<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Auth Profile 8.1.x LDAP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229558#M66006</link>
    <description>&lt;P&gt;Yes, although the format for the username in our org would be mball.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry for the delay, got the info from the server folk.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CN=Last\, First M. (ORG)&lt;/P&gt;&lt;P&gt;UPN= FLast@domain.com&lt;/P&gt;&lt;P&gt;sAMAccountName= FLast&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since users can log in and get groups pulled using user@domain.com with the following settings,&lt;/P&gt;&lt;P&gt;Attribute userPrincipalName&lt;/P&gt;&lt;P&gt;Blank domain&lt;/P&gt;&lt;P&gt;%USERINPUT%&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it would make sense to me that the following settings would modify just user to work, but do not.&lt;/P&gt;&lt;P&gt;userPrincipalName&lt;/P&gt;&lt;P&gt;domain.com&lt;/P&gt;&lt;P&gt;%USERINPUT%@%USERDOMAIN%&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 05 Sep 2018 14:16:39 GMT</pubDate>
    <dc:creator>OGMaverick</dc:creator>
    <dc:date>2018-09-05T14:16:39Z</dc:date>
    <item>
      <title>Auth Profile 8.1.x LDAP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/228960#M65810</link>
      <description>&lt;P&gt;We'd like our users to be able to log into Captive Portal or Globalprotect with user@domain.com or just user.&amp;nbsp; We've messed around with seemingly every combination of username modifiers, but have not been able to get it to work both ways.&amp;nbsp; Currently, logging in with user@domain.com works and the filter can see the user's AD group memberships.&amp;nbsp; In certain configs, we can get just 'user' to log in, but no user groups are pulled.&amp;nbsp; Does anyone have this working both ways? Currently on 8.1.2.&amp;nbsp;&amp;nbsp;Can't do 8.1.3 due to a bug that wouldn't allow us to commit on the HA pair.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Aug 2018 00:22:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/228960#M65810</guid>
      <dc:creator>OGMaverick</dc:creator>
      <dc:date>2018-08-31T00:22:40Z</dc:date>
    </item>
    <item>
      <title>Re: Auth Profile 8.1.x LDAP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229097#M65861</link>
      <description>&lt;P&gt;I have never tried this but could you not have one auth profile with no modifier and another with the domain modifier and add them both to an authentication sequence.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;perhaps&amp;nbsp;putting your most popular auth type at the top...&lt;/P&gt;</description>
      <pubDate>Sat, 01 Sep 2018 07:44:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229097#M65861</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-09-01T07:44:11Z</dc:date>
    </item>
    <item>
      <title>Re: Auth Profile 8.1.x LDAP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229393#M65948</link>
      <description>&lt;P&gt;We've tried auth sequences as well, but currently we aren't able to get AD groups pulled when someone logs in as 'user'.&amp;nbsp; They can successfully log into the portal and the palo shows their user's DN, but will not show their group memberships.&amp;nbsp; Setting it up another way where they succesffuly log in as user@domain.com pulls their groups.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 14:10:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229393#M65948</guid>
      <dc:creator>OGMaverick</dc:creator>
      <dc:date>2018-09-04T14:10:32Z</dc:date>
    </item>
    <item>
      <title>Re: Auth Profile 8.1.x LDAP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229396#M65950</link>
      <description>&lt;P&gt;so when "user" logs in, are they using the same auth profile as user@domain.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;that may be confusing...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;do you get the same results with just one auth profile.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 14:46:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229396#M65950</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-09-04T14:46:20Z</dc:date>
    </item>
    <item>
      <title>Re: Auth Profile 8.1.x LDAP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229403#M65954</link>
      <description>&lt;P&gt;We've tried with 1 auth profile to catch both as well as a sequence with 2 profiles.&amp;nbsp; The current setup is a sequence that goes through the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Working with&amp;nbsp;@domain.com &amp;amp; pulls groups&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;Login Attribute: userPrincipalName&lt;/P&gt;&lt;P&gt;User Domain: blank&lt;/P&gt;&lt;P&gt;Modifer: %USERINPUT%&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Can log in without&amp;nbsp;@domain.com but does not pull groups:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Login Attribute: userPrincipalName&lt;/P&gt;&lt;P&gt;User Domain:&amp;nbsp;domain.com&lt;/P&gt;&lt;P&gt;Modifer: %USERINPUT%@%USERDOMAIN%&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I feel that we've tried every combination of modifier + user domain (blank, domain, domain.com) + userPrincipalName vs&amp;nbsp;sAMAccountName to no avail of getting groups pulled when it lets just 'user' login.&amp;nbsp; If we can just get a profile that works to let 'user' login &amp;amp; pull groups, then we'd be set putting it in a sequence.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 16:44:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229403#M65954</guid>
      <dc:creator>OGMaverick</dc:creator>
      <dc:date>2018-09-04T16:44:29Z</dc:date>
    </item>
    <item>
      <title>Re: Auth Profile 8.1.x LDAP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229406#M65956</link>
