<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What privileges required by service account used by palo alto firewall in LDAP server profile to fetch group information from LDAP server in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/what-privileges-required-by-service-account-used-by-palo-alto/m-p/477499#M103680</link>
    <description>&lt;P&gt;What privileges required by service account used by palo alto firewall in LDAP server profile to fetch group information from LDAP server for group mapping?&lt;/P&gt;&lt;P&gt;Do we need admin privilege ? or&lt;/P&gt;&lt;P&gt;is it enough that we need service account only to be a member of the following groups&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Event Log Reader &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Distributed COM Users &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Server Operators&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 01 Apr 2022 07:43:31 GMT</pubDate>
    <dc:creator>perumalj</dc:creator>
    <dc:date>2022-04-01T07:43:31Z</dc:date>
    <item>
      <title>What privileges required by service account used by palo alto firewall in LDAP server profile to fetch group information from LDAP server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-privileges-required-by-service-account-used-by-palo-alto/m-p/477499#M103680</link>
      <description>&lt;P&gt;What privileges required by service account used by palo alto firewall in LDAP server profile to fetch group information from LDAP server for group mapping?&lt;/P&gt;&lt;P&gt;Do we need admin privilege ? or&lt;/P&gt;&lt;P&gt;is it enough that we need service account only to be a member of the following groups&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Event Log Reader &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Distributed COM Users &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Server Operators&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2022 07:43:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-privileges-required-by-service-account-used-by-palo-alto/m-p/477499#M103680</guid>
      <dc:creator>perumalj</dc:creator>
      <dc:date>2022-04-01T07:43:31Z</dc:date>
    </item>
    <item>
      <title>Re: What privileges required by service account used by palo alto firewall in LDAP server profile to fetch group information from LDAP server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-privileges-required-by-service-account-used-by-palo-alto/m-p/477514#M103681</link>
      <description>&lt;P&gt;Hi Perumal,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Event Log Reader&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Distributed COM Users&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Server Operators&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;These three privilege's&amp;nbsp;enough .&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please refer the below document for your reference.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/kcSArticleDetail?id=kA10g000000ClGG" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/kcSArticleDetail?id=kA10g000000ClGG&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2022 08:08:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-privileges-required-by-service-account-used-by-palo-alto/m-p/477514#M103681</guid>
      <dc:creator>SubaMuthuram</dc:creator>
      <dc:date>2022-04-01T08:08:23Z</dc:date>
    </item>
    <item>
      <title>Re: What privileges required by service account used by palo alto firewall in LDAP server profile to fetch group information from LDAP server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-privileges-required-by-service-account-used-by-palo-alto/m-p/564362#M114198</link>
      <description>&lt;P&gt;The link provided as the "Solution" is for User-ID Service Account, not ActiveDirectory / LDAP Authentication Profile Service Account, they are not one and the same.&lt;BR /&gt;My understanding, is for the Firewall and any PAN Applications (e.g., GlobalProtect) to provide Password Management Services this requires Domain Administrative Privileges' in ActiveDirectory / LDAP. So while the above permissions may be bare minimum to authenticate users, Password Management requires elevated privilege's to perform pass through of Passwords expiry notices, capability to change passwords once expired or set in AD for reset, and ability to report locked accounts.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 19:28:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-privileges-required-by-service-account-used-by-palo-alto/m-p/564362#M114198</guid>
      <dc:creator>BrianMarks</dc:creator>
      <dc:date>2023-11-03T19:28:32Z</dc:date>
    </item>
    <item>
      <title>Re: What privileges required by service account used by palo alto firewall in LDAP server profile to fetch group information from LDAP server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-privileges-required-by-service-account-used-by-palo-alto/m-p/564382#M114205</link>
      <description>&lt;P&gt;For LDAP binding and group mapping you need only to be member of "Domain Users" group.&lt;/P&gt;
&lt;P&gt;Every domain user can read whole LDAP directory so no special permissions needed!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For UserID (so Palo can connect to domain controllers, read security logs and map ip addresses to usernames) you need permissions you mentioned.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Nov 2023 01:23:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-privileges-required-by-service-account-used-by-palo-alto/m-p/564382#M114205</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-11-04T01:23:16Z</dc:date>
    </item>
  </channel>
</rss>

