<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID Agent Ignore a group of users in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-ignore-a-group-of-users/m-p/201994#M59638</link>
    <description>&lt;P&gt;If&amp;nbsp;we want to have user-ID based rules also for admin accounts, to grant access to management systems etc, that won't work of course if we filter out those accounts in user-ID agents.&lt;/P&gt;</description>
    <pubDate>Fri, 23 Feb 2018 13:56:44 GMT</pubDate>
    <dc:creator>TerjeLundbo</dc:creator>
    <dc:date>2018-02-23T13:56:44Z</dc:date>
    <item>
      <title>User-ID Agent Ignore a group of users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-ignore-a-group-of-users/m-p/201943#M59621</link>
      <description>&lt;P&gt;Hello together,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to ignore a group of users with the User-ID Agent, and also on the firewall without the agent?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tryed to add a group ( example\Ignore User-ID ) to the ignore_user_list.txt for the Agent. But it seemed not to work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also tryed:&lt;/P&gt;&lt;P&gt;example\Ignore User-ID&lt;/P&gt;&lt;P&gt;Ignore User-ID&lt;/P&gt;&lt;P&gt;"example\Ignore User-ID"&lt;/P&gt;&lt;P&gt;"Ignore User-ID"&lt;/P&gt;&lt;P&gt;'example\Ignore User-ID'&lt;/P&gt;&lt;P&gt;'Ignore User-ID'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe it is only prossible for singe user accounts and not for groups? But I think this would be a really good feature.&lt;/P&gt;&lt;P&gt;It would be nice if anyone can give me a hint on this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 09:36:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-ignore-a-group-of-users/m-p/201943#M59621</guid>
      <dc:creator>Clermont</dc:creator>
      <dc:date>2018-02-23T09:36:02Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent Ignore a group of users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-ignore-a-group-of-users/m-p/201958#M59623</link>
      <description>&lt;P&gt;i cant see how this would be possible as user-ip mappings are per user not group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't see why you would want to ignore a group of users... if its for a security policy then just use the group information in the policy and deny it...&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 10:03:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-ignore-a-group-of-users/m-p/201958#M59623</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-02-23T10:03:57Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent Ignore a group of users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-ignore-a-group-of-users/m-p/201968#M59625</link>
      <description>&lt;P&gt;You can't ignore a user group&lt;/P&gt;
&lt;P&gt;The user-id agent records user ID's as they come in through events and then simply matches the user ID to the ignore list to see if it needs to be ignored, there is no group membership lookup&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is a feature request, however. So you can reach out to your local sales team and have them add your vote to &lt;STRONG style="margin: 0px; padding: 0px; color: #333333; font-family: verdana, arial, tahoma, sans-serif; font-size: 12.7488px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-style: initial; text-decoration-color: initial;"&gt;FR ID:&lt;/STRONG&gt;&lt;SPAN style="color: #333333; font-family: verdana, arial, tahoma, sans-serif; font-size: 12.7488px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;1172&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 10:49:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-ignore-a-group-of-users/m-p/201968#M59625</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-02-23T10:49:04Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent Ignore a group of users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-ignore-a-group-of-users/m-p/201976#M59629</link>
      <description>&lt;P&gt;Thank you vermy much for your replay.&lt;/P&gt;&lt;P&gt;I want to ignore a group of users to prevent the "normal" accounts of the administrators to be overwritten by the administrative account of that user.&lt;/P&gt;&lt;P&gt;For example there is a rule for Internet traffic with User-ID. Traffic is allowed for all normal users. Not for administrative accounts.&lt;/P&gt;&lt;P&gt;I'm working on my computer with my normal account "marco". Then I connect to a Server via RDP using my administrative account "marco-admin". Sometimes User-ID then thinks my computer is assigned to "marco-admin" and i can not access the internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 12:25:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-ignore-a-group-of-users/m-p/201976#M59629</guid>
      <dc:creator>Clermont</dc:creator>
      <dc:date>2018-02-23T12:25:18Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent Ignore a group of users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-ignore-a-group-of-users/m-p/201978#M59630</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/64981"&gt;@Clermont&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is very unfortunate!&lt;/P&gt;
&lt;P&gt;Do you have a lot of admins? You can use wildcards in usernames in the ignore list, but only as the last character&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so if you could change your usernames, you would be able to ignore all admin-*&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 12:29:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-ignore-a-group-of-users/m-p/201978#M59630</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-02-23T12:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent Ignore a group of users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-ignore-a-group-of-users/m-p/201985#M59631</link>
      <description>&lt;P&gt;wow... how odd... i can understand the "server ip" to marco-admin but was not aware that the "clent device ip" could also be associated to the username used to logon to the server...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is this because of some network level authentication?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll need to watch out for that.....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cheers for the info.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 12:40:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-ignore-a-group-of-users/m-p/201985#M59631</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-02-23T12:40:10Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent Ignore a group of users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-ignore-a-group-of-users/m-p/201986#M59632</link>