      <description>&lt;P&gt;ok im gonna test this tomorrow but im sure you need to fill in the user domain field.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this is where %userdomain% is populated from.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you login as fred@domain.com with the user domain field blank and the modifier set to userinput@userdomain then you will actually login as fred.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have the netbios name in our user domain field as this is what is used for group mappings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;anothe post will follow with PA help snippet thingy...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 16:42:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229406#M65956</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-09-04T16:42:02Z</dc:date>
    </item>
    <item>
      <title>Re: Auth Profile 8.1.x LDAP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229407#M65957</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I'm sorry, we actually do have the user domain filled with our domain for the profile where we are expecting just 'user'.&amp;nbsp; Edited&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 16:45:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229407#M65957</guid>
      <dc:creator>OGMaverick</dc:creator>
      <dc:date>2018-09-04T16:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: Auth Profile 8.1.x LDAP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229408#M65958</link>
      <description>&lt;P&gt;ok no point sending the help file...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;could you just post an example (using domain.com) of a users CN, UPN and SamAccountName.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i will have a play in the morning...&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 16:48:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229408#M65958</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-09-04T16:48:32Z</dc:date>
    </item>
    <item>
      <title>Re: Auth Profile 8.1.x LDAP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229421#M65961</link>
      <description>&lt;P&gt;Hope this helps -&amp;nbsp;&lt;A href="https://imgur.com/a/2fym3fn" target="_blank"&gt;https://imgur.com/a/2fym3fn&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a 220 test box, so free to make any changes to test at any time.&amp;nbsp; Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 18:12:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229421#M65961</guid>
      <dc:creator>OGMaverick</dc:creator>
      <dc:date>2018-09-04T18:12:32Z</dc:date>
    </item>
    <item>
      <title>Re: Auth Profile 8.1.x LDAP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229423#M65962</link>
      <description>&lt;P&gt;Cool clips but of no help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;im looking for format&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;fred smiff&lt;/P&gt;&lt;P&gt;fred.smiff&lt;/P&gt;&lt;P&gt;fred.smiff@domain.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 18:39:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229423#M65962</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-09-04T18:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: Auth Profile 8.1.x LDAP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229538#M65988</link>
      <description>&lt;P&gt;OK i am able to connect via GP as either mick.ball or mick.ball@domain.thingy.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and i can add user policies for domain.thingy.com\mick.ball&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the policy applies to both mick.ball and mick.ball@domain.thingy.com logins.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is that your expected outcome?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2018 13:00:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229538#M65988</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-09-05T13:00:39Z</dc:date>
    </item>
    <item>
      <title>Re: Auth Profile 8.1.x LDAP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229558#M66006</link>
      <description>&lt;P&gt;Yes, although the format for the username in our org would be mball.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry for the delay, got the info from the server folk.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CN=Last\, First M. (ORG)&lt;/P&gt;&lt;P&gt;UPN= FLast@domain.com&lt;/P&gt;&lt;P&gt;sAMAccountName= FLast&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since users can log in and get groups pulled using user@domain.com with the following settings,&lt;/P&gt;&lt;P&gt;Attribute userPrincipalName&lt;/P&gt;&lt;P&gt;Blank domain&lt;/P&gt;&lt;P&gt;%USERINPUT%&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it would make sense to me that the following settings would modify just user to work, but do not.&lt;/P&gt;&lt;P&gt;userPrincipalName&lt;/P&gt;&lt;P&gt;domain.com&lt;/P&gt;&lt;P&gt;%USERINPUT%@%USERDOMAIN%&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2018 14:16:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229558#M66006</guid>
      <dc:creator>OGMaverick</dc:creator>
      <dc:date>2018-09-05T14:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: Auth Profile 8.1.x LDAP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229567#M66011</link>
      <description>&lt;P&gt;i have exactly that..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ldapmod.png" style="width: 422px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16424iBB8854A5A750CF1E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ldapmod.png" alt="ldapmod.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this works for both mick.ball@domain.com and mick.ball&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or is it the group stuff thats not working for you...&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2018 14:54:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229567#M66011</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-09-05T14:54:08Z</dc:date>
    </item>
    <item>
      <title>Re: Auth Profile 8.1.x LDAP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229577#M66015</link>
