<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Service Account used for UserID Agent in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/service-account-used-for-userid-agent/m-p/1230766#M5951</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hi Support Team, We need to ensure the service accounts used for the UserID agents installed on the domain controllers have the right active directory permissions and limit the permissions to what is required for them to function. I have the following question: 1. What are the required permissions and privileges for it to be functional? 2. What are the risks of misconfiguration or disabling this account?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 03 Jun 2025 00:23:37 GMT</pubDate>
    <dc:creator>MasoodBrv</dc:creator>
    <dc:date>2025-06-03T00:23:37Z</dc:date>
    <item>
      <title>Service Account used for UserID Agent</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/service-account-used-for-userid-agent/m-p/1230766#M5951</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi Support Team, We need to ensure the service accounts used for the UserID agents installed on the domain controllers have the right active directory permissions and limit the permissions to what is required for them to function. I have the following question: 1. What are the required permissions and privileges for it to be functional? 2. What are the risks of misconfiguration or disabling this account?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2025 00:23:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/service-account-used-for-userid-agent/m-p/1230766#M5951</guid>
      <dc:creator>MasoodBrv</dc:creator>
      <dc:date>2025-06-03T00:23:37Z</dc:date>
    </item>
    <item>
      <title>Re: Service Account used for UserID Agent</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/service-account-used-for-userid-agent/m-p/1230903#M5956</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I would first direct you to read the best practices:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVPCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVPCA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To answer your questions:&lt;/P&gt;
&lt;P&gt;1.&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/user-id/map-ip-addresses-to-users/create-a-dedicated-service-account-for-the-user-id-agent" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/user-id/map-ip-addresses-to-users/create-a-dedicated-service-account-for-the-user-id-agent&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;2. if you disable the account and have policies that utilize User-ID as a requirement, then this will cause traffic to those policies to not be matched and the traffic would not be allowed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2025 19:51:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/service-account-used-for-userid-agent/m-p/1230903#M5956</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2025-06-03T19:51:21Z</dc:date>
    </item>
  </channel>
</rss>

