<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User Mapping - AD access denied in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-mapping-ad-access-denied/m-p/530957#M109518</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&lt;BR /&gt;&lt;BR /&gt;After I went through the log, the error log number generated by the customer PA is 1288,1603 and the error log number written in the URL is 1587,1272.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;UL style="font-weight: 400;"&gt;
&lt;LI&gt;&lt;SPAN&gt;2023-02-08 06:54:00.114 +0900 Error:&amp;nbsp; pan_user_id_win_get_error_status(pan_user_id_win.c:&lt;STRONG&gt;1288&lt;/STRONG&gt;) : WMIC message from server AD_3: NTSTATUS: NT_STATUS_ACCESS_DENIED - Access denied&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN&gt;2023-02-08 06:54:01.111 +0900 Error:&amp;nbsp; pan_user_id_win_wmic_log_query(pan_user_id_win.c:&lt;STRONG&gt;1603&lt;/STRONG&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; log query for AD_2 failed: NTSTATUS: NT_STATUS_ACCESS_DENIED - Access denied&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-02-14 at 9.23.00 AM.png" style="width: 846px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47888i00D720B71DDE0CAA/image-dimensions/846x55/is-moderation-mode/true?v=v2" width="846" height="55" role="button" title="Screenshot 2023-02-14 at 9.23.00 AM.png" alt="Screenshot 2023-02-14 at 9.23.00 AM.png" /&gt;&lt;/span&gt;&lt;BR /&gt;Can the same issue occur in this case?&lt;BR /&gt;&lt;BR /&gt;Additionally, the customer is using the &lt;STRONG&gt;KB5015808&lt;/STRONG&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Tue, 14 Feb 2023 04:39:41 GMT</pubDate>
    <dc:creator>JoHyeonJae</dc:creator>
    <dc:date>2023-02-14T04:39:41Z</dc:date>
    <item>
      <title>User Mapping - AD access denied</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-mapping-ad-access-denied/m-p/530232#M109422</link>
      <description>&lt;P&gt;Hello all,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;You are using Microsoft Active Directory, but you receive the following error log:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Useridd.log&amp;nbsp;&lt;BR /&gt;&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL style="font-weight: 400;"&gt;
&lt;LI&gt;&lt;SPAN&gt;Error:&amp;nbsp; pan_user_id_win_wmic_log_query(pan_user_id_win.c:1603): log query for AD_3 failed: NTSTATUS: NT_STATUS_ACCESS_DENIED - Access denied&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;2023-02-08 06:54:00.114 +0900 Error:&amp;nbsp; pan_user_id_win_get_error_status(pan_user_id_win.c:1288) : WMIC message from server AD_3: NTSTATUS: NT_STATUS_ACCESS_DENIED - Access denied&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;2023-02-08 06:54:01.111 +0900 Error:&amp;nbsp; pan_user_id_win_wmic_log_query(pan_user_id_win.c:1603): log query for AD_2 failed: NTSTATUS: NT_STATUS_ACCESS_DENIED - Access denied&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;2023-02-08 06:54:01.111 +0900 Error:&amp;nbsp; pan_user_id_win_get_error_status(pan_user_id_win.c:1288): WMIC message from server AD_2: NTSTATUS: NT_STATUS_ACCESS_DENIED - Access denied&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;2023-02-08 06:54:02.114 +0900 2023-02-08 06:54:02.114 +0900 Error:&amp;nbsp; pan_user_id_win_wmic_log_query(pan_user_id_win.c:1603): log query for AD_3 failed: NTSTATUS: NT_STATUS_ACCESS_DENIED - Access denied&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;2023-02-08 06:54:02.114 +0900 Error:&amp;nbsp; pan_user_id_win_get_error_status(pan_user_id_win.c:1288): WMIC message from server AD_3: NTSTATUS: NT_STATUS_ACCESS_DENIED - Access denied&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Error:&amp;nbsp; pan_user_id_win_wmic_log_query(pan_user_id_win.c:1603): log query for AD_1 failed: NTSTATUS: NT_STATUS_ACCESS_DENIED - Access denied&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;2023-02-08 06:54:02.114 +0900 Error:&amp;nbsp; pan_user_id_win_get_error_status(pan_user_id_win.c:1288): WMIC message from server AD_1: NTSTATUS: NT_STATUS_ACCESS_DENIED - Access denied&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;2023-02-08 06:54:03.114 +0900 Error:&amp;nbsp; pan_user_id_win_wmic_log_query(pan_user_id_win.c:1603): log query for AD_2 failed: NTSTATUS: NT_STATUS_ACCESS_DENIED - Access denied&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;2023-02-08 06:54:03.114 +0900 Error:&amp;nbsp; pan_user_id_win_get_error_status(pan_user_id_win.c:1288): WMIC message from server AD_2: NTSTATUS: NT_STATUS_ACCESS_DENIED - Access denied&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;2023-02-08 06:54:04.115 +0900 Error:&amp;nbsp; pan_user_id_win_wmic_log_query(pan_user_id_win.c:1603): log query for AD_1 failed: NTSTATUS: NT_STATUS_ACCESS_DENIED - Access denied&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;2023-02-08 06:54:04.115 +0900 Error:&amp;nbsp; pan_user_id_win_get_error_status(pan_user_id_win.c:1288): WMIC message from server AD_1: NTSTATUS: NT_STATUS_ACCESS_DENIED - Access denied&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;These issues occur even if AD settings are checked and changed based on the link below.&lt;BR /&gt;&amp;gt;&lt;A title="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGGCA0" contenteditable="false" href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGGCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGGCA0&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Has anyone experienced and solved these issues?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2023 02:23:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-mapping-ad-access-denied/m-p/530232#M109422</guid>
