<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UserID Agent - Required User Rights in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-required-user-rights/m-p/38622#M28293</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;meanwhile (after mentioning the missing information to support), there is a document for this.&lt;/P&gt;&lt;P&gt;Unfortunately it's missing some information and (i.e. in regards to the registry) it's wrong. It also doesn't explain how to setup the firewall part of the User ID Setup, so I created my own documents.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached two PDFs for anyone with a similar Problem in the future.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 27 Jul 2012 17:29:39 GMT</pubDate>
    <dc:creator>u13550</dc:creator>
    <dc:date>2012-07-27T17:29:39Z</dc:date>
    <item>
      <title>UserID Agent - Required User Rights</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-required-user-rights/m-p/38620#M28291</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm in the process of implementing the UserID Agent into a Windows 2008 Domain&lt;/P&gt;&lt;P&gt;My goal is to have a single user in the AD for all features required by PaloAlto.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I created a "panagent" user and added it to the "EventLog Readers" group, so it has access to the event logs&lt;/P&gt;&lt;P&gt;I the configured the Agent to use this user in it's service settings to start the service, which automatically grants "logon as a service" rights to the panagent User, but the service does not start, or better: it starts and stops immediately.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to have the user as restricted as possible, so I do not want to add it to domain admins or local administrators group.&lt;/P&gt;&lt;P&gt;Does the UserID Service need anything special apart form "logon as a service"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Andre&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jul 2012 18:17:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-required-user-rights/m-p/38620#M28291</guid>
      <dc:creator>u13550</dc:creator>
      <dc:date>2012-07-24T18:17:53Z</dc:date>
    </item>
    <item>
      <title>Re: UserID Agent - Required User Rights</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-required-user-rights/m-p/38621#M28292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;unbelievable, but there is nothing to find in documentation, which describe how to setup a user-id-agent with limited access.&lt;/P&gt;&lt;P&gt;Is everybody out there running it with full access?&lt;/P&gt;&lt;P&gt;Andre, configure your user as you describe by yourself. The account need the grant "logon as a service" on the machine it runs on and the "EventLog Readers" grant on AD servers as described in official doc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Additionally&lt;/SPAN&gt;, on the machine the agent is running, you have to do the following steps (thanks to Sysinternals Process Monitor):&lt;/P&gt;&lt;P&gt;1.) Grant read-write access to the program directory of the user-id agent for the ua-user (e.g. on 32Bit OS: "C:\Program Files\Palo Alto Networks", on 64Bit OS: "C:\Program Files (x86)\Palo Alto Networks") .&lt;/P&gt;&lt;P&gt;2.) Grant read-write access to the "Palo Alto Networks" registry key (e.g. on 32Bit OS: "HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks", on 64Bit OS: "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Palo Alto Networks")&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's it, hope this helps you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Jul 2012 15:43:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-required-user-rights/m-p/38621#M28292</guid>
      <dc:creator>pplaw</dc:creator>
      <dc:date>2012-07-27T15:43:39Z</dc:date>
    </item>
    <item>
      <title>Re: UserID Agent - Required User Rights</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-required-user-rights/m-p/38622#M28293</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;meanwhile (after mentioning the missing information to support), there is a document for this.&lt;/P&gt;&lt;P&gt;Unfortunately it's missing some information and (i.e. in regards to the registry) it's wrong. It also doesn't explain how to setup the firewall part of the User ID Setup, so I created my own documents.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached two PDFs for anyone with a similar Problem in the future.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Jul 2012 17:29:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-required-user-rights/m-p/38622#M28293</guid>
      <dc:creator>u13550</dc:creator>
      <dc:date>2012-07-27T17:29:39Z</dc:date>
    </item>
  </channel>
</rss>

