<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is it possible to create custom role in PAN-OS that allows management of administrator accounts? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-create-custom-role-in-pan-os-that-allows/m-p/170622#M54066</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/30584"&gt;@scottsander&lt;/a&gt;&lt;/P&gt;&lt;P&gt;If you use RADIUS/TACACS+ for authentication then you could do the user/rights management on your RADIUS server or even better if the RADIUS is connected to an Active Directory you could create a usergroup and if a user from this user tries to log in the RADIUS will tell the firewall what Admin Role should be applied. This method could be used for all the mentionned points in your post except the local administrators for because of the reason already explained by &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;. But also with this method you have to keep in mind: the admin of the RADIUS server will also be able to configure superuser rights, if he wants to ...&lt;/P&gt;</description>
    <pubDate>Tue, 08 Aug 2017 21:12:33 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2017-08-08T21:12:33Z</dc:date>
    <item>
      <title>Is it possible to create custom role in PAN-OS that allows management of administrator accounts?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-create-custom-role-in-pan-os-that-allows/m-p/170499#M54051</link>
      <description>&lt;P&gt;I would like to create a custom Admin Role in PAN-OS 7.1.9 that is like a system admin for the device with the ability to configure and manage authentication, logging, licensing, certificates, dynamic updates, software, and administrators; however, when I am creating a new Admin Role, the Administrators and Admin Roles items can only be set to Read Only or Disabled.&amp;nbsp; The account I am logged in with has the Superuser dynamic role.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to create a custom role that can manage Administrators and Admin Roles?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2017 12:32:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-create-custom-role-in-pan-os-that-allows/m-p/170499#M54051</guid>
      <dc:creator>scottsander</dc:creator>
      <dc:date>2017-08-08T12:32:13Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to create custom role in PAN-OS that allows management of administrator accounts?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-create-custom-role-in-pan-os-that-allows/m-p/170530#M54056</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/30584"&gt;@scottsander&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The superuser role is the only admin role that is allowed to administer other Administrators or Admin Roles themselves.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you grant someone the ability to modify Administrators and modify the Admin Roles you in essence give them the ability to enable their account as a superuser, therefore the function is locked to users already granted the administrator role.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2017 14:48:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-create-custom-role-in-pan-os-that-allows/m-p/170530#M54056</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-08-08T14:48:26Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to create custom role in PAN-OS that allows management of administrator accounts?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-create-custom-role-in-pan-os-that-allows/m-p/170622#M54066</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/30584"&gt;@scottsander&lt;/a&gt;&lt;/P&gt;&lt;P&gt;If you use RADIUS/TACACS+ for authentication then you could do the user/rights management on your RADIUS server or even better if the RADIUS is connected to an Active Directory you could create a usergroup and if a user from this user tries to log in the RADIUS will tell the firewall what Admin Role should be applied. This method could be used for all the mentionned points in your post except the local administrators for because of the reason already explained by &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;. But also with this method you have to keep in mind: the admin of the RADIUS server will also be able to configure superuser rights, if he wants to ...&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2017 21:12:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-create-custom-role-in-pan-os-that-allows/m-p/170622#M54066</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-08-08T21:12:33Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to create custom role in PAN-OS that allows management of administrator accounts?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-create-custom-role-in-pan-os-that-allows/m-p/170751#M54101</link>
      <description>&lt;P&gt;Interesting idea. I don't know much about TACACS+, but I don't like PAN's implementation of RADIUS since it only uses unencrypted PAP unless you are in FIPS mode and even then it only uses CHAP. I use Kerberos today.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2017 12:43:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-create-custom-role-in-pan-os-that-allows/m-p/170751#M54101</guid>
      <dc:creator>scottsander</dc:creator>
      <dc:date>2017-08-09T12:43:07Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to create custom role in PAN-OS that allows management of administrator accounts?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-create-custom-role-in-pan-os-that-allows/m-p/170756#M54104</link>
      <description>&lt;P&gt;Just a thought, but you probably have a bigger problem if an attacker is able to capture your RADIUS traffic than PAP really is (the firewall management and RADIUS server are in protected networks)&lt;/P&gt;&lt;P&gt;But I know what you're saying.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And I totally forgot to mention: SAML&lt;/P&gt;&lt;P&gt;Only works with the WebUI and not for SSH but is also a great methof for authentication and passwords aren't sent at all to the firewall, only to your SAML IdP&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2017 12:59:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-create-custom-role-in-pan-os-that-allows/m-p/170756#M54104</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-08-09T12:59:24Z</dc:date>
    </item>
  </channel>
</rss>

