin Roles' set to read only, this is the default status on a custom role that has Device access enabled so you'll just need to review everything else.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Keep in mind that this doesn't prevent them from loading a modified configuration file directly and committing it, it just prevents them from modifying things in normal means. You'll have more control over the GUI as you will with the XML, CLI, or REST settings. I would personally highly recommend disabling access to those three for this user, ensuring that 'Adminstrators' and 'Admin Roles' are set to read-only, and setting the 'Operations' tab to read-only so that the user couldn't upload and load a modified configuration file directly.&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 13:54:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-user-account/m-p/586797#M3201</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-05-15T13:54:23Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto user account</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-user-account/m-p/586804#M3203</link>
      <description>&lt;P&gt;Thank you &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1545369061"&gt;@Abdelhak&lt;/a&gt; !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I misunderstood.&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 14:33:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-user-account/m-p/586804#M3203</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-05-15T14:33:17Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto user account</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-user-account/m-p/586805#M3204</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1545369061"&gt;@Abdelhak&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe the built-in Device Administrator role fits the bill?&amp;nbsp; &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewall-administration/manage-firewall-administrators/administrative-role-types" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewall-administration/manage-firewall-administrators/administrative-role-types&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 14:35:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-user-account/m-p/586805#M3204</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-05-15T14:35:48Z</dc:date>
    </item>
  </channel>
</rss>

