<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Exclude account(s) from authentication? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/exclude-account-s-from-authentication/m-p/245699#M70002</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/52796"&gt;@LukeBullimore&lt;/a&gt;&amp;nbsp;I believe that is the opposite of what we'd like to do.&amp;nbsp; There are many many groups and users to be allowed and only a few we'd like denied from logging into captive portal, so a deny option would be best instead of an allow.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;We do currently have a security policy to deny all traffic if they are coming from the captive portal network + match one of the generic user accounts.&amp;nbsp; We'd much rather prefer them not be able to log in with the user at all on the captive portal, as they would now have to wait 24 hours to be re-prompted for creds or have us manually flush them so they can log in with the proper accounts.&lt;/P&gt;</description>
    <pubDate>Fri, 11 Jan 2019 14:22:26 GMT</pubDate>
    <dc:creator>OGMaverick</dc:creator>
    <dc:date>2019-01-11T14:22:26Z</dc:date>
    <item>
      <title>Exclude account(s) from authentication?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exclude-account-s-from-authentication/m-p/245202#M69906</link>
      <description>&lt;P&gt;I know there is the allow list, but what about an exclude?&amp;nbsp; We use Captive Portal for BYOD and have thousands of accounts we want to allow, but exclude our double digit generic accounts from being able to log in.&amp;nbsp; What's the best way to achieve this?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jan 2019 12:51:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exclude-account-s-from-authentication/m-p/245202#M69906</guid>
      <dc:creator>OGMaverick</dc:creator>
      <dc:date>2019-01-08T12:51:16Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude account(s) from authentication?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exclude-account-s-from-authentication/m-p/245269#M69917</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/84842"&gt;@OGMaverick&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;So I would generally create a new AD group for something like this, and then simply deny the group associated with the accounts that you don't want to provide access to.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jan 2019 20:37:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exclude-account-s-from-authentication/m-p/245269#M69917</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-01-08T20:37:46Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude account(s) from authentication?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exclude-account-s-from-authentication/m-p/245360#M69934</link>
      <description>&lt;P&gt;That is what we'd like to do, but we only see the option to &lt;EM&gt;allow &lt;/EM&gt;a group/accounts.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2019 17:31:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exclude-account-s-from-authentication/m-p/245360#M69934</guid>
      <dc:creator>OGMaverick</dc:creator>
      <dc:date>2019-01-09T17:31:07Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude account(s) from authentication?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exclude-account-s-from-authentication/m-p/245515#M69948</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/84842"&gt;@OGMaverick&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Under the advanced tab of an authentication profile (Device -&amp;gt; Authentication Profile), you can allow only certain users or groups from authenticating against that authentication profile via the "allow list".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You would do this change against the authentication profile that is tied to your captive portal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me know if this helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Luke.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 12:39:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exclude-account-s-from-authentication/m-p/245515#M69948</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2019-01-10T12:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude account(s) from authentication?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exclude-account-s-from-authentication/m-p/245574#M69966</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/84842"&gt;@OGMaverick&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;SO&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/52796"&gt;@LukeBullimore&lt;/a&gt;&amp;nbsp;gives a good solution, but even if you don't want to mess around with the Auth Profile you can do the following.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;You're going to get a proper user-id mapping with Captive Portal ya, so why wouldn't you make 2 security policies.&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Denies the generic accounts if coming from the BYOD IP range from accessing anything.&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) Allow known-user on the rest of the policies. If they have been auth'd then good to go, otherwise the generic accounts hit the first rule and the traffic is denied.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 18:30:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exclude-account-s-from-authentication/m-p/245574#M69966</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-01-10T18:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude account(s) from authentication?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exclude-account-s-from-authentication/m-p/245699#M70002</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/52796"&gt;@LukeBullimore&lt;/a&gt;&amp;nbsp;I believe that is the opposite of what we'd like to do.&amp;nbsp; There are many many groups and users to be allowed and only a few we'd like denied from logging into captive portal, so a deny option would be best instead of an allow.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;We do currently have a security policy to deny all traffic if they are coming from the captive portal network + match one of the generic user accounts.&amp;nbsp; We'd much rather prefer them not be able to log in with the user at all on the captive portal, as they would now have to wait 24 hours to be re-prompted for creds or have us manually flush them so they can log in with the proper accounts.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2019 14:22:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exclude-account-s-from-authentication/m-p/245699#M70002</guid>
      <dc:creator>OGMaverick</dc:creator>
      <dc:date>2019-01-11T14:22:26Z</dc:date>
    </item>
  </channel>
</rss>

