<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 8.1.4 CP Normalizing in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/8-1-4-cp-normalizing/m-p/237821#M68140</link>
    <description>&lt;P&gt;All of our users who auth over CP are now normalizing as 'domain&lt;STRONG&gt;.com&lt;/STRONG&gt;\user' although we need them to be user@domain.com.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The authentication profile they go through has the&amp;nbsp;%USERINPUT%@%USERDOMAIN% modifier.&amp;nbsp; Domain is filled in &amp;amp; login attribute is 'userPrincipalName'.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All users who are gettng mapped through AD instead of CP are showing corrently as user@domain.com.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We only have 1 auth profile, 1 ldap server profile, 1 group mapping settings profile.&lt;/P&gt;</description>
    <pubDate>Tue, 30 Oct 2018 17:41:32 GMT</pubDate>
    <dc:creator>OGMaverick</dc:creator>
    <dc:date>2018-10-30T17:41:32Z</dc:date>
    <item>
      <title>8.1.4 CP Normalizing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/8-1-4-cp-normalizing/m-p/237821#M68140</link>
      <description>&lt;P&gt;All of our users who auth over CP are now normalizing as 'domain&lt;STRONG&gt;.com&lt;/STRONG&gt;\user' although we need them to be user@domain.com.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The authentication profile they go through has the&amp;nbsp;%USERINPUT%@%USERDOMAIN% modifier.&amp;nbsp; Domain is filled in &amp;amp; login attribute is 'userPrincipalName'.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All users who are gettng mapped through AD instead of CP are showing corrently as user@domain.com.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We only have 1 auth profile, 1 ldap server profile, 1 group mapping settings profile.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Oct 2018 17:41:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/8-1-4-cp-normalizing/m-p/237821#M68140</guid>
      <dc:creator>OGMaverick</dc:creator>
      <dc:date>2018-10-30T17:41:32Z</dc:date>
    </item>
    <item>
      <title>Re: 8.1.4 CP Normalizing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/8-1-4-cp-normalizing/m-p/237829#M68142</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/84842"&gt;@OGMaverick&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;All of our users who auth over CP are now normalizing as 'domain&lt;STRONG&gt;.com&lt;/STRONG&gt;\user' although we need them to be user@domain.com.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;What do you mean with "now"? Did the format suddenly change? Was there something changed by somwone in youe company? Did you upgrade from PAN-OS 8.0 to 8.1?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Oct 2018 18:12:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/8-1-4-cp-normalizing/m-p/237829#M68142</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-10-30T18:12:04Z</dc:date>
    </item>
    <item>
      <title>Re: 8.1.4 CP Normalizing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/8-1-4-cp-normalizing/m-p/237831#M68144</link>
      <description>&lt;P&gt;There were the following 2 changes:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;8.1.2 &amp;gt; 8.1.4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Changed auth profile to include the modifier so users can log in as 'user' &lt;EM&gt;or&lt;/EM&gt; 'user@ccboe.com'&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Oct 2018 18:17:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/8-1-4-cp-normalizing/m-p/237831#M68144</guid>
      <dc:creator>OGMaverick</dc:creator>
      <dc:date>2018-10-30T18:17:26Z</dc:date>
    </item>
    <item>
      <title>Re: 8.1.4 CP Normalizing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/8-1-4-cp-normalizing/m-p/237832#M68145</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/84842"&gt;@OGMaverick&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The reason&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;is asking about the possible upgrade path is due to the fact that there were default-behavior changes introduced in 8.1, so if this is your first release on 8.1 you could be encountering the changes for the first time. Take a look at your profile and see what the&amp;nbsp;&lt;STRONG&gt;Primary Username&lt;/STRONG&gt; field is.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Oct 2018 18:19:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/8-1-4-cp-normalizing/m-p/237832#M68145</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-10-30T18:19:38Z</dc:date>
    </item>
    <item>
      <title>Re: 8.1.4 CP Normalizing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/8-1-4-cp-normalizing/m-p/237834#M68146</link>
      <description>&lt;P&gt;We've been on 8.1.x since we got our boxes (5220)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, up until now we were only using userinput instead of modifying it so that users could log in with or without the domain.&amp;nbsp; Primary username is&amp;nbsp;&lt;STRONG&gt;userPrincipalName.&amp;nbsp; &lt;/STRONG&gt;The 8.1.4 upgrade &amp;amp; auth profile change were done at the same time.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Oct 2018 18:33:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/8-1-4-cp-normalizing/m-p/237834#M68146</guid>
      <dc:creator>OGMaverick</dc:creator>
      <dc:date>2018-10-30T18:33:04Z</dc:date>
    </item>
    <item>
      <title>Re: 8.1.4 CP Normalizing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/8-1-4-cp-normalizing/m-p/237863#M68157</link>
      <description>&lt;P&gt;... this probably is still a tricky task to do ...&lt;/P&gt;&lt;P&gt;I once spent quite while with testing this authentication for global protect with PAN-OS 8.0. But I gave up because of similar/the same problems that you describe.&lt;/P&gt;&lt;P&gt;Anyway if I would do it again, I would try it with two authentication profiles that are combined in a authentication sequence with the option "&lt;SPAN&gt;Use domain to determine authentication profile" enabled. In the sequence you have to place the auth profile for sAMAccountname first and the other for UPN as second profile. This way you have more flexibility with the domain/modifier and hopefully this is a way that will work.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Oct 2018 22:53:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/8-1-4-cp-normalizing/m-p/237863#M68157</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-10-30T22:53:11Z</dc:date>
    </item>
  </channel>
</rss>

