<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GlobalProtect Machine account exists with device serial number config in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-machine-account-exists-with-device-serial-number/m-p/543421#M111260</link>
    <description>&lt;P&gt;Dear Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm trying to set up GlobalProtect's 'Serial Number Check' feature, but I'm having a hard time.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;GlobalProtect is already being used in conjunction with LDAP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, when I do not use the function, I log in normally.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to control by matching the serial number to the LDAP user.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it correct that the serial number mentioned here means the device ID of Windows/Mac?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And in the firewall, there seems to be nothing to set other than changing the function to 'yes'.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CHOEKyungJun_0-1685060942772.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50348iAC4F314E9F9B2084/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="CHOEKyungJun_0-1685060942772.png" alt="CHOEKyungJun_0-1685060942772.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I tried entering the device ID in Serial Number among the LDAP properties, but it doesn't work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CHOEKyungJun_1-1685060964833.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50349i8992EC79AF96117E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="CHOEKyungJun_1-1685060964833.png" alt="CHOEKyungJun_1-1685060964833.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CHOEKyungJun_2-1685060974068.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50350iAFE743F1C13E937F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="CHOEKyungJun_2-1685060974068.png" alt="CHOEKyungJun_2-1685060974068.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If anyone has done the above setup or knows how to do it, please let me know.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 26 May 2023 00:31:31 GMT</pubDate>
    <dc:creator>CHOE-KyungJun</dc:creator>
    <dc:date>2023-05-26T00:31:31Z</dc:date>
    <item>
      <title>GlobalProtect Machine account exists with device serial number config</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-machine-account-exists-with-device-serial-number/m-p/543421#M111260</link>
      <description>&lt;P&gt;Dear Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm trying to set up GlobalProtect's 'Serial Number Check' feature, but I'm having a hard time.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;GlobalProtect is already being used in conjunction with LDAP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, when I do not use the function, I log in normally.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to control by matching the serial number to the LDAP user.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it correct that the serial number mentioned here means the device ID of Windows/Mac?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And in the firewall, there seems to be nothing to set other than changing the function to 'yes'.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CHOEKyungJun_0-1685060942772.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50348iAC4F314E9F9B2084/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="CHOEKyungJun_0-1685060942772.png" alt="CHOEKyungJun_0-1685060942772.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I tried entering the device ID in Serial Number among the LDAP properties, but it doesn't work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CHOEKyungJun_1-1685060964833.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50349i8992EC79AF96117E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="CHOEKyungJun_1-1685060964833.png" alt="CHOEKyungJun_1-1685060964833.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CHOEKyungJun_2-1685060974068.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50350iAFE743F1C13E937F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="CHOEKyungJun_2-1685060974068.png" alt="CHOEKyungJun_2-1685060974068.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If anyone has done the above setup or knows how to do it, please let me know.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 00:31:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-machine-account-exists-with-device-serial-number/m-p/543421#M111260</guid>
      <dc:creator>CHOE-KyungJun</dc:creator>
      <dc:date>2023-05-26T00:31:31Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Machine account exists with device serial number config</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-machine-account-exists-with-device-serial-number/m-p/543679#M111315</link>
      <description>&lt;P&gt;In looking at the help for this section. &lt;/P&gt;
&lt;TABLE class="FormatA" style="color: #000000; font-family: 'Times New Roman'; font-size: medium; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;" summary=""&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="Table_Cell" style="border-bottom: thin solid black; border-left: thin solid black; border-right: thin solid black; padding-left: 3px; padding-top: 1px; vertical-align: top;"&gt;
&lt;DIV class="Table_Cell" style="font-family: 'Decimal Book', Lato; font-size: 10pt; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 4pt; margin-top: 4pt;"&gt;&lt;A name="ID0EOK4Y" target="_blank"&gt;&lt;/A&gt;Machine account exists with device serial number&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD class="Table_Cell" style="border-bottom: thin solid black; border-left: thin solid black; border-right: thin solid black; padding-left: 3px; padding-top: 1px; vertical-align: top;"&gt;
&lt;DIV class="Table_Cell" style="font-family: 'Decimal Book', Lato; font-size: 10pt; font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 4pt; margin-top: 4pt;"&gt;&lt;A name="ID0EYK4Y" target="_blank"&gt;&lt;/A&gt;Configure matching criteria based on whether the endpoint serial number exists in the Active Directory.&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;BR /&gt;I think it will be to tie to the device (not the user) to LDAP.&lt;BR /&gt;So I think GP can get confirmation that the device belongs in AD (as long as AD responds back).&lt;BR /&gt;I am not sure of the mechanism, but it is best to open a TAC case to get confirmation on the solution.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 28 May 2023 00:11:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-machine-account-exists-with-device-serial-number/m-p/543679#M111315</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2023-05-28T00:11:45Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Machine account exists with device serial number config</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-machine-account-exists-with-device-serial-number/m-p/544239#M111392</link>
      <description>&lt;P&gt;I read additional information that the Serial number check is used by the Cloud Identity Engine for registering endpoints.&lt;BR /&gt;&lt;BR /&gt;If you are using GlobalProtect and you have enabled Serial Number Check, select the Endpoint Serial Number option to allow the Cloud Identity Engine to collect serial numbers from managed endpoints. This information is used by the GlobalProtect portal to check if the serial number exists in the directory for verification that the endpoint is managed by GlobalProtect.&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 20:19:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-machine-account-exists-with-device-serial-number/m-p/544239#M111392</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2023-05-31T20:19:00Z</dc:date>
    </item>
  </channel>
</rss>

