<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID for Exchange Permission Issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-exchange-permission-issue/m-p/27913#M20358</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/message/15865#15865"&gt;https://live.paloaltonetworks.com/message/15865#15865&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Be aware that only owa connection can be used, due to Exchange limitation there is no POP3 or IMAP user connection information.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 26 May 2013 10:08:29 GMT</pubDate>
    <dc:creator>NGS_SOC</dc:creator>
    <dc:date>2013-05-26T10:08:29Z</dc:date>
    <item>
      <title>User-ID for Exchange Permission Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-exchange-permission-issue/m-p/27911#M20356</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm running an agent-based User-ID setup against three AD DCs and two Exchange CAS servers.&amp;nbsp; Unfortunately, despite having the Event Log Reader permission, I cannot seem to get data from the Exchange servers.&amp;nbsp; I am successfully getting data from the DCs, but the Exchange servers always show either Connecting or Connecting (A required privilege is not held by the agent.).&amp;nbsp; Any ideas on whether or not Exchange requires additional permissions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 May 2013 20:44:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-exchange-permission-issue/m-p/27911#M20356</guid>
      <dc:creator>SabreAce33</dc:creator>
      <dc:date>2013-05-21T20:44:08Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID for Exchange Permission Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-exchange-permission-issue/m-p/27912#M20357</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any takers?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 May 2013 16:43:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-exchange-permission-issue/m-p/27912#M20357</guid>
      <dc:creator>SabreAce33</dc:creator>
      <dc:date>2013-05-24T16:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID for Exchange Permission Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-exchange-permission-issue/m-p/27913#M20358</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/message/15865#15865"&gt;https://live.paloaltonetworks.com/message/15865#15865&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Be aware that only owa connection can be used, due to Exchange limitation there is no POP3 or IMAP user connection information.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 May 2013 10:08:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-exchange-permission-issue/m-p/27913#M20358</guid>
      <dc:creator>NGS_SOC</dc:creator>
      <dc:date>2013-05-26T10:08:29Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID for Exchange Permission Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-exchange-permission-issue/m-p/27914#M20359</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am also having this issue.&amp;nbsp; I have a case open with support but there is no resolution yet.&amp;nbsp; I am using User-ID agent 5.0.5 and can connect to domain controllers just fine.&amp;nbsp; The Exchange server connections show "&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;Connecting (A required privilege is not held by the agent.)&lt;/SPAN&gt;"&amp;nbsp; I am attempting to connect to Exchange 2010.]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jun 2013 18:02:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-exchange-permission-issue/m-p/27914#M20359</guid>
      <dc:creator>melonheadr</dc:creator>
      <dc:date>2013-06-26T18:02:37Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID for Exchange Permission Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-exchange-permission-issue/m-p/27915#M20360</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wish I had something to add.&amp;nbsp; That's the exact problem I'm having, though I'm using 5.0.4.&amp;nbsp; Please let me know what you find out!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jun 2013 18:08:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-exchange-permission-issue/m-p/27915#M20360</guid>
      <dc:creator>SabreAce33</dc:creator>
      <dc:date>2013-06-26T18:08:49Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID for Exchange Permission Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-exchange-permission-issue/m-p/27916#M20361</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The closest thing I can find is this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="http://www.experts-exchange.com/Software/Server_Software/File_Servers/Active_Directory/Q_27949015.html" title="http://www.experts-exchange.com/Software/Server_Software/File_Servers/Active_Directory/Q_27949015.html"&gt;http://www.experts-exchange.com/Software/Server_Software/File_Servers/Active_Directory/Q_27949015.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scroll all the way to the bottom:&lt;/P&gt;&lt;P&gt;"&lt;SPAN style="color: #222222; font-family: 'Droid Serif', Georgia, 'Times New Roman', serif; background-color: #ffffff;"&gt;Ending up not being able to use the event log viewers group and had to add the accout to administrators group.&lt;/SPAN&gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps Exchange 2010 doesn't use the "Event Log Readers" group...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jun 2013 18:14:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-exchange-permission-issue/m-p/27916#M20361</guid>
      <dc:creator>melonheadr</dc:creator>
      <dc:date>2013-06-26T18:14:07Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID for Exchange Permission Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-exchange-permission-issue/m-p/27917#M20362</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Huh..my AD/Exchange guy swears up and down this shouldn't be required and that Event Log Readers should be fine...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jun 2013 18:19:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-exchange-permission-issue/m-p/27917#M20362</guid>
      <dc:creator>SabreAce33</dc:creator>
      <dc:date>2013-06-26T18:19:47Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID for Exchange Permission Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-exchange-permission-issue/m-p/27918#M20363</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you had a chance to look at this doc &lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-3664"&gt;https://live.paloaltonetworks.com/docs/DOC-3664&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jun 2013 18:22:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-exchange-permission-issue/m-p/27918#M20363</guid>
