<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can we limit the Panorama XML API access ? in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/how-can-we-limit-the-panorama-xml-api-access/m-p/582537#M2263</link>
    <description>&lt;P&gt;Hello, did you find a solution to this? I'm trying to do the same thing to limit an admin account's XML API access to specific device groups. Unfortunately, it looks like using an Access Domain with "Device Group and Template" doesn't provide access to XML API. From what I see, it only provides access to Web GUI and REST API. Did you find a workaround for this? Thanks!&lt;/P&gt;</description>
    <pubDate>Wed, 03 Apr 2024 18:01:20 GMT</pubDate>
    <dc:creator>jeremyafaulkner</dc:creator>
    <dc:date>2024-04-03T18:01:20Z</dc:date>
    <item>
      <title>How can we limit the Panorama XML API access ?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/how-can-we-limit-the-panorama-xml-api-access/m-p/556630#M1816</link>
      <description>&lt;P&gt;How can we limit the Panorama XML API access ?&lt;/P&gt;
&lt;P&gt;How can we limit the Panorama XML API access ? We are using this XML API for Terraform and ansible automation. We want to give only access to few device group and we don't want to give access to all device group. please advice how can we achieve this. We checked in Admin roles in Panorama and we don't see much options to restrict to specific device group&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Our request is - how can we restrict the API access to only certain device group.&lt;BR /&gt;Wiki pages in the palo website doesn't have any information about how can we limit only to certain device group.&lt;/P&gt;
&lt;P&gt;I'm elaborating more with example here.&lt;/P&gt;
&lt;P&gt;device group - INETFW1&lt;BR /&gt;device group - INETFW1&lt;BR /&gt;device group - SNETFW1&lt;BR /&gt;device group - SNETFW2&lt;/P&gt;
&lt;P&gt;we want to give only API XML access to INETFW1 and SNETFW1 device group ? how can we achieve this?&lt;/P&gt;
&lt;P&gt;what we need to have is a custom privilege to be restricted on to specific device group in Panorama XML API access.&lt;BR /&gt;Please let us know how can we limit the panorama XML API access to specific device group?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2023 02:46:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/how-can-we-limit-the-panorama-xml-api-access/m-p/556630#M1816</guid>
      <dc:creator>ManojManoj</dc:creator>
      <dc:date>2023-09-06T02:46:14Z</dc:date>
    </item>
    <item>
      <title>Re: How can we limit the Panorama XML API access ?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/how-can-we-limit-the-panorama-xml-api-access/m-p/556647#M1821</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/313840"&gt;@ManojManoj&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for posting.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This should be possible with Access Domains combined with Admin Roles. Here is documentation for reference:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/panorama-overview/role-based-access-control/access-domains" target="_self"&gt;Access Domains&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2023 03:40:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/how-can-we-limit-the-panorama-xml-api-access/m-p/556647#M1821</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2023-09-06T03:40:30Z</dc:date>
    </item>
    <item>
      <title>Re: How can we limit the Panorama XML API access ?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/how-can-we-limit-the-panorama-xml-api-access/m-p/557106#M1833</link>
      <description>&lt;P&gt;Hi @Pavel,&lt;/P&gt;
&lt;P&gt;Please don't blindly answer without understanding the question mentioned here. &lt;BR /&gt;Our requirement is to restrict the access via API and not via web gui or other ways. &lt;BR /&gt;Did you check it in your lab system Panorama for restricting XML API access before you comment about this?&lt;BR /&gt;Did you have previous experience dealing this XML API access restriction in Panorama?&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2023 03:46:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/how-can-we-limit-the-panorama-xml-api-access/m-p/557106#M1833</guid>
      <dc:creator>ManojManoj</dc:creator>
      <dc:date>2023-09-08T03:46:34Z</dc:date>
    </item>
    <item>
      <title>Re: How can we limit the Panorama XML API access ?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/how-can-we-limit-the-panorama-xml-api-access/m-p/557110#M1834</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/313840"&gt;@ManojManoj&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I read your post carefully before replying to you. I have been using access domain in the past only for GUI access. By reading your post the access domain came to my mind as possible solution. I checked the API documentation and this parameter is passed in the API call therefore I deemed this as possible:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_0-1694146484518.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53533i41422CA0BF473AAD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="PavelK_0-1694146484518.png" alt="PavelK_0-1694146484518.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The answer to your second question, no, I have not verified it in the lab.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2023 04:17:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/how-can-we-limit-the-panorama-xml-api-access/m-p/557110#M1834</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2023-09-08T04:17:21Z</dc:date>
    </item>
    <item>
      <title>Re: How can we limit the Panorama XML API access ?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/how-can-we-limit-the-panorama-xml-api-access/m-p/582537#M2263</link>
      <description>&lt;P&gt;Hello, did you find a solution to this? I'm trying to do the same thing to limit an admin account's XML API access to specific device groups. Unfortunately, it looks like using an Access Domain with "Device Group and Template" doesn't provide access to XML API. From what I see, it only provides access to Web GUI and REST API. Did you find a workaround for this? Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 18:01:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/how-can-we-limit-the-panorama-xml-api-access/m-p/582537#M2263</guid>
      <dc:creator>jeremyafaulkner</dc:creator>
      <dc:date>2024-04-03T18:01:20Z</dc:date>
    </item>
    <item>
      <title>Re: How can we limit the Panorama XML API access ?</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/how-can-we-limit-the-panorama-xml-api-access/m-p/1238119#M2978</link>
      <description>&lt;P&gt;Hello, have you confirmed if Access Domains combined with Admin Roles will work to limit API access to certain device groups?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Travis&lt;/P&gt;</description>
      <pubDate>Tue, 16 Sep 2025 21:26:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/how-can-we-limit-the-panorama-xml-api-access/m-p/1238119#M2978</guid>
      <dc:creator>trjohnson</dc:creator>
      <dc:date>2025-09-16T21:26:02Z</dc:date>
    </item>
  </channel>
</rss>

