<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect Limitations in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-limitations/m-p/76062#M42152</link>
    <description>&lt;P&gt;ok so if we base on cert and the machine become disabled in AD, we can revoke the cert and eliminate users from connecting?&lt;/P&gt;</description>
    <pubDate>Fri, 08 Apr 2016 13:58:02 GMT</pubDate>
    <dc:creator>rrau</dc:creator>
    <dc:date>2016-04-08T13:58:02Z</dc:date>
    <item>
      <title>Global Protect Limitations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-limitations/m-p/76020#M42139</link>
      <description>&lt;P&gt;Is there a way to stop disabled AD computer accounts from connecting to GP? &amp;nbsp;We have a HIP profile attached to the GP rules which force the user to be compliant (ie. member of domain and have AntiVirus). &amp;nbsp;however, when we disable their computer account, they are still able to connect. &amp;nbsp;We can stop them from connecting by removing their user account from the allowed AD group however, we dont disable user accounts as much as we do computer accts.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2016 21:06:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-limitations/m-p/76020#M42139</guid>
      <dc:creator>rrau</dc:creator>
      <dc:date>2016-04-07T21:06:00Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Limitations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-limitations/m-p/76023#M42141</link>
      <description>&lt;P&gt;You authenticate based on user credentials?&lt;/P&gt;
&lt;P&gt;Maybe you add second factor - computer certificate that you roll out from AD.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2016 21:37:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-limitations/m-p/76023#M42141</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-04-07T21:37:46Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Limitations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-limitations/m-p/76060#M42150</link>
      <description>&lt;P&gt;Yes, we authenticate based on user creds.&lt;/P&gt;
&lt;P&gt;maybe we could user certs..hmmm&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2016 13:29:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-limitations/m-p/76060#M42150</guid>
      <dc:creator>rrau</dc:creator>
      <dc:date>2016-04-08T13:29:11Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Limitations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-limitations/m-p/76061#M42151</link>
      <description>&lt;P&gt;Yes you can.&lt;/P&gt;
&lt;P&gt;AD cert service will enroll user certs to all users.&lt;/P&gt;
&lt;P&gt;And GP can authenticate based on cert, username/password or both.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2016 13:43:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-limitations/m-p/76061#M42151</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-04-08T13:43:15Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Limitations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-limitations/m-p/76062#M42152</link>
      <description>&lt;P&gt;ok so if we base on cert and the machine become disabled in AD, we can revoke the cert and eliminate users from connecting?&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2016 13:58:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-limitations/m-p/76062#M42152</guid>
      <dc:creator>rrau</dc:creator>
      <dc:date>2016-04-08T13:58:02Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Limitations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-limitations/m-p/76067#M42156</link>
      <description>&lt;P&gt;Yes.&lt;/P&gt;
&lt;P&gt;Or modify this powershell a bit to check disabled computer accounts instead of user accounts and schedule it to run every now and then to disable certificates automatically.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://mikepfeiffer.net/2013/04/restricting-access-to-lync-for-disabled-active-directory-users/" target="_self"&gt;http://mikepfeiffer.net/2013/04/restricting-access-to-lync-for-disabled-active-directory-users/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2016 14:58:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-limitations/m-p/76067#M42156</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-04-08T14:58:29Z</dc:date>
    </item>
  </channel>
</rss>

