<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Required permissions for Active Directory integration in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/required-permissions-for-active-directory-integration/m-p/234610#M67256</link>
    <description>&lt;P&gt;Awesome thank you.&amp;nbsp; Looks like it actually doesn't need the Event Log Reader but did need Distributed Com Users.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 09 Oct 2018 18:03:01 GMT</pubDate>
    <dc:creator>Dylanroehrig</dc:creator>
    <dc:date>2018-10-09T18:03:01Z</dc:date>
    <item>
      <title>Required permissions for Active Directory integration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/required-permissions-for-active-directory-integration/m-p/234575#M67248</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to get AD authentication to work for GlobalProtect.&amp;nbsp; I have been following this document &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmAdCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmAdCAK&lt;/A&gt; for configuring the AD integration part, and it says:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Before you integrate a Palo Alto Networks device with AD, you must create a user ID in AD that you'll use to access LDAP. At a minimum, this account must be a member of the built-in Server Operators group in AD. For security reasons and to be compliant with the best practices, you should adhere&amp;nbsp;to the minimum access rights for this account.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I put the account that I created in the Server Operators group, however when it tries to connect to a domain controller, I get &lt;FONT color="#FF0000"&gt;Access Denied&lt;/FONT&gt; (Device &amp;gt; User Identification &amp;gt; User Mapping &amp;gt; Server Monitoring box).&amp;nbsp; If I stick that account in the Domain Admins group, I get &lt;FONT color="#339966"&gt;Connected&lt;/FONT&gt;.&amp;nbsp; So, is the document wrong about the minimum required access rights, or am I missing a permission someplace else?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Dylan&lt;/P&gt;</description>
      <pubDate>Tue, 09 Oct 2018 15:02:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/required-permissions-for-active-directory-integration/m-p/234575#M67248</guid>
      <dc:creator>Dylanroehrig</dc:creator>
      <dc:date>2018-10-09T15:02:03Z</dc:date>
    </item>
    <item>
      <title>Re: Required permissions for Active Directory integration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/required-permissions-for-active-directory-integration/m-p/234587#M67253</link>
      <description>&lt;P&gt;I'm sure you need the following...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Event Log Reader&lt;/P&gt;&lt;P&gt;Distributed COM Users&lt;/P&gt;&lt;P&gt;Server Operators&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Server operators is the very minimum, just about allows you to bind but not dig deep and read logs...&lt;/P&gt;</description>
      <pubDate>Tue, 09 Oct 2018 16:19:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/required-permissions-for-active-directory-integration/m-p/234587#M67253</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-10-09T16:19:42Z</dc:date>
    </item>
    <item>
      <title>Re: Required permissions for Active Directory integration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/required-permissions-for-active-directory-integration/m-p/234610#M67256</link>
      <description>&lt;P&gt;Awesome thank you.&amp;nbsp; Looks like it actually doesn't need the Event Log Reader but did need Distributed Com Users.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Oct 2018 18:03:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/required-permissions-for-active-directory-integration/m-p/234610#M67256</guid>
      <dc:creator>Dylanroehrig</dc:creator>
      <dc:date>2018-10-09T18:03:01Z</dc:date>
    </item>
    <item>
      <title>Re: Required permissions for Active Directory integration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/required-permissions-for-active-directory-integration/m-p/420742#M93896</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have tried this solution and it failed. Would I have to reboot the firewall after I do changes? (remove the account from the domain admin group)&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jul 2021 15:12:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/required-permissions-for-active-directory-integration/m-p/420742#M93896</guid>
      <dc:creator>DavidGuzman</dc:creator>
      <dc:date>2021-07-20T15:12:44Z</dc:date>
    </item>
  </channel>
</rss>