      <description>&lt;P&gt;ok just rdp'd with my test account and client ip mapping also changed to test account.&lt;/P&gt;&lt;P&gt;I can now see how this could be useful...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks again for the info/explanation.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 12:55:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-ignore-a-group-of-users/m-p/201986#M59632</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-02-23T12:55:47Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent Ignore a group of users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-ignore-a-group-of-users/m-p/201987#M59633</link>
      <description>&lt;P&gt;Thanks for your fast reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunatelly our admins end with "*adm" &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I have about 30 accounts. I think I will add them manuelly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just to make sure: Do I have to add them with the domain prefix "domain\marco-admin" or is the username "marco-admin" enough?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have a nice weekend&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 13:07:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-ignore-a-group-of-users/m-p/201987#M59633</guid>
      <dc:creator>Clermont</dc:creator>
      <dc:date>2018-02-23T13:07:25Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent Ignore a group of users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-ignore-a-group-of-users/m-p/201988#M59634</link>
      <description>&lt;P&gt;Is this a bug or a feature? We are just getting started with user-ID, and I can see this being an issue for us working in the IT dept. We use RDP a lot.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 13:12:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-ignore-a-group-of-users/m-p/201988#M59634</guid>
      <dc:creator>TerjeLundbo</dc:creator>
      <dc:date>2018-02-23T13:12:42Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent Ignore a group of users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-ignore-a-group-of-users/m-p/201989#M59635</link>
      <description>&lt;P&gt;Maybe something of both, because the RDP-Logon on a Server is linked for your local machine in User-ID.&amp;nbsp; So we decided to ignore the administrative accounts for User-ID. Which would be much easier with a group.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 13:27:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-ignore-a-group-of-users/m-p/201989#M59635</guid>
      <dc:creator>Clermont</dc:creator>
      <dc:date>2018-02-23T13:27:44Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent Ignore a group of users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-ignore-a-group-of-users/m-p/201990#M59636</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/53120"&gt;@TerjeLundbo&lt;/a&gt;, not sure if I would class this as a bug, more of a feature with some annoying aspects.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have used user-id for some time now and have never had this issue, but only because my user logon also has server admin rights.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have only become aware of this via this post, love this site....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you use a different account for RDP&amp;nbsp; then it&amp;nbsp;will/could be an issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 13:37:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-ignore-a-group-of-users/m-p/201990#M59636</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-02-23T13:37:56Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent Ignore a group of users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-ignore-a-group-of-users/m-p/201991#M59637</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/64981"&gt;@Clermont&lt;/a&gt;&amp;nbsp;I'd recommend adding the domain while you're at it (not sure if mandatory but have always done it that way)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/53120"&gt;@TerjeLundbo&lt;/a&gt;&amp;nbsp;which part are you referring to exactly? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; the rdp anamoly is kinda how microsoft handles authentications (it passes along your source IP with the auth so the user-id agent gets the log and sees your admin pc's ip even though you're logging in remotely)&lt;/P&gt;
&lt;P&gt;The ignore user list is there to help prevent this issue, and also in case there are automated scripts running on a workstation that could trigger after a user has logged on and cause a new authentication log for the workstation's ip, with a service account&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 13:41:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-ignore-a-group-of-users/m-p/201991#M59637</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-02-23T13:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent Ignore a group of users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-ignore-a-group-of-users/m-p/201994#M59638</link>
      <description>&lt;P&gt;If&amp;nbsp;we want to have user-ID based rules also for admin accounts, to grant access to management systems etc, that won't work of course if we filter out those accounts in user-ID agents.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 13:56:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-ignore-a-group-of-users/m-p/201994#M59638</guid>
      <dc:creator>TerjeLundbo</dc:creator>
      <dc:date>2018-02-23T13:56:44Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent Ignore a group of users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-ignore-a-group-of-users/m-p/201998#M59639</link>
      <description>&lt;P&gt;that's correct, depending on the scenario:&lt;/P&gt;
&lt;P&gt;when RDPing into a remote system, the ip mapping of the source will be affected, to which the admin is already logged in&lt;/P&gt;
&lt;P&gt;If the admin then starts performing locat tasks "as administrator" there'll be a secondary authetication that affects the remoted system&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can also enable probes (netbios or WMI) which will periodically poll workstations for their actually 'logged in' user, so if the ip is hijacked by an admin or service account, the probe will correct that mapping also&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 14:04:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-ignore-a-group-of-users/m-p/201998#M59639</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-02-23T14:04:19Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent Ignore a group of users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-ignore-a-group-of-users/m-p/202034#M59646</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;So I ran into a similar situation and found that using exchange logs instead of a domain controllers security logs refreshed faster since outlook is constantly authenticating to exchange. Not sure if that will work in you environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 17:32:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-ignore-a-group-of-users/m-p/202034#M59646</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-02-23T17:32:17Z</dc:date>
    </item>
  </channel>
</rss>

