<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows User-ID Agent  Access is denied in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-access-is-denied/m-p/546126#M111634</link>
    <description>&lt;P&gt;Thank you.&amp;nbsp; I guess I did miss that important detail.&lt;BR /&gt;As a test, can you try installation and implementation as a Domain Admin account (just for confirmation)&lt;/P&gt;
&lt;P&gt;If this works fine, then you know that this is a permission issue on the AD side and not from the PANW UserID agent side.&lt;BR /&gt;&lt;BR /&gt;Usually, this becomes the root cause of errors.&lt;BR /&gt;&lt;BR /&gt;Please advise.&lt;/P&gt;</description>
    <pubDate>Thu, 15 Jun 2023 12:55:33 GMT</pubDate>
    <dc:creator>S.Cantwell</dc:creator>
    <dc:date>2023-06-15T12:55:33Z</dc:date>
    <item>
      <title>Windows User-ID Agent  Access is denied</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-access-is-denied/m-p/544064#M111364</link>
      <description>&lt;P&gt;I'm setting up User-ID.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;i have a windows server 2012r2 domain controller, and a windows server 2019 domain member for the agent software.&lt;/LI&gt;
&lt;LI&gt;I have configured a service account with user rights assignment to allow logon as a service on the agent host.&amp;nbsp; i have configured permissions to the install directory and to the registry key for the software.&lt;/LI&gt;
&lt;LI&gt;I have added the account to the Event Log Readers and Distributed COM Users groups.&lt;/LI&gt;
&lt;LI&gt;I have created a firewall rule on the DC to allow all connections from the agent host server.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;The debug logs indicate that OpenEventLog failed.&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 23:16:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-access-is-denied/m-p/544064#M111364</guid>
      <dc:creator>jonathanb</dc:creator>
      <dc:date>2023-05-30T23:16:28Z</dc:date>
    </item>
    <item>
      <title>Re: Windows User-ID Agent  Access is denied</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-access-is-denied/m-p/545650#M111572</link>
      <description>&lt;P&gt;Hello there&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This has been well documented since Aug 2019 (or 2020) when MS decided to release a patch that no longer allows the agentless UserID agent to function, and MS servers respond back with Access Denied.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000wkkfCAA&amp;amp;lang=en_US%E2%80%A9" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000wkkfCAA&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Please de provision the agentless version, and instead, utilize either than StandAlone UserID agent (can be downloaded from their support site) or consider toward cloud based authentication, using PANW CIE (Cloud Identity Engine)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-new-features/identity-features/cloud-identity-engine" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-new-features/identity-features/cloud-identity-engine&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2023 19:31:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-access-is-denied/m-p/545650#M111572</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2023-06-12T19:31:39Z</dc:date>
    </item>
    <item>
      <title>Re: Windows User-ID Agent  Access is denied</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-access-is-denied/m-p/545651#M111573</link>
      <description>&lt;P&gt;Thanks.&amp;nbsp; If it wasn't clear, the windows agent host is in use because i'm using the windows agent.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2023 20:15:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-access-is-denied/m-p/545651#M111573</guid>
      <dc:creator>jonathanb</dc:creator>
      <dc:date>2023-06-12T20:15:33Z</dc:date>
    </item>
    <item>
      <title>Re: Windows User-ID Agent  Access is denied</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-access-is-denied/m-p/546126#M111634</link>
      <description>&lt;P&gt;Thank you.&amp;nbsp; I guess I did miss that important detail.&lt;BR /&gt;As a test, can you try installation and implementation as a Domain Admin account (just for confirmation)&lt;/P&gt;
&lt;P&gt;If this works fine, then you know that this is a permission issue on the AD side and not from the PANW UserID agent side.&lt;BR /&gt;&lt;BR /&gt;Usually, this becomes the root cause of errors.&lt;BR /&gt;&lt;BR /&gt;Please advise.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2023 12:55:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-user-id-agent-access-is-denied/m-p/546126#M111634</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2023-06-15T12:55:33Z</dc:date>
    </item>
  </channel>
</rss>

