<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is it possible to create AD group based authentication for PaloAlto administrators? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-create-ad-group-based-authentication-for/m-p/20316#M14801</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your question is about using a group instead of users for admin, answer is no .... not yet&lt;/P&gt;&lt;P&gt;Else for sure you can group all your pa'sadmin in AD group and use all user in this group for defining admin profile and role. &lt;/P&gt;&lt;P&gt;What you have to do is to follow this doc: &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-4740"&gt;https://live.paloaltonetworks.com/docs/DOC-4740&lt;/A&gt;,create your admin account in the palo then assign them to admin role.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 27 Aug 2013 12:02:48 GMT</pubDate>
    <dc:creator>VinceM</dc:creator>
    <dc:date>2013-08-27T12:02:48Z</dc:date>
    <item>
      <title>Is it possible to create AD group based authentication for PaloAlto administrators?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-create-ad-group-based-authentication-for/m-p/20315#M14800</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to create AD group based authentication for PaloAlto administrators?&lt;/P&gt;&lt;P&gt;If yes, kindly provide the steps for the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Gururaj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Aug 2013 11:15:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-create-ad-group-based-authentication-for/m-p/20315#M14800</guid>
      <dc:creator>Gururaj</dc:creator>
      <dc:date>2013-08-27T11:15:28Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to create AD group based authentication for PaloAlto administrators?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-create-ad-group-based-authentication-for/m-p/20316#M14801</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your question is about using a group instead of users for admin, answer is no .... not yet&lt;/P&gt;&lt;P&gt;Else for sure you can group all your pa'sadmin in AD group and use all user in this group for defining admin profile and role. &lt;/P&gt;&lt;P&gt;What you have to do is to follow this doc: &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-4740"&gt;https://live.paloaltonetworks.com/docs/DOC-4740&lt;/A&gt;,create your admin account in the palo then assign them to admin role.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Aug 2013 12:02:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-create-ad-group-based-authentication-for/m-p/20316#M14801</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2013-08-27T12:02:48Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to create AD group based authentication for PaloAlto administrators?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-create-ad-group-based-authentication-for/m-p/20317#M14802</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can use Radius VSA to accomplish group permission for admin.&amp;nbsp; Here's a doc on Radius VSA and configuration examples for Windows server: &lt;A href="https://live.paloaltonetworks.com/docs/DOC-1765"&gt; Radius Vendor Specific Attributes (VSA)   &lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Aug 2013 13:55:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-create-ad-group-based-authentication-for/m-p/20317#M14802</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2013-08-27T13:55:48Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to create AD group based authentication for PaloAlto administrators?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-create-ad-group-based-authentication-for/m-p/20318#M14803</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are planning to use a group name under Device ---&amp;gt; administrator then it wont work&lt;/P&gt;&lt;P&gt;You have to user individual user names with LDAP as authentication profile.&lt;/P&gt;&lt;P&gt;Step1:&lt;/P&gt;&lt;P&gt;create LDAP profile&lt;/P&gt;&lt;P&gt;Device --&amp;gt; Server Profiles ---&amp;gt; LDAP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7936_Capture.JPG.jpg" style="width: 620px; height: 315px;" /&gt;&lt;/P&gt;&lt;P&gt;Step2:&lt;/P&gt;&lt;P&gt;Create authentication profile under Device --&amp;gt; Authentication Profiles&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7940_Capture.JPG.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step3:&lt;/P&gt;&lt;P&gt;Now select under Device --&amp;gt; administrator&lt;/P&gt;&lt;P&gt;Create an Administrator user. Make sure the user name is same as on the DC other wise the user will not able able to login.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7941_Capture.JPG.jpg" /&gt;&lt;/P&gt;&lt;P&gt;Now commit the changes and the user will be able to login.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;However if this is not feasible for you and you do not want to configure all you users here . You can also use Radius and set it with Admin Roles.&lt;/P&gt;&lt;P&gt;Here is a doc that explains how to do that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-1765"&gt;https://live.paloaltonetworks.com/docs/DOC-1765&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Numan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Aug 2013 23:00:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-create-ad-group-based-authentication-for/m-p/20318#M14803</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2013-08-27T23:00:15Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to create AD group based authentication for PaloAlto administrators?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-create-ad-group-based-authentication-for/m-p/20319#M14804</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is another doc which explains on how to setup LDAP authentication&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-2910"&gt;https://live.paloaltonetworks.com/docs/DOC-2910&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Let us know if this helps.&lt;BR /&gt;Thanks&lt;/P&gt;&lt;P&gt;Numan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Aug 2013 23:01:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-create-ad-group-based-authentication-for/m-p/20319#M14804</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2013-08-27T23:01:28Z</dc:date>
    </item>
  </channel>
</rss>

