<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Credential Phishing with credential submission method as Use Domain Credential Filter in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/credential-phishing-with-credential-submission-method-as-use/m-p/158197#M51790</link>
    <description>&lt;P&gt;Hello team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Customer has configured Credential Phishing with credential submission method as Use Domain Credential Filter and it does not work&lt;BR /&gt;The user id agent is configured on the writeable domain controller&lt;BR /&gt;But according to the below document to enable credential detection, must install the Windows-based User-ID agent on an RODC&lt;BR /&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/threat-prevention/configure-credential-detection-with-the-windows-based-user-id-agent#_20973" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/threat-prevention/configure-credential-detection-with-the-windows-based-user-id-agent#_20973&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Wanted to verify if RODC is mandatory to enable credential detection or will it work on writeable domain controller&lt;/P&gt;&lt;P&gt;The output of show user user-id-agent state SVR-DC2 is attached&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kindly verify regarding the same&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="output.PNG" style="width: 796px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9404iCFE9D0BAFEB8866E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="output.PNG" alt="output.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Banu Priya&lt;/P&gt;</description>
    <pubDate>Wed, 24 May 2017 22:47:31 GMT</pubDate>
    <dc:creator>bgunasekar</dc:creator>
    <dc:date>2017-05-24T22:47:31Z</dc:date>
    <item>
      <title>Credential Phishing with credential submission method as Use Domain Credential Filter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/credential-phishing-with-credential-submission-method-as-use/m-p/158197#M51790</link>
      <description>&lt;P&gt;Hello team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Customer has configured Credential Phishing with credential submission method as Use Domain Credential Filter and it does not work&lt;BR /&gt;The user id agent is configured on the writeable domain controller&lt;BR /&gt;But according to the below document to enable credential detection, must install the Windows-based User-ID agent on an RODC&lt;BR /&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/threat-prevention/configure-credential-detection-with-the-windows-based-user-id-agent#_20973" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/threat-prevention/configure-credential-detection-with-the-windows-based-user-id-agent#_20973&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Wanted to verify if RODC is mandatory to enable credential detection or will it work on writeable domain controller&lt;/P&gt;&lt;P&gt;The output of show user user-id-agent state SVR-DC2 is attached&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kindly verify regarding the same&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="output.PNG" style="width: 796px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9404iCFE9D0BAFEB8866E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="output.PNG" alt="output.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Banu Priya&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2017 22:47:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/credential-phishing-with-credential-submission-method-as-use/m-p/158197#M51790</guid>
      <dc:creator>bgunasekar</dc:creator>
      <dc:date>2017-05-24T22:47:31Z</dc:date>
    </item>
    <item>
      <title>Re: Credential Phishing with credential submission method as Use Domain Credential Filter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/credential-phishing-with-credential-submission-method-as-use/m-p/158359#M51831</link>
      <description>&lt;P&gt;When you asked the question, I was thinking the RODC was just a suggestion for security reasons, and the link you tagged actually states as such:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/threat-prevention/configure-credential-detection-with-the-windows-based-user-id-agent#_20973" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/threat-prevention/configure-credential-detection-with-the-windows-based-user-id-agent#_20973&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;Installing the User-ID agent on an RODC can be useful for a few reasons: access to the domain controller directory is not required to enable credential detection and you can support credential detection for a limited or targeted set of users. Because the directory the RODC hosts is read-only, the directory contents remain secure on the domain controller."&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2017 17:45:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/credential-phishing-with-credential-submission-method-as-use/m-p/158359#M51831</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2017-05-25T17:45:20Z</dc:date>
    </item>
    <item>
      <title>Re: Credential Phishing with credential submission method as Use Domain Credential Filter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/credential-phishing-with-credential-submission-method-as-use/m-p/211264#M61647</link>
      <description>&lt;P&gt;Did you get your issue resolved?&lt;/P&gt;</description>
      <pubDate>Sun, 22 Apr 2018 22:27:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/credential-phishing-with-credential-submission-method-as-use/m-p/211264#M61647</guid>
      <dc:creator>staustin</dc:creator>
      <dc:date>2018-04-22T22:27:19Z</dc:date>
    </item>
    <item>
      <title>Re: Credential Phishing with credential submission method as Use Domain Credential Filter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/credential-phishing-with-credential-submission-method-as-use/m-p/218304#M63115</link>
      <description>&lt;P&gt;I'd like to know the same, for I'd like to implement but I don't want to set up an RODC for the sole purpose of supporting this.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 22:36:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/credential-phishing-with-credential-submission-method-as-use/m-p/218304#M63115</guid>
      <dc:creator>cenders</dc:creator>
      <dc:date>2018-06-18T22:36:11Z</dc:date>
    </item>
    <item>
      <title>Re: Credential Phishing with credential submission method as Use Domain Credential Filter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/credential-phishing-with-credential-submission-method-as-use/m-p/305861#M79493</link>
      <description>&lt;P&gt;Have you got answer for this ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2020 13:05:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/credential-phishing-with-credential-submission-method-as-use/m-p/305861#M79493</guid>
      <dc:creator>OmPrasad</dc:creator>
      <dc:date>2020-01-07T13:05:54Z</dc:date>
    </item>
    <item>
      <title>Re: Credential Phishing with credential submission method as Use Domain Credential Filter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/credential-phishing-with-credential-submission-method-as-use/m-p/306877#M79704</link>
      <description>&lt;P&gt;Unfortunately for this feature to work an RODC is required. Starting from windows server 2012 (or maybe even 2008) the password hashes are not readable from an AD joined server and not even on the domaincontroller itself - even obviously the password hashes are available there. The only way to read these hashes is on an RODC.&lt;/P&gt;&lt;P&gt;(I received this answer from PaloAlto Support)&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 20:45:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/credential-phishing-with-credential-submission-method-as-use/m-p/306877#M79704</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-01-15T20:45:36Z</dc:date>
    </item>
    <item>
      <title>Re: Credential Phishing with credential submission method as Use Domain Credential Filter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/credential-phishing-with-credential-submission-method-as-use/m-p/306895#M79709</link>
      <description>&lt;P&gt;Yes, I tested the same configuring RODC when it was not working on AD. It worked on RODC only.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jan 2020 06:41:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/credential-phishing-with-credential-submission-method-as-use/m-p/306895#M79709</guid>
      <dc:creator>OmPrasad</dc:creator>
      <dc:date>2020-01-16T06:41:47Z</dc:date>
    </item>
    <item>
      <title>Re: Credential Phishing with credential submission method as Use Domain Cre</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/credential-phishing-with-credential-submission-method-as-use/m-p/332630#M84079</link>
      <description>&lt;P&gt;this is exactly what we needed to know.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2020 18:55:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/credential-phishing-with-credential-submission-method-as-use/m-p/332630#M84079</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2020-06-09T18:55:07Z</dc:date>
    </item>
  </channel>
</rss>