      <dc:creator>sraghunandan</dc:creator>
      <dc:date>2013-06-26T18:22:01Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID for Exchange Permission Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-exchange-permission-issue/m-p/27919#M20364</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree.&amp;nbsp; PAN support wanted me to add the service-account to the local admin group on the Exchange servers.&amp;nbsp; I refused and asked him to provide me documentation that this is required.&amp;nbsp; Least privilege model... right?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jun 2013 18:22:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-exchange-permission-issue/m-p/27919#M20364</guid>
      <dc:creator>melonheadr</dc:creator>
      <dc:date>2013-06-26T18:22:24Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID for Exchange Permission Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-exchange-permission-issue/m-p/27920#M20365</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have.&amp;nbsp; The only difference between that doc and our deployment is Server Operators, which won't fly with our AD guys.&amp;nbsp; The Exchange monitoring, which is not outlined in that document at all, works fine without Server Operators.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jun 2013 18:25:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-exchange-permission-issue/m-p/27920#M20365</guid>
      <dc:creator>SabreAce33</dc:creator>
      <dc:date>2013-06-26T18:25:53Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID for Exchange Permission Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-exchange-permission-issue/m-p/27921#M20366</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Totally concur.&amp;nbsp; That's not a valid answer for me.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jun 2013 18:26:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-exchange-permission-issue/m-p/27921#M20366</guid>
      <dc:creator>SabreAce33</dc:creator>
      <dc:date>2013-06-26T18:26:25Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID for Exchange Permission Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-exchange-permission-issue/m-p/27922#M20367</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Definitely followed the document.&amp;nbsp; My service-account is part of "event log readers" and "server operators." As said before, the User-ID agent works fine with domain controllers.&amp;nbsp; Something is odd with the connection to Exchange servers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jun 2013 18:28:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-exchange-permission-issue/m-p/27922#M20367</guid>
      <dc:creator>melonheadr</dc:creator>
      <dc:date>2013-06-26T18:28:34Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID for Exchange Permission Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-exchange-permission-issue/m-p/27923#M20368</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I sat down and worked with my Exchange admin.&amp;nbsp; He added my service account to the Exchange server's local "event log readers" group.&amp;nbsp; Bam, user-ID agent is now connected.&amp;nbsp; I haven't dug through the data yet but at least it resolves the error I was receiving.&amp;nbsp; Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Charlie&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Jul 2013 19:39:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-exchange-permission-issue/m-p/27923#M20368</guid>
      <dc:creator>melonheadr</dc:creator>
      <dc:date>2013-07-10T19:39:24Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID for Exchange Permission Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-exchange-permission-issue/m-p/27924#M20369</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Charlie,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll talk to my AD/Exchange guy next week and see if that does the trick.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jul 2013 21:49:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-exchange-permission-issue/m-p/27924#M20369</guid>
      <dc:creator>SabreAce33</dc:creator>
      <dc:date>2013-07-19T21:49:35Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID for Exchange Permission Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-exchange-permission-issue/m-p/27925#M20370</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The documentation for the built-in PAN-OS user-ID agent appears to be incomplete.&amp;nbsp; Here is what I had to do in order to get it to work for our Exchange 2010 CAS servers:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Grant the user-ID agent service account "Enable Account" and "Remote Access" permission to the CIMV2 WMI namespace on the Exchange CAS servers.&lt;/LI&gt;&lt;LI&gt;Add the service account to the local "Event Log Readers" and "Distributed COM Users" groups on the Exchange CAS servers.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did &lt;EM&gt;not&lt;/EM&gt; have to add the service account to the domain "Server Operators" or "Domain Admins" groups or local "Power Users" or "Administrators" groups as I have seen suggested in some places.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The second step appears to be the sticky part as the documentation just says to add the user to the built-in groups.&amp;nbsp; Many probably (and I did) assume that means the groups that are built into the Active Directory domain.&amp;nbsp; While membership in those Active Directory groups is in fact required in order to have the built-in user-ID agent successfully monitor &lt;EM&gt;Active Directory domain controllers&lt;/EM&gt;, membership in those groups does &lt;EM&gt;not&lt;/EM&gt; grant that same membership in the local group equivalents on other domain member servers, including Exchange servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, if you want the built-in user-ID agent to monitor both domain controllers and Exchange CAS servers, it has to be a member of both the domain "Event Log Readers" and "Distributed COM Users" groups and the same local group equivalents on the Exchange CAS servers themselves.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps others.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jun 2015 15:06:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-exchange-permission-issue/m-p/27925#M20370</guid>
      <dc:creator>scottsander</dc:creator>
      <dc:date>2015-06-03T15:06:52Z</dc:date>
    </item>
  </channel>
</rss>

