<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User loses privileges...UserID in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49932#M36744</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps"&gt;I dont know why it should&lt;/SPAN&gt;&lt;SPAN class="hps"&gt; affect&lt;/SPAN&gt; me in my local machine that &lt;SPAN class="hps"&gt;I&lt;/SPAN&gt; connect to other pc with other user by RDP and when i close this session i dont recuperate my privileges&lt;SPAN class="hps"&gt;&lt;/SPAN&gt;. In the moment that i connect to another machine via RDP with any user i get the privileges of this user in my local machine....... this is a weird behaviour....&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 10 Oct 2013 14:45:48 GMT</pubDate>
    <dc:creator>soporteseguridad</dc:creator>
    <dc:date>2013-10-10T14:45:48Z</dc:date>
    <item>
      <title>User loses privileges...UserID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49921#M36733</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps"&gt;In our company&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;we have two&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;internet&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;browsing profiles&lt;/SPAN&gt;.&lt;BR /&gt;&lt;SPAN class="hps"&gt;Users who&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;belong to the&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;AD&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;Domain&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;users&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;have limited access to&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;internet&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;and&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;users&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;AD&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;group&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;belongs to&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;UsuariosInternet&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;can access&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;anywhere.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps"&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class="hps"&gt;My&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;AD&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;user is&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;canopr&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;&lt;/SPAN&gt;&lt;SPAN class="hps"&gt;and&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;I have&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;internet access&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;from my&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;PC&lt;/SPAN&gt; &lt;SPAN class="atn hps"&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;10.5.1.149&lt;/SPAN&gt;), &lt;SPAN class="hps"&gt;when I log&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;on&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;to a server by&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;remote desktop&lt;/SPAN&gt; &lt;SPAN class="atn hps"&gt;(&lt;/SPAN&gt;mstsc) &lt;SPAN class="hps"&gt;and I identify with&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;the user&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;oalgt&lt;/SPAN&gt;&lt;SPAN class="hps"&gt;\&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;explotacio&lt;/SPAN&gt;, &lt;SPAN class="hps"&gt;stopped&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;internet&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;access&lt;/SPAN&gt;. &lt;SPAN class="hps"&gt;The&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;userID&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;the user&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;agent&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;learns&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;that identified&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;on the IP&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;10.5.1.149&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;is&lt;/SPAN&gt; explotacio. &lt;SPAN class="hps"&gt;This performance&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;understand that&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;is wrong.&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;Is there any&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;way around it&lt;/SPAN&gt;&lt;SPAN&gt;?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN&gt;Thanks&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2013 08:23:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49921#M36733</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2013-10-09T08:23:17Z</dc:date>
    </item>
    <item>
      <title>Re: User loses privileges...UserID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49922#M36734</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If that's a terminal server where multiple users are active simultaneously, do you have the Terminal Services Agent installed and working ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2013 09:44:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49922#M36734</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2013-10-09T09:44:42Z</dc:date>
    </item>
    <item>
      <title>Re: User loses privileges...UserID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49923#M36735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No. Its just a server where i can access via RDP to manage several apps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2013 09:46:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49923#M36735</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2013-10-09T09:46:03Z</dc:date>
    </item>
    <item>
