<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Active Directory group naming scheme in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/active-directory-group-naming-scheme/m-p/98967#M44163</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I'd be interested to here is anyone has come up with interesting naming schemes for AD groups used within Palo Alto firewall policies.&lt;/P&gt;&lt;P&gt;I'm looking for inspiration as I'm looking to come up with a logical scheme on our end.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers.&lt;/P&gt;</description>
    <pubDate>Thu, 21 Jul 2016 01:48:23 GMT</pubDate>
    <dc:creator>jezkerwin</dc:creator>
    <dc:date>2016-07-21T01:48:23Z</dc:date>
    <item>
      <title>Active Directory group naming scheme</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-directory-group-naming-scheme/m-p/98967#M44163</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I'd be interested to here is anyone has come up with interesting naming schemes for AD groups used within Palo Alto firewall policies.&lt;/P&gt;&lt;P&gt;I'm looking for inspiration as I'm looking to come up with a logical scheme on our end.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jul 2016 01:48:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-directory-group-naming-scheme/m-p/98967#M44163</guid>
      <dc:creator>jezkerwin</dc:creator>
      <dc:date>2016-07-21T01:48:23Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory group naming scheme</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-directory-group-naming-scheme/m-p/99053#M44164</link>
      <description>&lt;P&gt;Can you elaborate your request&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jul 2016 07:38:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-directory-group-naming-scheme/m-p/99053#M44164</guid>
      <dc:creator>Roby_Sreejith</dc:creator>
      <dc:date>2016-07-21T07:38:02Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory group naming scheme</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-directory-group-naming-scheme/m-p/99112#M44167</link>
      <description>&lt;P&gt;I'm interested to learn how people name their groups within Active Directory that are used within the Palo Alto Firewall Policies.&lt;/P&gt;&lt;P&gt;Are they named randomly or does the name of the group identify what the policy does within the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm looking to come up with a naming scheme for myself that makes sense, is easy to manage and has relevance when identifying the policy within the firewall so I'd like to learn if others have come up with a scheme or system that they use that I could draw inspiration on for my requirements.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example, if a policy is giving RDP access to a bunch of servers on floor 3 of office 1 is the rule named 'Off_1_Flr_3_RDP_allow' or is it called 'access to rdp for developers'.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jul 2016 12:45:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-directory-group-naming-scheme/m-p/99112#M44167</guid>
      <dc:creator>jezkerwin</dc:creator>
      <dc:date>2016-07-21T12:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory group naming scheme</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-directory-group-naming-scheme/m-p/99211#M44171</link>
      <description>&lt;P&gt;Do you mean just the security rule names / nomenclature?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you're actually talking about security groups in AD that are used in policy on the firewall...Well in most environments the guys that control the firewall have no input on the naming standard of AD security groups.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jul 2016 19:03:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-directory-group-naming-scheme/m-p/99211#M44171</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-07-21T19:03:06Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory group naming scheme</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-directory-group-naming-scheme/m-p/99302#M44174</link>
      <description>&lt;P&gt;Yeah, I'm talking about the nomenclature of the AD security groups themselves.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess I'm in a different position where I have the input in naming both.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jul 2016 00:22:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-directory-group-naming-scheme/m-p/99302#M44174</guid>
      <dc:creator>jezkerwin</dc:creator>
      <dc:date>2016-07-22T00:22:26Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory group naming scheme</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-directory-group-naming-scheme/m-p/99622#M44196</link>
      <description>&lt;P&gt;Naming conventions that I've found most helpful over various employers are ones that are both brief and meaningful. &amp;nbsp;This usually entails determining first the major categories and then sub-groups that have logical meaning for the organization. &amp;nbsp;Then developing a short 3-4 letter abreviation for them to encode into the name.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can further simplify the AD setup by creating security groups that simply contain other groups.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;List of job roles that contain actual users&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;List of resources needing access security that contain job role groups only&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The security policy then can be nuanced to either the resource or the role depending on the details of the rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And names are recognizable abbreviations of the resource or the role.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jul 2016 12:49:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-directory-group-naming-scheme/m-p/99622#M44196</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2016-07-23T12:49:04Z</dc:date>
    </item>
  </channel>
</rss>

