<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Upgrade to PAN OS 10.0 in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/upgrade-to-pan-os-10-0/m-p/476851#M323</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've been on hold for nearly 3hrs trying to get through to TAC after raising my L2 ticket online, the automated message told me I should try the live community &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since upgrading to&amp;nbsp;10.0 (aiming to get to 10.1.4) admins aren't able to login to Panorama to manage prisma access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Log shows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Authorization failed for user jblogs@domain.com via Web from 10.3X.XX.XX : Invalid configuration. &lt;STRONG&gt;No ado/role found&lt;/STRONG&gt; jbloggs@domain.com &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;03/30 02:35:19&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;SAML SSO authenticated for user 'xxx@domain.com . auth profile 'Okta-MGMT-Profile', vsys 'shared', server profile 'Okta-management-SAML', IdP entityID '&lt;A href="http://www.okta.com/XXXXXXXX" target="_blank"&gt;http://www.okta.com/XXXXXXXX&lt;/A&gt;', From:10.3X.XX.XX&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;03/30 02:35:19&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The users&amp;nbsp;have &amp;nbsp;dynamic "super user" role assigned. I'm not sure what "ado" means in the above log but it seems like SAML is authenticating successfully. Any help appreciated.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 30 Mar 2022 11:25:51 GMT</pubDate>
    <dc:creator>jbusby</dc:creator>
    <dc:date>2022-03-30T11:25:51Z</dc:date>
    <item>
      <title>Upgrade to PAN OS 10.0</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/upgrade-to-pan-os-10-0/m-p/476851#M323</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've been on hold for nearly 3hrs trying to get through to TAC after raising my L2 ticket online, the automated message told me I should try the live community &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since upgrading to&amp;nbsp;10.0 (aiming to get to 10.1.4) admins aren't able to login to Panorama to manage prisma access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Log shows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Authorization failed for user jblogs@domain.com via Web from 10.3X.XX.XX : Invalid configuration. &lt;STRONG&gt;No ado/role found&lt;/STRONG&gt; jbloggs@domain.com &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;03/30 02:35:19&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;SAML SSO authenticated for user 'xxx@domain.com . auth profile 'Okta-MGMT-Profile', vsys 'shared', server profile 'Okta-management-SAML', IdP entityID '&lt;A href="http://www.okta.com/XXXXXXXX" target="_blank"&gt;http://www.okta.com/XXXXXXXX&lt;/A&gt;', From:10.3X.XX.XX&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;03/30 02:35:19&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The users&amp;nbsp;have &amp;nbsp;dynamic "super user" role assigned. I'm not sure what "ado" means in the above log but it seems like SAML is authenticating successfully. Any help appreciated.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 11:25:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/upgrade-to-pan-os-10-0/m-p/476851#M323</guid>
      <dc:creator>jbusby</dc:creator>
      <dc:date>2022-03-30T11:25:51Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade to PAN OS 10.0</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/upgrade-to-pan-os-10-0/m-p/477170#M324</link>
      <description>&lt;P&gt;Found the solution:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The upgrade must have removed this parameter that was set by a previous admin:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;set auth strict-username-check no&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's actually documented here:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-new-features/upgrade-pan-os/upgradedowngrade-considerations.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-new-features/upgrade-pan-os/upgradedowngrade-considerations.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 09:10:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/upgrade-to-pan-os-10-0/m-p/477170#M324</guid>
      <dc:creator>jbusby</dc:creator>
      <dc:date>2022-03-31T09:10:27Z</dc:date>
    </item>
  </channel>
</rss>