      <title>Re: User loses privileges...UserID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49924#M36736</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does UserID map the user who is connecting to RDP to an ip address ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;UserID can have the same user mapped to several ip's, but I'm not sure it can have several users mapped to one ip (except Terminal services agent). My guess is the RDP log on is captured as a logon event and the user is replaced in the ip mapping. We see this behaviour when we do administrative tasks (using a domain admin account) within a restricted user account. But that is expected behaviour for us...&lt;/P&gt;&lt;P&gt;In fact, I can reproduce the problem you're describing when connecting to a server using rdp. But shortly after, the normal user is mapped back to the client ip (we're using event log monitoring, session monitoring and wmi client probing; all with short intervals).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2013 10:03:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49924#M36736</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2013-10-09T10:03:39Z</dc:date>
    </item>
    <item>
      <title>Re: User loses privileges...UserID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49925#M36737</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, UserID maps the user who connects to the server via RDP. There is any way to keep the "privileges" although im working in other server via RDP?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2013 10:17:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49925#M36737</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2013-10-09T10:17:05Z</dc:date>
    </item>
    <item>
      <title>Re: User loses privileges...UserID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49926#M36738</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What UserID mechanisms do you use ? At what intervals ?&lt;/P&gt;&lt;P&gt;Eventually, your normal user should automatically be picked up again. But that depends on the mechanisms and interval. If you want very tight correlation between actual users and ip's, you'll have to rethink your UserID setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Take a look at &lt;A href="https://live.paloaltonetworks.com/docs/DOC-5939"&gt;Architecting User Identification Deployments&lt;/A&gt; . This and the admin guide helped me a lot in getting UserID right and efficient.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2013 10:24:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49926#M36738</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2013-10-09T10:24:38Z</dc:date>
    </item>
    <item>
      <title>Re: User loses privileges...UserID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49927#M36739</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have read the manual it seems correctly configured. This problem also happens with the user has two diferent mail inbox. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2013 15:30:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49927#M36739</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2013-10-09T15:30:43Z</dc:date>
    </item>
    <item>
      <title>Re: User loses privileges...UserID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49928#M36740</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps"&gt;What&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;happens to me&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;is that when I&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;connect via&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;terminal services&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;to a server,&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;my&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;local IP address&lt;/SPAN&gt; is &lt;SPAN class="hps"&gt;associated with&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;the&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;user in which&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;I connect.&lt;/SPAN&gt;&lt;SPAN class="hps"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Oct 2013 15:33:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49928#M36740</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2013-10-09T15:33:34Z</dc:date>
    </item>
    <item>
      <title>Re: User loses privileges...UserID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49929#M36741</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Simply initiating a RDP session, logs some kind of logon event (checking against AD whether or not that user is allowed to make RDP connections). It doesn't even yet relate to the server you're trying to connect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can actually reproduce this with a similar logon event: make a connection to an administrative share (\\somepc\c$), Windows will ask for credentials. Say you log on with a domain admin account. That domain admin account will be mapped to your ip address. Until timeout OR until your normal user does some kind of logon event (accessing your home folder can be enough) OR until the WMI probe determines your user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is all by design.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Eventually, is your user mapped back to your ip or not ? If so, how long does it take ?&lt;/P&gt;&lt;P&gt;You can monitor it in the CLI using the command "show user ip-user-mapping ip [your ip]"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Oct 2013 06:31:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49929#M36741</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2013-10-10T06:31:23Z</dc:date>
    </item>
    <item>
      <title>Re: User loses privileges...UserID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49930#M36742</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK ill try to explain better.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have my user oalgt/bruguepr&amp;nbsp; in my local pc. I open a RDP in order to manage a server, i log in this server as oalgt/explotacion. When i log in this server via RDP my local pc (user: oalgt/bruguepr) get the same privilege like explotacio.&lt;/P&gt;&lt;P&gt;And if i check the UserID agent i can see that my ip has the user explotacio. If i close the rdp ill continue having the explotacio privileges......what is the correct behaviour for this???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This also happens with user who has 2 mail inbox, where they access with different users.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Oct 2013 13:23:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49930#M36742</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2013-10-10T13:23:31Z</dc:date>
    </item>
    <item>
