<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic UserID - possible to identify AD computer name in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/userid-possible-to-identify-ad-computer-name/m-p/32374#M23728</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have firmware version 4.1.1 and use the appropriate User-ID program for this firmware. I undretand how it all works for Active Directory user accounts, but what I want to know is can it be used to scan AD containers that only contain computer names, which I can then use in my security policies?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to block certain apps for specific AD computers (not users), which are all members of an AD security group and apply a security policy based on the AD group.&amp;nbsp; The only other way I can think of is by setting up many address objects and throwing them all into an address group, but any users on DHCP may change IP address, rendering this solution useless.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this something for DEV?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 19 Jan 2012 04:43:14 GMT</pubDate>
    <dc:creator>ReadingEnt</dc:creator>
    <dc:date>2012-01-19T04:43:14Z</dc:date>
    <item>
      <title>UserID - possible to identify AD computer name</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-possible-to-identify-ad-computer-name/m-p/32374#M23728</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have firmware version 4.1.1 and use the appropriate User-ID program for this firmware. I undretand how it all works for Active Directory user accounts, but what I want to know is can it be used to scan AD containers that only contain computer names, which I can then use in my security policies?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to block certain apps for specific AD computers (not users), which are all members of an AD security group and apply a security policy based on the AD group.&amp;nbsp; The only other way I can think of is by setting up many address objects and throwing them all into an address group, but any users on DHCP may change IP address, rendering this solution useless.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this something for DEV?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jan 2012 04:43:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-possible-to-identify-ad-computer-name/m-p/32374#M23728</guid>
      <dc:creator>ReadingEnt</dc:creator>
      <dc:date>2012-01-19T04:43:14Z</dc:date>
    </item>
    <item>
      <title>Re: UserID - possible to identify AD computer name</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-possible-to-identify-ad-computer-name/m-p/32375#M23729</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'd say - look at Global Protect if you want a packaged product. If you have the skills/time you could use the API to push computer names and IP in to the PAN. Would require some development time on your end though.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jan 2012 08:26:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-possible-to-identify-ad-computer-name/m-p/32375#M23729</guid>
      <dc:creator>rapoint_person</dc:creator>
      <dc:date>2012-01-19T08:26:16Z</dc:date>
    </item>
  </channel>
</rss>

