<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Time-Based Access Restriction and Password Expiration for Local Users in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/time-based-access-restriction-and-password-expiration-for-local/m-p/1261355#M7088</link>
    <description>&lt;P&gt;You can attach "Password Profile" to locally configured administrators.&lt;/P&gt;
&lt;P&gt;This fills password change requirement.&lt;/P&gt;
&lt;P&gt;Assuming you have segmented network where those admins source from LAN or GlobalProtect zone and reach to MGMT zone for Palo management (admin to Palo traffic passes Palo dataplane) then you can simply create security policy with "Schedule" attached to it (can be configured on Actions tab) to specify time window when those sessions are permitted.&lt;/P&gt;</description>
    <pubDate>Fri, 07 Aug 2026 11:51:19 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2026-08-07T11:51:19Z</dc:date>
    <item>
      <title>Time-Based Access Restriction and Password Expiration for Local Users</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/time-based-access-restriction-and-password-expiration-for-local/m-p/1261227#M7085</link>
      <description>&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;Hello Palo Alto Community Team,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;I need your assistance with configuring local user accounts on a Palo Alto Networks firewall.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;My requirements are:&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL start="1" data-spread="false"&gt;
&lt;LI&gt;&lt;SPAN&gt;Configure &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;time-based access restrictions&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; for specific local users. For example, allow a user to log in only during a specified time period (such as Monday–Friday, 8:00 AM to 5:00 PM).&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Configure &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;password expiration&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; for each local user so that users are required to change their password after a defined number of days.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;Could you please advise:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL data-spread="false"&gt;
&lt;LI&gt;&lt;SPAN&gt;Whether these features are supported for &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;local users&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; on the Palo Alto firewall?&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;If supported, what is the recommended configuration procedure?&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;If these features are not available for local users, what is the recommended alternative (for example, using LDAP, Active Directory, or another authentication method)?&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;Thank you for your support.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Kind regards,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2026 09:16:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/time-based-access-restriction-and-password-expiration-for-local/m-p/1261227#M7085</guid>
      <dc:creator>SamuelKas</dc:creator>
      <dc:date>2026-08-06T09:16:51Z</dc:date>
    </item>
    <item>
      <title>Re: Time-Based Access Restriction and Password Expiration for Local Users</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/time-based-access-restriction-and-password-expiration-for-local/m-p/1261355#M7088</link>
      <description>&lt;P&gt;You can attach "Password Profile" to locally configured administrators.&lt;/P&gt;
&lt;P&gt;This fills password change requirement.&lt;/P&gt;
&lt;P&gt;Assuming you have segmented network where those admins source from LAN or GlobalProtect zone and reach to MGMT zone for Palo management (admin to Palo traffic passes Palo dataplane) then you can simply create security policy with "Schedule" attached to it (can be configured on Actions tab) to specify time window when those sessions are permitted.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Aug 2026 11:51:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/time-based-access-restriction-and-password-expiration-for-local/m-p/1261355#M7088</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2026-08-07T11:51:19Z</dc:date>
    </item>
  </channel>
</rss>

