<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to set 2FA to local superuser in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-set-2fa-to-local-superuser/m-p/524882#M108576</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Correct, the builtin or local accounts to the firewall are all stored on the firewall and do not use external means for authentication. Best option is to use the 'Minimum Password Complexity' and set the settings fairly high and tight. Here are the settings for the STIG, but the password lengths should be over 30 and randomly generated along with rotated.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_0-1671736924169.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/46360iE37699E7F3826841/image-size/medium?v=v2&amp;amp;px=400" role="button" title="OtakarKlier_0-1671736924169.png" alt="OtakarKlier_0-1671736924169.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you utilize the password change, make sure you do it prior to it needing to be changed or you could get locked out of it! Also if you use API passwords, these will also change when the passwords are changes/rotated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Thu, 22 Dec 2022 19:23:06 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2022-12-22T19:23:06Z</dc:date>
    <item>
      <title>How to set 2FA to local superuser</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-set-2fa-to-local-superuser/m-p/524847#M108568</link>
      <description>&lt;P style="font-weight: 400;"&gt;Prerequisites&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;Currently,&amp;nbsp; user has two admin accounts.&lt;/P&gt;
&lt;OL style="font-weight: 400;"&gt;
&lt;LI&gt;Default local admin account(Superuser)&lt;/LI&gt;
&lt;LI&gt;New local admin account synchronized with Cisco Duo(Superuser)&lt;/LI&gt;
&lt;/OL&gt;
&lt;P style="font-weight: 400;"&gt;End user has to consider how to treat “Default local admin account”.&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;As a result of consideration, the following items are the options to deal with it:&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;Option1: To make “Default local admin account” synchronized with some authenticator like Duo or enhance the login security of this account in some way.&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;Option2: To delete “Default local admin account”&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;■Verification (Done)&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;Option1:Paloalto claims that a local superuser account is not assigned&amp;nbsp;to any form of external authentication service other than just password authentication on the firewall.&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;This is to ensure that users can still access the firewall, in the event where the network or the authentication server goes down, and this will be the only local account to access the firewall.&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;⇒It means that it is impossible to make “Default local admin account” synchronized with multi-factor authenticator.&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;Option2:He tried to delete “Default local admin account” but it could not be carried out with the message “At least, one local Superuser needs to be defined in Administrators”.&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;■What is the checking point in this issue to Paloalto？&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;Regarding Option 1, Please confirm more to Paloalto if there are other ways to enhance authentication and security for this option 1.&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2022 10:03:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-set-2fa-to-local-superuser/m-p/524847#M108568</guid>
      <dc:creator>Purushotham</dc:creator>
      <dc:date>2022-12-22T10:03:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to set 2FA to local superuser</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-set-2fa-to-local-superuser/m-p/524882#M108576</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Correct, the builtin or local accounts to the firewall are all stored on the firewall and do not use external means for authentication. Best option is to use the 'Minimum Password Complexity' and set the settings fairly high and tight. Here are the settings for the STIG, but the password lengths should be over 30 and randomly generated along with rotated.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_0-1671736924169.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/46360iE37699E7F3826841/image-size/medium?v=v2&amp;amp;px=400" role="button" title="OtakarKlier_0-1671736924169.png" alt="OtakarKlier_0-1671736924169.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you utilize the password change, make sure you do it prior to it needing to be changed or you could get locked out of it! Also if you use API passwords, these will also change when the passwords are changes/rotated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2022 19:23:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-set-2fa-to-local-superuser/m-p/524882#M108576</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-12-22T19:23:06Z</dc:date>
    </item>
  </channel>
</rss>

