<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disable Admin Accounts in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/disable-admin-accounts/m-p/18180#M13254</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There's also a third option if you don't want to create an account in AD for your contractor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create a local user on the FW (see screenshot) and add that local user to the Administrators list with the role you want them to have. When the contractor's engagement is complete, just uncheck the Enable box under the local user account (see screenshot).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Local-User-Admin.png" class="jive-image image-2" src="https://live.paloaltonetworks.com/legacyfs/online/13827_Local-User-Admin.png" style="height: 231px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Local-User-Account.png" class="jive-image image-3" src="https://live.paloaltonetworks.com/legacyfs/online/13828_Local-User-Account.png" style="height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 09 Jun 2014 12:36:41 GMT</pubDate>
    <dc:creator>jwolach</dc:creator>
    <dc:date>2014-06-09T12:36:41Z</dc:date>
    <item>
      <title>Disable Admin Accounts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-admin-accounts/m-p/18177#M13251</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there a way to disable FW admin accounts?&amp;nbsp; Let's say we have a situation where we have consultants who come on site and we only want to enable their access for certain periods of time and then disable them after the engagement is complete.&amp;nbsp; Is this possible?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried creating a custom role with no access, but it wouldn't let me commit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PANOS 5.0.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jun 2014 18:03:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-admin-accounts/m-p/18177#M13251</guid>
      <dc:creator>mark_dy</dc:creator>
      <dc:date>2014-06-06T18:03:00Z</dc:date>
    </item>
    <item>
      <title>Re: Disable Admin Accounts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-admin-accounts/m-p/18178#M13252</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A couple of options as its not possible to disable an account on the PA itself&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Change the password on the account after the consultants leave&lt;/LI&gt;&lt;LI&gt;Configure either Kerberos or LDAP authentication for the account and disable the account there&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I typically recommend number two since it does not require a commit on the firewall to change the password.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jun 2014 18:26:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-admin-accounts/m-p/18178#M13252</guid>
      <dc:creator>jcostello</dc:creator>
      <dc:date>2014-06-06T18:26:19Z</dc:date>
    </item>
    <item>
      <title>Re: Disable Admin Accounts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-admin-accounts/m-p/18179#M13253</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Meant to include the link to this article in my prior response&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-2745"&gt;Using LDAP to Authenticate to the WebUI&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RADIUS can also be used for WebUI authentication&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-6762"&gt;Configuring Read-only Admin Access with RADIUS Running on Win2008 and Cisco ACS 5.2&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1701"&gt;Configuring Administrator Authentication with Windows 2008 RADIUS Server (NPS/IAS)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3916"&gt;How to define Access Domains for Administrators&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jun 2014 19:39:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-admin-accounts/m-p/18179#M13253</guid>
      <dc:creator>jcostello</dc:creator>
      <dc:date>2014-06-06T19:39:58Z</dc:date>
    </item>
    <item>
      <title>Re: Disable Admin Accounts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-admin-accounts/m-p/18180#M13254</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There's also a third option if you don't want to create an account in AD for your contractor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create a local user on the FW (see screenshot) and add that local user to the Administrators list with the role you want them to have. When the contractor's engagement is complete, just uncheck the Enable box under the local user account (see screenshot).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Local-User-Admin.png" class="jive-image image-2" src="https://live.paloaltonetworks.com/legacyfs/online/13827_Local-User-Admin.png" style="height: 231px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Local-User-Account.png" class="jive-image image-3" src="https://live.paloaltonetworks.com/legacyfs/online/13828_Local-User-Account.png" style="height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jun 2014 12:36:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-admin-accounts/m-p/18180#M13254</guid>
      <dc:creator>jwolach</dc:creator>
      <dc:date>2014-06-09T12:36:41Z</dc:date>
    </item>
    <item>
      <title>Re: Disable Admin Accounts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-admin-accounts/m-p/18181#M13255</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That still requires a commit on the Palo Alto to disable the account&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jun 2014 13:29:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-admin-accounts/m-p/18181#M13255</guid>
      <dc:creator>jcostello</dc:creator>
      <dc:date>2014-06-09T13:29:13Z</dc:date>
    </item>
  </channel>
</rss>

