<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User ID Agent all DCs in connecting (Access is denied) status after migrating from Win 2012 to Win 2019 Server in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-all-dcs-in-connecting-access-is-denied-status/m-p/572487#M115196</link>
    <description>&lt;P&gt;Hi Tom,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We started with installing 10.2, than moved to version 8 to check if the issue is because of version, than again went for version 11. Nothing resolved the problem..&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jan 2024 05:42:50 GMT</pubDate>
    <dc:creator>JamshedDayar</dc:creator>
    <dc:date>2024-01-10T05:42:50Z</dc:date>
    <item>
      <title>User ID Agent all DCs in connecting (Access is denied) status after migrating from Win 2012 to Win 2019 Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-all-dcs-in-connecting-access-is-denied-status/m-p/572035#M115130</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have installed 10.2 version of UIA in new win 2019 server as our 2012 server would be shutdown soon. The problem is after configuring all the required permissions the agent status overall is connected, but on all our ADs listed in UIA, the status is stuck at connecting and after sometimes we get Access is Denied status as well. The service account used for new UIA is the same as old setup which is working fine on win 2012.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is a PA in between which has policy to allow such traffic. Surprisingly though the agent is fetching user info from the ADs but we are reluctant to integrate this new setup with PA due to the problem stated above.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have already tried all the KBs available for such logs/msg like patch upgrade or running it as admin etc etc&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone can shed a light on how further we can tshoot this problem.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The specific error on the log file is&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Error 115 : Cannot open security log for XYZ. Access is denied.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JamshedDayar_1-1704692360221.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56300i81F928558164840F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="JamshedDayar_1-1704692360221.png" alt="JamshedDayar_1-1704692360221.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="User-ID" id="User-ID"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 05:42:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-all-dcs-in-connecting-access-is-denied-status/m-p/572035#M115130</guid>
      <dc:creator>JamshedDayar</dc:creator>
      <dc:date>2024-01-08T05:42:13Z</dc:date>
    </item>
    <item>
      <title>Re: User ID Agent all DCs in connecting (Access is denied) status after migrating from Win 2012 to Win 2019 Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-all-dcs-in-connecting-access-is-denied-status/m-p/572182#M115144</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/334632"&gt;@JamshedDayar&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I'd verify with whoever is running those servers that you don't have IP restrictions that weren't updated for the 2019 host on the DCs.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 21:45:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-all-dcs-in-connecting-access-is-denied-status/m-p/572182#M115144</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-01-08T21:45:47Z</dc:date>
    </item>
    <item>
      <title>Re: User ID Agent all DCs in connecting (Access is denied) status after migrating from Win 2012 to Win 2019 Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-all-dcs-in-connecting-access-is-denied-status/m-p/572255#M115154</link>
      <description>&lt;P&gt;Hi Bpry,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Incase of any restrictions, why UIA is still able to fetch all the updated information regarding user to ip mapping. This is the point that is confusing us. Anyway can you elaborate where I can ask the server team to check for these restrictions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2024 05:43:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-all-dcs-in-connecting-access-is-denied-status/m-p/572255#M115154</guid>
      <dc:creator>JamshedDayar</dc:creator>
      <dc:date>2024-01-09T05:43:34Z</dc:date>
    </item>
    <item>
      <title>Re: User ID Agent all DCs in connecting (Access is denied) status after migrating from Win 2012 to Win 2019 Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-all-dcs-in-connecting-access-is-denied-status/m-p/572348#M115170</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/334632"&gt;@JamshedDayar&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Hi all&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have installed 10.2 version of UIA in new win 2019 server as our 2012 server would be shutdown soon. The problem is after configuring all the required permissions the agent status overall is connected, but on all our ADs listed in UIA, the status is stuck at connecting and after sometimes we get Access is Denied status as well. The service account used for new UIA is the same as old setup which is working fine on win 2012.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is a PA in between which has policy to allow such traffic. Surprisingly though the agent is fetching user info from the ADs but we are reluctant to integrate this new setup with PA due to the problem stated above.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have already tried all the KBs available for such logs/msg like patch upgrade or running it as admin etc etc&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone can shed a light on how further we can tshoot this problem.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The specific error on the log file is&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Error 115 : Cannot open security log for XYZ. Access is denied.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JamshedDayar_1-1704692360221.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56300i81F928558164840F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="JamshedDayar_1-1704692360221.png" alt="JamshedDayar_1-1704692360221.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-product-mention" href="https://live.paloaltonetworks.com/t5/c-twzvq79624/User-ID/pd-p/User-ID" data-product="30-1" target="_blank"&gt;User-ID&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Your comments are a little confusing.&amp;nbsp; You have UIA installed on 2012 member servers previously.&amp;nbsp; You have a new 2019 member server that has UIA installed on it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's the UIA on the 2019 member server that has lets say 10 domain controllers it's monitoring.&amp;nbsp; Of those 10 ALL of them sometimes say connected and other times ALL of them say access denied?&amp;nbsp; Or is there a subset of the 10 that will say access denied?&lt;BR /&gt;&lt;BR /&gt;I would agree with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; -- this is usually because of the service account that's running the UIA doesn't have the needed permissions to read the AD event logs on the DC, or maybe the service account isn't running the UIA software like it needs to be.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would follow the UIA deployment process step by step again.&amp;nbsp; I bet you resolve your issue.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2024 14:43:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-all-dcs-in-connecting-access-is-denied-status/m-p/572348#M115170</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2024-01-09T14:43:49Z</dc:date>