      <title>Re: User loses privileges...UserID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49931#M36743</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The problem you're having (user explotacion getting mapped to your local ip address) is perfectly clear. And like I said before: This is excpected behaviour because a logon event is logged. And no, we are not talking about the fact that user explotacio is logging on to the server, we are talking about "a" Windows logon event.&lt;/P&gt;&lt;P&gt;Check the security log in event viewer: you'll find thousands of logon events, that have nothing to do with a user logging on (entering username/password) to a computer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The security log on a DC is the source PaloAlto uses to collect these events, since they contain the user and an ip....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After having logged on to the server, almost any action you do locally (like browsing in Windows Explorer, opening an application) will trigger a logon event that should eventually be picked up by UserID. On the conditions that you are in fact in a domein environment (the logon event is checked by the DC) and UserID interval is short enough.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Oct 2013 13:46:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49931#M36743</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2013-10-10T13:46:34Z</dc:date>
    </item>
    <item>
      <title>Re: User loses privileges...UserID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49932#M36744</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps"&gt;I dont know why it should&lt;/SPAN&gt;&lt;SPAN class="hps"&gt; affect&lt;/SPAN&gt; me in my local machine that &lt;SPAN class="hps"&gt;I&lt;/SPAN&gt; connect to other pc with other user by RDP and when i close this session i dont recuperate my privileges&lt;SPAN class="hps"&gt;&lt;/SPAN&gt;. In the moment that i connect to another machine via RDP with any user i get the privileges of this user in my local machine....... this is a weird behaviour....&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Oct 2013 14:45:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49932#M36744</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2013-10-10T14:45:48Z</dc:date>
    </item>
    <item>
      <title>Re: User loses privileges...UserID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49933#M36745</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please understand that this actually has nothing to do with the RDP session.&lt;/P&gt;&lt;P&gt;This is standard Windows behaviour in a Windows domain: Your DC is the only "authority" that determines whether or not you have access to a resource. This is the logon even I'm talking about.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nothing you do in PaloAlto config wil change that behaviour. All PA does is read that info.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Oct 2013 14:54:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49933#M36745</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2013-10-10T14:54:49Z</dc:date>
    </item>
    <item>
      <title>Re: User loses privileges...UserID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49934#M36746</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This behavior is expected, UserID does ip-user-mapping based off of the Windows Security logs and when a user RDP's to a machine, Windows logs the security event based on the IP of the PC that initiated the RDP.&lt;/P&gt;&lt;P&gt;The only workaround for this to add the username: &lt;SPAN class="hps" style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;oalgt&lt;/SPAN&gt;&lt;SPAN class="hps" style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;\&lt;/SPAN&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt; &lt;/SPAN&gt;&lt;SPAN class="hps" style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;explotacio&lt;/SPAN&gt; in the ignore users list. This is not an issue with the firewall or the agent.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Refer:&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-2893"&gt;https://live.paloaltonetworks.com/docs/DOC-2893&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps,&lt;/P&gt;&lt;P&gt;Aditi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Oct 2013 15:56:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49934#M36746</guid>
      <dc:creator>apasupulati</dc:creator>
      <dc:date>2013-10-10T15:56:34Z</dc:date>
    </item>
    <item>
      <title>Re: User loses privileges...UserID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49935#M36747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;And what would happen with the users whos has 2 inbox in their exchange??? it happens the same for them??&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Oct 2013 16:21:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49935#M36747</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2013-10-10T16:21:47Z</dc:date>
    </item>
    <item>
      <title>Re: User loses privileges...UserID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49936#M36748</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Depends on how they log on.&lt;/P&gt;&lt;P&gt;Does the user have full access permission to the 2nd mailbox ? If so, you can make everything work with the same credentials.&lt;/P&gt;&lt;P&gt;Or does the 2nd mailbox actually require logging on to it ? If so, you again have a logon event that will be picked up by UserID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In a AD environment, using different logins to different resources, is not really best practice for me. Give a user one account and make sure he can access whatever resource he needs with that account. You shouln't bother your users with several logins.&lt;/P&gt;&lt;P&gt;Obviously this doesn't apply to users who do administrative tasks, where the admin account should be strictly separate from their everyday user account.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope you get it sorted out...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Oct 2013 06:35:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-loses-privileges-userid/m-p/49936#M36748</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2013-10-11T06:35:01Z</dc:date>
    </item>
  </channel>
</rss>

