<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID Agent: wildcard support in ignore_user_list.txt in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-wildcard-support-in-ignore-user-list-txt/m-p/471056#M103057</link>
    <description>&lt;P&gt;Yeah support speculate it's to prevent potential costly misconfigurations of regex lookups, we've hit our SE up for the FR &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Say hi to mum for me!&lt;/P&gt;</description>
    <pubDate>Mon, 07 Mar 2022 23:23:58 GMT</pubDate>
    <dc:creator>mb_equate</dc:creator>
    <dc:date>2022-03-07T23:23:58Z</dc:date>
    <item>
      <title>User-ID Agent: wildcard support in ignore_user_list.txt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-wildcard-support-in-ignore-user-list-txt/m-p/469988#M102977</link>
      <description>&lt;P&gt;A customer of mine uses a mix of prefixes and suffixes for service and privileged accounts respectively, and needs to ignore these accounts to prevent incorrect mappings. This is&amp;nbsp;especially true where policy applies to non-privileged groups, if a non-privileged user accesses resource with privileged account (e.g. RDP NLA) and their expected policy does not apply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In an ideal world, the ignore-user list should look like this:&lt;/P&gt;&lt;P&gt;*.adm&lt;BR /&gt;svc-*&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The privileged accounts (*.adm) cannot be excluded with a wildcard because it can only be used "&lt;SPAN&gt;as the last character in the entry". In theory this should work for service accounts (svc-*) however that entry is not in the exclude list when viewed from the firewall yet the unsupported entry (*.adm) is:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt; show user user-id-agent config name {agent}&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ignore Users:&lt;BR /&gt;*.adm&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is there a simple way to ignore ip-user-mapping for accounts matching a specific suffix, or must we add users individually (or outsource the job to a powershell script)?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 04:59:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-wildcard-support-in-ignore-user-list-txt/m-p/469988#M102977</guid>
      <dc:creator>mb_equate</dc:creator>
      <dc:date>2022-03-03T04:59:01Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent: wildcard support in ignore_user_list.txt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-wildcard-support-in-ignore-user-list-txt/m-p/470834#M103031</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/127749"&gt;@mb_equate&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;In the meantime, why not add your vote to the existing feature request (&lt;SPAN class="news-body-text"&gt;&lt;SPAN&gt;&lt;STRONG&gt;ID: 7423&lt;/STRONG&gt; -&amp;nbsp; &lt;EM&gt;add ignore list entries using a wildcard at the beginning of the usernames&lt;/EM&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;).&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;To add your vote to this feature request, please reach out to your local sales rep and have him add your vote to FR ID 7423.&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;Cheers !&lt;/P&gt;
&lt;P data-unlink="true"&gt;Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 07 Mar 2022 09:23:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-wildcard-support-in-ignore-user-list-txt/m-p/470834#M103031</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2022-03-07T09:23:39Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent: wildcard support in ignore_user_list.txt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-wildcard-support-in-ignore-user-list-txt/m-p/470865#M103034</link>
      <description>&lt;P&gt;suffix wildcards are not supported in the ignore-user-list, you could try to convince your customers to start using .svc just like they did for .adm &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2022 11:18:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-wildcard-support-in-ignore-user-list-txt/m-p/470865#M103034</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2022-03-07T11:18:16Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent: wildcard support in ignore_user_list.txt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-wildcard-support-in-ignore-user-list-txt/m-p/471056#M103057</link>
      <description>&lt;P&gt;Yeah support speculate it's to prevent potential costly misconfigurations of regex lookups, we've hit our SE up for the FR &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Say hi to mum for me!&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2022 23:23:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-wildcard-support-in-ignore-user-list-txt/m-p/471056#M103057</guid>
      <dc:creator>mb_equate</dc:creator>
      <dc:date>2022-03-07T23:23:58Z</dc:date>
    </item>
  </channel>
</rss>