      <dc:creator>JoHyeonJae</dc:creator>
      <dc:date>2023-02-08T02:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: User Mapping - AD access denied</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-mapping-ad-access-denied/m-p/530233#M109423</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/208779"&gt;@JoHyeonJae&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You need to look at the security event viewer on your AD server to see the specific reason the access is denied.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2023 02:37:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-mapping-ad-access-denied/m-p/530233#M109423</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-02-08T02:37:16Z</dc:date>
    </item>
    <item>
      <title>RE: User Mapping - AD access denied</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-mapping-ad-access-denied/m-p/530398#M109453</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I have looked through the security event viewer on the Server side.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;But, t&lt;SPAN&gt;here was no evidence to cause it. Is there anything else I can check?&lt;BR /&gt;&lt;BR /&gt;And I found the following article while tracking the error log that occurred. Is it not related to the issue that occurred?&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://support.microsoft.com/en-us/topic/kb5004442-manage-changes-for-windows-dcom-server-security-feature-bypass-cve-2021-26414-f1400b52-c141-43d2-941e-37ed901c769c" target="_blank"&gt;https://support.microsoft.com/en-us/topic/kb5004442-manage-changes-for-windows-dcom-server-security-feature-bypass-cve-2021-26414-f1400b52-c141-43d2-941e-37ed901c769c&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 00:56:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-mapping-ad-access-denied/m-p/530398#M109453</guid>
      <dc:creator>JoHyeonJae</dc:creator>
      <dc:date>2023-02-09T00:56:49Z</dc:date>
    </item>
    <item>
      <title>Re: User Mapping - AD access denied</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-mapping-ad-access-denied/m-p/530420#M109456</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/208779"&gt;@JoHyeonJae&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;So you see the DCOM error on the server?&amp;nbsp; It will be in the system event viewer.&amp;nbsp;&lt;/FONT&gt; Thank you for that URL.&amp;nbsp; It has been updated since I last looked.&amp;nbsp; It looks like this issue -&amp;gt; &lt;A href="https://live.paloaltonetworks.com/t5/general-topics/user-identification-and-winrm-on-http/m-p/481674" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/general-topics/user-identification-and-winrm-on-http/m-p/481674&lt;/A&gt;.&amp;nbsp; It sounds like if you apply the patch you will be good, but it may be disabled next month.&amp;nbsp; I think PANW will need to provide a fix by then.&amp;nbsp; Please let me know what you find.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 00:30:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-mapping-ad-access-denied/m-p/530420#M109456</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-02-14T00:30:16Z</dc:date>
    </item>
    <item>
      <title>Re: User Mapping - AD access denied</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-mapping-ad-access-denied/m-p/530957#M109518</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&lt;BR /&gt;&lt;BR /&gt;After I went through the log, the error log number generated by the customer PA is 1288,1603 and the error log number written in the URL is 1587,1272.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;UL style="font-weight: 400;"&gt;
&lt;LI&gt;&lt;SPAN&gt;2023-02-08 06:54:00.114 +0900 Error:&amp;nbsp; pan_user_id_win_get_error_status(pan_user_id_win.c:&lt;STRONG&gt;1288&lt;/STRONG&gt;) : WMIC message from server AD_3: NTSTATUS: NT_STATUS_ACCESS_DENIED - Access denied&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN&gt;2023-02-08 06:54:01.111 +0900 Error:&amp;nbsp; pan_user_id_win_wmic_log_query(pan_user_id_win.c:&lt;STRONG&gt;1603&lt;/STRONG&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; log query for AD_2 failed: NTSTATUS: NT_STATUS_ACCESS_DENIED - Access denied&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-02-14 at 9.23.00 AM.png" style="width: 846px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47888i00D720B71DDE0CAA/image-dimensions/846x55/is-moderation-mode/true?v=v2" width="846" height="55" role="button" title="Screenshot 2023-02-14 at 9.23.00 AM.png" alt="Screenshot 2023-02-14 at 9.23.00 AM.png" /&gt;&lt;/span&gt;&lt;BR /&gt;Can the same issue occur in this case?&lt;BR /&gt;&lt;BR /&gt;Additionally, the customer is using the &lt;STRONG&gt;KB5015808&lt;/STRONG&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 14 Feb 2023 04:39:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-mapping-ad-access-denied/m-p/530957#M109518</guid>
      <dc:creator>JoHyeonJae</dc:creator>
      <dc:date>2023-02-14T04:39:41Z</dc:date>
    </item>
  </channel>
</rss>

