<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: are you permitted to remove all local admin accounts pan-OS 9.1 or higher? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/are-you-permitted-to-remove-all-local-admin-accounts-pan-os-9-1/m-p/464896#M102543</link>
    <description>&lt;P&gt;you're preaching to the choir, as long as your physical security is in place, and you've safeguarded local admin credentials, a local admin is part of good BCP/DRP design. I had to shake my head a little on that one. do you have access to any documentation that I can reference?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Feb 2022 15:02:49 GMT</pubDate>
    <dc:creator>S_Hiebert</dc:creator>
    <dc:date>2022-02-10T15:02:49Z</dc:date>
    <item>
      <title>are you permitted to remove all local admin accounts pan-OS 9.1 or higher?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/are-you-permitted-to-remove-all-local-admin-accounts-pan-os-9-1/m-p/464616#M102514</link>
      <description>&lt;P&gt;hello all,&lt;/P&gt;&lt;P&gt;I'm a PA noob who has recently just transitioned to a team that has a pretty heavy backlog. sorting through it, I see another team has requested that we remove local admin accounts from our firewalls. to my knowledge, the only local accounts on any of the FWs is the default account, with all admins authenticating using AD.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I understand the possible security risks of having a local admin, but not having any backup to networked AAA services sounds really dumb to me. some vendors won't even permit you to run without local credentials.&amp;nbsp;&lt;BR /&gt;does PanOS even permit you to run without a local admin, default or otherwise?&amp;nbsp;&lt;/P&gt;&lt;P&gt;is there any difference between a VM and dedicated appliance? we run both.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any answers or documentation you could provide would be much appreciated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Feb 2022 20:09:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/are-you-permitted-to-remove-all-local-admin-accounts-pan-os-9-1/m-p/464616#M102514</guid>
      <dc:creator>S_Hiebert</dc:creator>
      <dc:date>2022-02-09T20:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: are you permitted to remove all local admin accounts pan-OS 9.1 or higher?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/are-you-permitted-to-remove-all-local-admin-accounts-pan-os-9-1/m-p/464715#M102526</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/207969"&gt;@S_Hiebert&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Why would you ever want to remove any local admin account from your firewalls? If your AAA servers are down you couldn't login, if you made a mistake and severed communication to the box you couldn't login, the upstream network is down you can't login. Sounds like an incompetent security department not thinking through the actual repercussions of what they're requesting.&lt;/P&gt;
&lt;P&gt;Regardless, you can't actually do this in PAN-OS. You need at least one superuser account active in the administrators group to prevent people from doing exactly what your other group is asking.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 03:28:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/are-you-permitted-to-remove-all-local-admin-accounts-pan-os-9-1/m-p/464715#M102526</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-02-10T03:28:02Z</dc:date>
    </item>
    <item>
      <title>Re: are you permitted to remove all local admin accounts pan-OS 9.1 or higher?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/are-you-permitted-to-remove-all-local-admin-accounts-pan-os-9-1/m-p/464896#M102543</link>
      <description>&lt;P&gt;you're preaching to the choir, as long as your physical security is in place, and you've safeguarded local admin credentials, a local admin is part of good BCP/DRP design. I had to shake my head a little on that one. do you have access to any documentation that I can reference?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 15:02:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/are-you-permitted-to-remove-all-local-admin-accounts-pan-os-9-1/m-p/464896#M102543</guid>
      <dc:creator>S_Hiebert</dc:creator>
      <dc:date>2022-02-10T15:02:49Z</dc:date>
    </item>
  </channel>
</rss>