    </item>
    <item>
      <title>Re: User ID Agent all DCs in connecting (Access is denied) status after migrating from Win 2012 to Win 2019 Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-all-dcs-in-connecting-access-is-denied-status/m-p/572367#M115173</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/334632"&gt;@JamshedDayar&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't know of any Windows issues with the UIA on W2019.&amp;nbsp; I agree with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt; that a reinstall of the UIA is your best bet to fix it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2024 17:04:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-all-dcs-in-connecting-access-is-denied-status/m-p/572367#M115173</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-01-09T17:04:51Z</dc:date>
    </item>
    <item>
      <title>Re: User ID Agent all DCs in connecting (Access is denied) status after migrating from Win 2012 to Win 2019 Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-all-dcs-in-connecting-access-is-denied-status/m-p/572486#M115195</link>
      <description>&lt;P&gt;Hi Brandon,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me clarify.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Currently we have UIA version 8 on our 2012 server which is working fine since ages, status on that for all DCs is connected. no issues&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now we are deploying a win 2019 server with newer version of UIA 10.2 but using the same service account thats being already used for 2012 deployment ( so permissions are not an issue imo as that one is working fine )&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now on the 2019 server, the UIA agent is running and connected, but on 3 DCs ( screenshot attached in 1st post ) , the status is stuck at connecting and after sometime it is Connecting ( Access is denied ).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have followed the KB and all local permissions are also granted to service account on new server as well.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 05:41:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-all-dcs-in-connecting-access-is-denied-status/m-p/572486#M115195</guid>
      <dc:creator>JamshedDayar</dc:creator>
      <dc:date>2024-01-10T05:41:02Z</dc:date>
    </item>
    <item>
      <title>Re: User ID Agent all DCs in connecting (Access is denied) status after migrating from Win 2012 to Win 2019 Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-all-dcs-in-connecting-access-is-denied-status/m-p/572487#M115196</link>
      <description>&lt;P&gt;Hi Tom,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We started with installing 10.2, than moved to version 8 to check if the issue is because of version, than again went for version 11. Nothing resolved the problem..&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 05:42:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-all-dcs-in-connecting-access-is-denied-status/m-p/572487#M115196</guid>
      <dc:creator>JamshedDayar</dc:creator>
      <dc:date>2024-01-10T05:42:50Z</dc:date>
    </item>
    <item>
      <title>Re: User ID Agent all DCs in connecting (Access is denied) status after migrating from Win 2012 to Win 2019 Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-all-dcs-in-connecting-access-is-denied-status/m-p/572557#M115208</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/334632"&gt;@JamshedDayar&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Hi Brandon,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me clarify.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Currently we have UIA version 8 on our 2012 server which is working fine since ages, status on that for all DCs is connected. no issues&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now we are deploying a win 2019 server with newer version of UIA 10.2 but using the same service account thats being already used for 2012 deployment ( so permissions are not an issue imo as that one is working fine )&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now on the 2019 server, the UIA agent is running and connected, but on 3 DCs ( screenshot attached in 1st post ) , the status is stuck at connecting and after sometime it is Connecting ( Access is denied ).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have followed the KB and all local permissions are also granted to service account on new server as well.&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Hrmm...If you're saying you've followed all the steps and the service account is running the software, it's possible there could be some weird issue going on, but that likely will need a support case to truly discover.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That said my enviornment is a mix of 3200s, 3400s, and 5250s running 10.1.X and 10.2.X PAN-OS.&amp;nbsp; I've got 4 UIAs targeting 100+ DCs and 1 credential agent.&amp;nbsp; We're running UIA software version 10.1.0-21 and we don't have any issues monitoring 2019 DCs.&amp;nbsp; Maybe try downgrading the UIAs to 10.1?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2 class="bookdetail-page-title"&gt;Where Can I Install the User-ID Agent?&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/compatibility-matrix/user-id-agent/where-can-i-install-the-user-id-agent#id8f750af3-799f-4546-8b9e-a44a23b5b5c0" target="_blank"&gt;https://docs.paloaltonetworks.com/compatibility-matrix/user-id-agent/where-can-i-install-the-user-id-agent#id8f750af3-799f-4546-8b9e-a44a23b5b5c0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2 class="bookdetail-page-title"&gt;Which Servers Can the User-ID Agent Monitor?&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/compatibility-matrix/user-id-agent/which-servers-can-the-user-id-agent-monitor#id48730da4-e269-4a3b-aeae-ea577c5c04ea" target="_blank"&gt;https://docs.paloaltonetworks.com/compatibility-matrix/user-id-agent/which-servers-can-the-user-id-agent-monitor#id48730da4-e269-4a3b-aeae-ea577c5c04ea&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 14:00:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-all-dcs-in-connecting-access-is-denied-status/m-p/572557#M115208</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2024-01-10T14:00:34Z</dc:date>
    </item>
  </channel>
</rss>

