<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User-ID - LDAP - Different domains at samAccountName and userPrincipalName in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-ldap-different-domains-at-samaccountname-and/m-p/463675#M102399</link>
    <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the following problem:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A Sub-AD-Domain in a forest with different domains at samAccountName and userPrincipalName.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;samAccountName: domain01\user01&lt;BR /&gt;userPrincipalName: user01@domain02.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dial-in with Global Protect via SAML with &lt;A href="mailto:user01@domain02.com" target="_blank"&gt;user01@domain02.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA recognizes user as user01@domain02.com. All rules based on User-ID don't work, because PA can't recognize the user (logically) via the existing Group Mapping (User Domain = domain01):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Daniel_Treutle_0-1644137123103.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38985iFA8C8C10FE9ED558/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Daniel_Treutle_0-1644137123103.png" alt="Daniel_Treutle_0-1644137123103.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My idea was to add another Group Mapping which additionally picks up the "domain02.com":&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Daniel_Treutle_1-1644137168688.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38986i94E372C902E75DA7/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Daniel_Treutle_1-1644137168688.png" alt="Daniel_Treutle_1-1644137168688.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But unfortunately User-ID spins completely after that. Sometimes a user is recognized, sometimes not. Total chaos.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know how to solve this?&lt;/P&gt;</description>
    <pubDate>Sun, 06 Feb 2022 08:50:03 GMT</pubDate>
    <dc:creator>Daniel_Treutle</dc:creator>
    <dc:date>2022-02-06T08:50:03Z</dc:date>
    <item>
      <title>User-ID - LDAP - Different domains at samAccountName and userPrincipalName</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-ldap-different-domains-at-samaccountname-and/m-p/463675#M102399</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the following problem:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A Sub-AD-Domain in a forest with different domains at samAccountName and userPrincipalName.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;samAccountName: domain01\user01&lt;BR /&gt;userPrincipalName: user01@domain02.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dial-in with Global Protect via SAML with &lt;A href="mailto:user01@domain02.com" target="_blank"&gt;user01@domain02.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA recognizes user as user01@domain02.com. All rules based on User-ID don't work, because PA can't recognize the user (logically) via the existing Group Mapping (User Domain = domain01):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Daniel_Treutle_0-1644137123103.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38985iFA8C8C10FE9ED558/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Daniel_Treutle_0-1644137123103.png" alt="Daniel_Treutle_0-1644137123103.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My idea was to add another Group Mapping which additionally picks up the "domain02.com":&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Daniel_Treutle_1-1644137168688.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38986i94E372C902E75DA7/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Daniel_Treutle_1-1644137168688.png" alt="Daniel_Treutle_1-1644137168688.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But unfortunately User-ID spins completely after that. Sometimes a user is recognized, sometimes not. Total chaos.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know how to solve this?&lt;/P&gt;</description>
      <pubDate>Sun, 06 Feb 2022 08:50:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-ldap-different-domains-at-samaccountname-and/m-p/463675#M102399</guid>
      <dc:creator>Daniel_Treutle</dc:creator>
      <dc:date>2022-02-06T08:50:03Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID - LDAP - Different domains at samAccountName and userPrincipalName</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-ldap-different-domains-at-samaccountname-and/m-p/463822#M102418</link>
      <description>&lt;P&gt;try setting your LDAP profile to port&amp;nbsp;&lt;STRONG&gt;3268&lt;/STRONG&gt; so you use the global catalog rather than the default ldap, this should help you create multiple group mappings for all your domains&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 12:38:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-ldap-different-domains-at-samaccountname-and/m-p/463822#M102418</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2022-02-07T12:38:36Z</dc:date>
    </item>
    <item>
      <title>Betreff: User-ID - LDAP - Different domains at samAccountName and userPrincipalName</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-ldap-different-domains-at-samaccountname-and/m-p/464193#M102458</link>
      <description>&lt;P&gt;Great! Working. Thank you so much!&lt;/P&gt;</description>
      <pubDate>Tue, 08 Feb 2022 12:55:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-ldap-different-domains-at-samaccountname-and/m-p/464193#M102458</guid>
      <dc:creator>Daniel_Treutle</dc:creator>
      <dc:date>2022-02-08T12:55:01Z</dc:date>
    </item>
  </channel>
</rss>

