<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: USER-ID Rules in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-rules/m-p/542451#M111111</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/249853"&gt;@Sanjay_Ramaiah&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you change the Primary Username to &lt;SPAN&gt;&lt;SPAN class="richTextArea slds-text-longform tile__title red-txt"&gt;userPrincipalName&lt;/SPAN&gt;&lt;/SPAN&gt;, then it will list the group members in UPN format.&amp;nbsp; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000CpgcCAC&amp;amp;lang=en_US%E2%80%A9" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000CpgcCAC&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;&amp;nbsp; The users in the group will match your SAML format.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe you cannot do that because you have other User-ID sources currently working with group mapping.&amp;nbsp; If this is the case, you are on the right track to get your usernames standardized in the right format.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Wed, 17 May 2023 09:59:43 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2023-05-17T09:59:43Z</dc:date>
    <item>
      <title>USER-ID Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-rules/m-p/542264#M111080</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;We have implemented SAML authentication for GP users. Since then the Source User logs are being seen as email IDs and not with the SAMACCOUNTNAME. So the rules implemented with the LDAP user groups are not working. Is there any way we can get this sorted?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Sanjay S&lt;/P&gt;</description>
      <pubDate>Tue, 16 May 2023 07:01:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-rules/m-p/542264#M111080</guid>
      <dc:creator>Sanjay_Ramaiah</dc:creator>
      <dc:date>2023-05-16T07:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: USER-ID Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-rules/m-p/542297#M111086</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/249853"&gt;@Sanjay_Ramaiah&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What do you have configured for your Primary Username under Device &amp;gt; User Identification &amp;gt; Group Mapping Settings &amp;gt; User and Group Attributes?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TomYoung_0-1684235448163.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50181i8F18DA02DD147908/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TomYoung_0-1684235448163.png" alt="TomYoung_0-1684235448163.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That should fix the problem.&amp;nbsp; If not, there are a couple other options:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Many SAML providers allow you to change the username format in their configuration.&lt;/LI&gt;
&lt;LI&gt;Normally, you could adjust the User Domain and Username Modifier fields in the authentication profile, but SAML is different.&amp;nbsp; I wonder if modifying the User Attributes in SAML Messages from IDP would fix it?&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Edit:&amp;nbsp; Forgot to post URL -&amp;gt; &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/user-identification/device-user-identification-group-mapping-settings" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/user-identification/device-user-identification-group-mapping-settings&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 May 2023 19:48:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-rules/m-p/542297#M111086</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-05-16T19:48:32Z</dc:date>
    </item>
    <item>
      <title>Re: USER-ID Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-rules/m-p/542421#M111106</link>
      <description>&lt;P&gt;Thank you very much Tom for your reply.&lt;/P&gt;
&lt;P&gt;In the Group Mapping we have configured the Server Profile with the PrimaryUsername as SAMACCOUNTNAME itself. After we started using SAML it will not check the Group Mappings right so now we are facing this issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you suggested will check at the SAML Provider end to see if we can make some changes. Will keep this chain updated. Thanks again &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2023 07:30:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-rules/m-p/542421#M111106</guid>
      <dc:creator>Sanjay_Ramaiah</dc:creator>
      <dc:date>2023-05-17T07:30:25Z</dc:date>
    </item>
    <item>
      <title>Re: USER-ID Rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-rules/m-p/542451#M111111</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/249853"&gt;@Sanjay_Ramaiah&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you change the Primary Username to &lt;SPAN&gt;&lt;SPAN class="richTextArea slds-text-longform tile__title red-txt"&gt;userPrincipalName&lt;/SPAN&gt;&lt;/SPAN&gt;, then it will list the group members in UPN format.&amp;nbsp; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000CpgcCAC&amp;amp;lang=en_US%E2%80%A9" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000CpgcCAC&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;&amp;nbsp; The users in the group will match your SAML format.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe you cannot do that because you have other User-ID sources currently working with group mapping.&amp;nbsp; If this is the case, you are on the right track to get your usernames standardized in the right format.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2023 09:59:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-rules/m-p/542451#M111111</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-05-17T09:59:43Z</dc:date>
    </item>
  </channel>
</rss>

