<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Config admin using radius group. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/config-admin-using-radius-group/m-p/1250335#M126155</link>
    <description>&lt;P&gt;I have VM-100 running panos-11.1.13. currently i have local admins for msp -superusers and 1 customer user with a customer -admin-role profile. customer wants to have mutiple admins controlled by their radius. so radius profile and auth profile is configured. how can i attach admin user group(listed under auth profile) to admin role profile.&lt;/P&gt;
&lt;P&gt;I see long way of getting list of users ,configure them attaching radius auth profile and admin role profile. or ldap would be better as i can extract group mapping in user identification.&lt;/P&gt;</description>
    <pubDate>Tue, 17 Mar 2026 05:01:46 GMT</pubDate>
    <dc:creator>inderjit21</dc:creator>
    <dc:date>2026-03-17T05:01:46Z</dc:date>
    <item>
      <title>Config admin using radius group.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-admin-using-radius-group/m-p/1250335#M126155</link>
      <description>&lt;P&gt;I have VM-100 running panos-11.1.13. currently i have local admins for msp -superusers and 1 customer user with a customer -admin-role profile. customer wants to have mutiple admins controlled by their radius. so radius profile and auth profile is configured. how can i attach admin user group(listed under auth profile) to admin role profile.&lt;/P&gt;
&lt;P&gt;I see long way of getting list of users ,configure them attaching radius auth profile and admin role profile. or ldap would be better as i can extract group mapping in user identification.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2026 05:01:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-admin-using-radius-group/m-p/1250335#M126155</guid>
      <dc:creator>inderjit21</dc:creator>
      <dc:date>2026-03-17T05:01:46Z</dc:date>
    </item>
    <item>
      <title>Re: Config admin using radius group.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-admin-using-radius-group/m-p/1250373#M126158</link>
      <description>&lt;P&gt;You can't add groups in your authentication profile&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For radius auth you can either create local accounts and set an authentication profile, or you can change the device level authentication settings to accept radius credentials. that way the radius server decides which accounts to accept and which attributes to return to the firewall (superuser, device admin,...)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2026-03-17_13-10-06.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70951i9502AE85B07D7750/image-size/large?v=v2&amp;amp;px=999" role="button" title="2026-03-17_13-10-06.png" alt="2026-03-17_13-10-06.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2026 12:13:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-admin-using-radius-group/m-p/1250373#M126158</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2026-03-17T12:13:50Z</dc:date>
    </item>
    <item>
      <title>Re: Config admin using radius group.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-admin-using-radius-group/m-p/1250604#M126169</link>
      <description>&lt;P&gt;thanks for the info. Currently I havent setup auth profile under auth setting so radius users were failing -complaining cant find radius profile. i created a radius user under administrator account and this radius user can access firewall. I dont want to create users under administrator so I will go ahead with configuring admin profile under auth setting. But i&amp;nbsp; have msp administrators on the firewall&amp;nbsp; who r superusers. My only concern is setting auth profile will not cut off these superuser from logging to fw?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2026 03:47:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-admin-using-radius-group/m-p/1250604#M126169</guid>
      <dc:creator>inderjit21</dc:creator>
      <dc:date>2026-03-20T03:47:06Z</dc:date>
    </item>
    <item>
      <title>Re: Config admin using radius group.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-admin-using-radius-group/m-p/1250691#M126179</link>
      <description>&lt;P&gt;local accounts will remain active (and preferred) while a system authentication profile is active, so make sure there's no overlap&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2026 09:37:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-admin-using-radius-group/m-p/1250691#M126179</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2026-03-23T09:37:27Z</dc:date>
    </item>
  </channel>
</rss>