      <description>&lt;P&gt;it may be an issue if you are still using auth order.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;just use one profile as i have because the user "user" will still auth against the first profile in auth order and ignore the second'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hmm. that may be confusing... just use 1 profile as per my post, if you need auth order for redundancy the just replicate same settings to different servers.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2018 15:05:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229577#M66015</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-09-05T15:05:43Z</dc:date>
    </item>
    <item>
      <title>Re: Auth Profile 8.1.x LDAP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229578#M66016</link>
      <description>&lt;P&gt;It's the group stuff.&amp;nbsp; That will let the user log in, but not pull any groups, making the security policies not match.&amp;nbsp; Once logged in with 'user', doing a show user ip-user-mapping ip x.x.x.x only shows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IP address: 192.168.1.10 (vsys1)&lt;BR /&gt;User: domain.com\FLast&lt;BR /&gt;From: CP&lt;BR /&gt;Idle Timeout: 894s&lt;BR /&gt;Max. TTL: 3583s&lt;BR /&gt;MFA Timestamp: first(1) - 2018/09/05 11:02:37&lt;BR /&gt;Group(s): domain.com\FLast(225)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;while logging in with user@domain.com shows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IP address: 192.168.1.10 (vsys1)&lt;BR /&gt;User: FLast@domain.com&lt;BR /&gt;From: CP&lt;BR /&gt;Idle Timeout: 896s&lt;BR /&gt;Max. TTL: 3596s&lt;BR /&gt;MFA Timestamp: first(1) - 2018/09/05 11:04:12&lt;BR /&gt;Group(s): &lt;SPAN&gt;FLast&lt;/SPAN&gt;&lt;SPAN&gt;@domain&lt;/SPAN&gt;&lt;SPAN&gt;.com&lt;/SPAN&gt;(115260)&lt;BR /&gt;domain\Flast(712)&lt;BR /&gt;cn=administrators,cn=builtin,dc=ccboe,dc=com(2147483660)&lt;/P&gt;&lt;P&gt;As well as the rest of the groups&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently publishing the change to have cap portal only user the 1 profile made for just 'user' like you showed, instead of the sequence.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;EDIT -&amp;nbsp;&lt;/P&gt;&lt;P&gt;Testing the portal with just the 1 profile that has&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;userPrincipalName&lt;/P&gt;&lt;P&gt;domain.com&lt;/P&gt;&lt;P&gt;%USERINPUT%@%USERDOMAIN%&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;resulted in the same behaiviour above without the groups.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2018 15:38:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229578#M66016</guid>
      <dc:creator>OGMaverick</dc:creator>
      <dc:date>2018-09-05T15:38:21Z</dc:date>
    </item>
    <item>
      <title>Re: Auth Profile 8.1.x LDAP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229579#M66017</link>
      <description>&lt;P&gt;what domain settings do you have in your group mapping server profile?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2018 15:11:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229579#M66017</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-09-05T15:11:47Z</dc:date>
    </item>
    <item>
      <title>Re: Auth Profile 8.1.x LDAP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229583#M66018</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://imgur.com/a/YJn5erd" target="_blank"&gt;https://imgur.com/a/YJn5erd&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had tried with the User Domain filled in here as well as the profile and instead of the profile, but can test again.&amp;nbsp; Group Include List is blank to include all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Testing the portal with just the 1 profile that has&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;userPrincipalName&lt;/P&gt;&lt;P&gt;domain.com&lt;/P&gt;&lt;P&gt;%USERINPUT%@%USERDOMAIN%&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;resulted in the same behaiviour above without the groups.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2018 15:37:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229583#M66018</guid>
      <dc:creator>OGMaverick</dc:creator>
      <dc:date>2018-09-05T15:37:48Z</dc:date>
    </item>
    <item>
      <title>Re: Auth Profile 8.1.x LDAP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229593#M66021</link>
      <description>&lt;P&gt;ok i would test again with 1 profile and add same domain to user domain in group id stuff.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2018 16:35:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229593#M66021</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-09-05T16:35:29Z</dc:date>
    </item>
    <item>
      <title>Re: Auth Profile 8.1.x LDAP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229598#M66022</link>
      <description>&lt;P&gt;That combination did it!&amp;nbsp; I think when we had user domain filled out in the group ID section previously, we were using&amp;nbsp;sAMAccountName instead of userPrincipalName for the profile's login attribute.&amp;nbsp;&amp;nbsp;The 1 profile now works to match the user both ways.&amp;nbsp; Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2018 17:09:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229598#M66022</guid>
      <dc:creator>OGMaverick</dc:creator>
      <dc:date>2018-09-05T17:09:29Z</dc:date>
    </item>
    <item>
      <title>Re: Auth Profile 8.1.x LDAP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229789#M66062</link>
      <description>&lt;P&gt;Mirrored the exact same&amp;nbsp;Auth Profile, User-ID Captive Portal (which is pointing to the new auth profile),&amp;nbsp; User-ID Group Mapping settings, &amp;amp; LDAP server to the main Palo which is also on the same PanOS version and it is not even normalizing there.&amp;nbsp; Wonder if ther is another setting elsewhere on the main&amp;nbsp;device that I'm missing&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 18:52:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/auth-profile-8-1-x-ldap/m-p/229789#M66062</guid>
      <dc:creator>OGMaverick</dc:creator>
      <dc:date>2018-09-06T18:52:36Z</dc:date>
    </item>
  </channel>
</rss>

