<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disable User in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/disable-user/m-p/543376#M111255</link>
    <description>&lt;P&gt;Hi Mike,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;You can create a local user (not a local administrator) under Device &amp;gt; Local User Database &amp;gt; Users.&amp;nbsp; That user has an Enable check box.&lt;/LI&gt;
&lt;LI&gt;Then create an authentication profile that points to the local users.&lt;/LI&gt;
&lt;LI&gt;Then create an admin with the same name and point it to the local authentication profile.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Then you can enable and disable at will.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Thu, 25 May 2023 20:43:30 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2023-05-25T20:43:30Z</dc:date>
    <item>
      <title>Disable User</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-user/m-p/207822#M60862</link>
      <description>&lt;P&gt;Is it possible to disable a user (local account)? I don't see this option in the web gui, but thought it might be something that can be done using the cli. I need to be able to allow access for specific reasons at specific times and disable access when not needed. Changing the user's password each time is the only other option I can think of so far.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Mar 2018 14:48:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-user/m-p/207822#M60862</guid>
      <dc:creator>mike406</dc:creator>
      <dc:date>2018-03-28T14:48:33Z</dc:date>
    </item>
    <item>
      <title>Re: Disable User</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-user/m-p/207844#M60868</link>
      <description>&lt;P&gt;Sounds like you are looking for schedules?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can setup a security policy that allows access and add a schedule to it so it is disabled (or enabled) at certain times. that way the policy is for that user/group of useres and will only allow or disallow the access during a certain window that you have defined.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Details:&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/documentation/71/pan-os/web-interface-help/objects/objects-schedules" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/71/pan-os/web-interface-help/objects/objects-schedules&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Wed, 28 Mar 2018 16:27:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-user/m-p/207844#M60868</guid>
      <dc:creator>hshawn</dc:creator>
      <dc:date>2018-03-28T16:27:06Z</dc:date>
    </item>
    <item>
      <title>Re: Disable User</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-user/m-p/208038#M60922</link>
      <description>&lt;P&gt;I think scheduling might help, but it's not really what I'm after. I need to be able to enable/disable a local user account to allow/deny login to the firewall to perform administration tasks.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 15:00:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-user/m-p/208038#M60922</guid>
      <dc:creator>mike406</dc:creator>
      <dc:date>2018-03-29T15:00:09Z</dc:date>
    </item>
    <item>
      <title>Re: Disable User</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-user/m-p/208047#M60925</link>
      <description>&lt;P&gt;To be clear, you want an administrator account that is disabled until it is needed for a particular task?&amp;nbsp; Another administrator (or api call, etc) would enable that account to allow the task to be completed then disable it when done?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do not know of a settign to disable an account, but you may be able to create an Admin Role that does not allow any access, and assign that to "disable" the account as needed.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 15:14:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-user/m-p/208047#M60925</guid>
      <dc:creator>JoeAndreini</dc:creator>
      <dc:date>2018-03-29T15:14:08Z</dc:date>
    </item>
    <item>
      <title>Re: Disable User</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-user/m-p/208055#M60927</link>
      <description>&lt;P&gt;I think I have a solution. I created a bogus auth_profile with the domain set to a non-existant name and the allow list populated with only a non-matching bogus user. This seems to work.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 15:34:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-user/m-p/208055#M60927</guid>
      <dc:creator>mike406</dc:creator>
      <dc:date>2018-03-29T15:34:59Z</dc:date>
    </item>
    <item>
      <title>Re: Disable User</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-user/m-p/208060#M60928</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79413"&gt;@mike406&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just keep this in mind: if you change something for an account that is already logged in - even if you delete the local account - this will not terminate the existing session. It only prevents new sessions.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 15:46:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-user/m-p/208060#M60928</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-03-29T15:46:57Z</dc:date>
    </item>
    <item>
      <title>Re: Disable User</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-user/m-p/543343#M111253</link>
      <description>&lt;P&gt;This is no longer the case.&amp;nbsp; If you make a change to a local admin while they are logged in, they are forced to reauthenticate.&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 14:28:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-user/m-p/543343#M111253</guid>
      <dc:creator>Jason_Lieberman</dc:creator>
      <dc:date>2023-05-25T14:28:27Z</dc:date>
    </item>
    <item>
      <title>Re: Disable User</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-user/m-p/543376#M111255</link>
      <description>&lt;P&gt;Hi Mike,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;You can create a local user (not a local administrator) under Device &amp;gt; Local User Database &amp;gt; Users.&amp;nbsp; That user has an Enable check box.&lt;/LI&gt;
&lt;LI&gt;Then create an authentication profile that points to the local users.&lt;/LI&gt;
&lt;LI&gt;Then create an admin with the same name and point it to the local authentication profile.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Then you can enable and disable at will.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 20:43:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-user/m-p/543376#M111255</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-05-25T20:43:30Z</dc:date>
    </item>
    <item>
      <title>Re: Disable User</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-user/m-p/543378#M111256</link>
      <description>&lt;P&gt;Doesn't that force the user to use credentials stored in the DB rather than certificates?&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 20:49:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-user/m-p/543378#M111256</guid>
      <dc:creator>Jason_Lieberman</dc:creator>
      <dc:date>2023-05-25T20:49:59Z</dc:date>
    </item>
    <item>
      <title>Re: Disable User</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-user/m-p/543387#M111257</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/182396"&gt;@Jason_Lieberman&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't see anywhere where &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79413"&gt;@mike406&lt;/a&gt; talked about certificates.&amp;nbsp; He mentioned local passwords.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 21:23:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-user/m-p/543387#M111257</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-05-25T21:23:43Z</dc:date>
    </item>
    <item>
      <title>Re: Disable User</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-user/m-p/543391#M111258</link>
      <description>&lt;P&gt;I wasn't trying to debate you.&amp;nbsp; I was just trying to get clarification.&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 21:57:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-user/m-p/543391#M111258</guid>
      <dc:creator>Jason_Lieberman</dc:creator>
      <dc:date>2023-05-25T21:57:59Z</dc:date>
    </item>
    <item>
      <title>Re: Disable User</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-user/m-p/543404#M111259</link>
      <description>&lt;P&gt;Oh!&amp;nbsp; That's cool.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was trying to figure out if it applied to the thread.&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 22:51:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-user/m-p/543404#M111259</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-05-25T22:51:23Z</dc:date>
    </item>
  </channel>
</rss>

