<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: user id not identifying user correctly in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-identifying-user-correctly/m-p/226228#M65129</link>
    <description>&lt;P&gt;would it not work if you added the migrated users (now and as you migrate them) to a user exclude list on the agent pointing to the old domain.&lt;/P&gt;</description>
    <pubDate>Tue, 07 Aug 2018 08:50:26 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2018-08-07T08:50:26Z</dc:date>
    <item>
      <title>user id not identifying user correctly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-identifying-user-correctly/m-p/224922#M64571</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;In the middle of a domain migration and users that have been migrated are not being identified correctly. The user that is logged into the new domain gets a blocked message but on the blocked message where it displays the username it shows their old domain \ username. (username being correct and the domain being the old one).&lt;/P&gt;&lt;P&gt;I have the user id agent running on both domains but user id is not listing the user correctly.&lt;/P&gt;&lt;P&gt;The users account for the rest of the network is working correctly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone else come across this?&lt;/P&gt;</description>
      <pubDate>Mon, 06 Aug 2018 10:27:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-identifying-user-correctly/m-p/224922#M64571</guid>
      <dc:creator>DavidBleek</dc:creator>
      <dc:date>2018-08-06T10:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: user id not identifying user correctly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-identifying-user-correctly/m-p/224929#M64572</link>
      <description>&lt;P&gt;if you enter in CLI&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show user group name "fqdn of your&amp;nbsp;AD group from new domain"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can you see all the users listed.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Aug 2018 11:04:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-identifying-user-correctly/m-p/224929#M64572</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-08-06T11:04:34Z</dc:date>
    </item>
    <item>
      <title>Re: user id not identifying user correctly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-identifying-user-correctly/m-p/224930#M64573</link>
      <description>&lt;P&gt;also...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what is the ip mapping timeout set to on the agent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if this time has elapsed then there should be no record of this user on the old domain mapping.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if it is being renewed then perhaps something on the users device is still auth'ing to the old domain.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Aug 2018 11:19:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-identifying-user-correctly/m-p/224930#M64573</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-08-06T11:19:02Z</dc:date>
    </item>
    <item>
      <title>Re: user id not identifying user correctly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-identifying-user-correctly/m-p/224931#M64574</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/60300"&gt;@DavidBleek&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I assume you have a two-way trust between the domains? And the computers, are these also migrated or only the useraccounts?&lt;/P&gt;</description>
      <pubDate>Mon, 06 Aug 2018 11:24:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-identifying-user-correctly/m-p/224931#M64574</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-08-06T11:24:58Z</dc:date>
    </item>
    <item>
      <title>Re: user id not identifying user correctly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-identifying-user-correctly/m-p/224937#M64577</link>
      <description>&lt;P&gt;yes its a 2 way trust, only user accounts have been migrated&lt;/P&gt;</description>
      <pubDate>Mon, 06 Aug 2018 12:17:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-identifying-user-correctly/m-p/224937#M64577</guid>
      <dc:creator>DavidBleek</dc:creator>
      <dc:date>2018-08-06T12:17:23Z</dc:date>
    </item>
    <item>
      <title>Re: user id not identifying user correctly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-identifying-user-correctly/m-p/224938#M64578</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;probing is set to 20 mins.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if I turn off "enable Session" from the user mapping user id agent set up tab under devive-iser identification then the user displays correctly but we now get a TLS error for all users so had to turn it back on.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Aug 2018 12:21:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-identifying-user-correctly/m-p/224938#M64578</guid>
      <dc:creator>DavidBleek</dc:creator>
      <dc:date>2018-08-06T12:21:12Z</dc:date>
    </item>
    <item>
      <title>Re: user id not identifying user correctly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-identifying-user-correctly/m-p/224967#M64587</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/60300"&gt;@DavidBleek&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Are all users allready migrated or are they migrated slowly over time? Do you use Microsoft Exchange and if yes, do you have these also configured as source in your User-ID Agent configuration?&lt;/P&gt;</description>
      <pubDate>Mon, 06 Aug 2018 15:24:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-identifying-user-correctly/m-p/224967#M64587</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-08-06T15:24:15Z</dc:date>
    </item>
    <item>
      <title>Re: user id not identifying user correctly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-identifying-user-correctly/m-p/226223#M65128</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;They are being migrated slowly. We use office 365&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 08:06:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-identifying-user-correctly/m-p/226223#M65128</guid>
      <dc:creator>DavidBleek</dc:creator>
      <dc:date>2018-08-07T08:06:49Z</dc:date>
    </item>
    <item>
      <title>Re: user id not identifying user correctly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-identifying-user-correctly/m-p/226228#M65129</link>
      <description>&lt;P&gt;would it not work if you added the migrated users (now and as you migrate them) to a user exclude list on the agent pointing to the old domain.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 08:50:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-identifying-user-correctly/m-p/226228#M65129</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-08-07T08:50:26Z</dc:date>
    </item>
    <item>
      <title>Re: user id not identifying user correctly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-identifying-user-correctly/m-p/226230#M65131</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/60300"&gt;@DavidBleek&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunetely in this case I cannot really help. I had the same problem. We are also in a domain migration where users get new computers which are joined to the new domain but the users were not migrated at the same time they receive the new computer. In my case we don't even have User-ID but the users show up anyway with "olddomain\user" AND "newdomain\user".&amp;nbsp;&lt;/P&gt;&lt;P&gt;As soon as the users are migrated and so user and comouter are in the new domain, the problem was gone. Adding exchangeservers would also help in your case, but I undersand that this could be difficult with O365 (unless you have exchange on premise). Maybe &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;has a good idea to solve this, but my recommendation is: Use as much User-ID sources as possible where you get the mapping from the new domain (Global Protect internal gateway, Captive portal with Kerberos/SAML single sign on, ...). This way the mapping from the old domain should be overriden as fast as possible (like the situation you have with server session read).&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 09:02:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-identifying-user-correctly/m-p/226230#M65131</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-08-07T09:02:15Z</dc:date>
    </item>
  </channel>
</rss>

