<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Group Based Administrator Account in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/group-based-administrator-account/m-p/466792#M102725</link>
    <description>&lt;P&gt;Hi BPry,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can we use RADIUS auth profile. So from a single administrative account we can use a group to login to the firewall. So we no need to create individual admin account for each users.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 18 Feb 2022 15:48:57 GMT</pubDate>
    <dc:creator>SubaMuthuram</dc:creator>
    <dc:date>2022-02-18T15:48:57Z</dc:date>
    <item>
      <title>Group Based Administrator Account</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/group-based-administrator-account/m-p/466738#M102715</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any option in Palo Alto, To create a single administrative account for a user group fetched from RADIUS.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Feb 2022 12:05:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/group-based-administrator-account/m-p/466738#M102715</guid>
      <dc:creator>SubaMuthuram</dc:creator>
      <dc:date>2022-02-18T12:05:53Z</dc:date>
    </item>
    <item>
      <title>Re: Group Based Administrator Account</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/group-based-administrator-account/m-p/466788#M102723</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179734"&gt;@SubaMuthuram&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;This isn't an option available on the firewall. You can't tie a group to a single account&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Feb 2022 15:41:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/group-based-administrator-account/m-p/466788#M102723</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-02-18T15:41:33Z</dc:date>
    </item>
    <item>
      <title>Re: Group Based Administrator Account</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/group-based-administrator-account/m-p/466792#M102725</link>
      <description>&lt;P&gt;Hi BPry,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can we use RADIUS auth profile. So from a single administrative account we can use a group to login to the firewall. So we no need to create individual admin account for each users.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Feb 2022 15:48:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/group-based-administrator-account/m-p/466792#M102725</guid>
      <dc:creator>SubaMuthuram</dc:creator>
      <dc:date>2022-02-18T15:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: Group Based Administrator Account</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/group-based-administrator-account/m-p/466794#M102727</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179734"&gt;@SubaMuthuram&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Let me check if I understand your question correctly - you want to group of users to authenticate and use the same username for administrating the firewall?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This doesn't look like good idea... It is best practise to have personal administrative accounts. This way you always know who, do what when. If you plan to have multiple users login to firewall with same account, why complicating and using RADIUS, just create local superadmin and put the password on peace of paper and gave it to the users (sorry, being sarcastic).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I haven't understand your question and you actually want to allow which users are allowed to connect to firewall admin, based on group membership. Yes, that can be configured&lt;/P&gt;
&lt;P&gt;I would you suggest to check this link - &lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/firewall-administration/manage-firewall-administrators/administrative-authentication.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/firewall-administration/manage-firewall-administrators/administrative-authentication.html&lt;/A&gt; you see which protocol support both external authentication and authorization (meaning you don't have to create account on the firewall)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From there you can&amp;nbsp; check how to setup RADIUS for admin login &lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/authentication/configure-radius-authentication.html#id01590369-93b6-48be-8928-eac0ade51d5d" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/authentication/configure-radius-authentication.html#id01590369-93b6-48be-8928-eac0ade51d5d&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Feb 2022 15:57:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/group-based-administrator-account/m-p/466794#M102727</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-02-18T15:57:21Z</dc:date>
    </item>
    <item>
      <title>Re: Group Based Administrator Account</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/group-based-administrator-account/m-p/466866#M102731</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is what I was looking for,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;From there you can&amp;nbsp; check how to setup RADIUS for admin login&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/authentication/configure-radius-authentication.html#id01590369-93b6-48be-8928-eac0ade51d5d" target="_blank" rel="nofollow noopener noreferrer"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/authentication/configure-radius-authentic...&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Feb 2022 19:30:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/group-based-administrator-account/m-p/466866#M102731</guid>
      <dc:creator>SubaMuthuram</dc:creator>
      <dc:date>2022-02-18T19:30:08Z</dc:date>
    </item>
  </channel>
</rss>

