<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User-ID stopped working / Failed to add group to id manager in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-stopped-working-failed-to-add-group-to-id-manager/m-p/249963#M71091</link>
    <description>&lt;P&gt;Hi Folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;just to let you know, since I found no KB Articel for this issue. Policy Push from Panorama respectively local Commit on the Firewalls ended in strange Error Message according Group Assignment to Policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;vsys1&lt;BR /&gt;Error: Failed to add group to id manager&lt;BR /&gt;Error: Failed to parse security policy&lt;BR /&gt;(Module: device)&lt;BR /&gt;Commit failed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cure comes with CLI Command:&amp;nbsp;"debug user-id reset user-id-manager type user-group"&lt;/P&gt;&lt;P&gt;-&amp;gt; configure&lt;BR /&gt;-&amp;gt; commit force&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Works like a charme!&lt;/P&gt;</description>
    <pubDate>Wed, 13 Feb 2019 14:48:44 GMT</pubDate>
    <dc:creator>enssenje</dc:creator>
    <dc:date>2019-02-13T14:48:44Z</dc:date>
    <item>
      <title>User-ID stopped working / Failed to add group to id manager</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-stopped-working-failed-to-add-group-to-id-manager/m-p/249963#M71091</link>
      <description>&lt;P&gt;Hi Folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;just to let you know, since I found no KB Articel for this issue. Policy Push from Panorama respectively local Commit on the Firewalls ended in strange Error Message according Group Assignment to Policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;vsys1&lt;BR /&gt;Error: Failed to add group to id manager&lt;BR /&gt;Error: Failed to parse security policy&lt;BR /&gt;(Module: device)&lt;BR /&gt;Commit failed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cure comes with CLI Command:&amp;nbsp;"debug user-id reset user-id-manager type user-group"&lt;/P&gt;&lt;P&gt;-&amp;gt; configure&lt;BR /&gt;-&amp;gt; commit force&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Works like a charme!&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 14:48:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-stopped-working-failed-to-add-group-to-id-manager/m-p/249963#M71091</guid>
      <dc:creator>enssenje</dc:creator>
      <dc:date>2019-02-13T14:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID stopped working / Failed to add group to id manager</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-stopped-working-failed-to-add-group-to-id-manager/m-p/426557#M94511</link>
      <description>&lt;P&gt;This can work for most commit issues as well (from my experience). I would like to add a note on what I was seeing here to maybe help others. I have "Group Mapping Settings" pushed from Panorama to my devices globally, sadly the "Groups Included List" does not work properly when pushed to devices. I have to go in and override the mappings on each device removing the include groups and adding them back in the override.&lt;BR /&gt;&lt;BR /&gt;A commit force does work from the local device but when pushing the Template and Group Config you still get:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV&gt;&lt;STRONG&gt;Details:&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;. &lt;/STRONG&gt;vsys1&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;. &lt;/STRONG&gt;Error: Failed to add group to id manager&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;. &lt;/STRONG&gt;Error: Failed to parse security policy&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;. &lt;/STRONG&gt;(Module: device)&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;. &lt;/STRONG&gt;Commit failed&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;This is where the override comes in to fix this on the Panorama push. The issue here is the firewall(s) don't have the group mapped that is being used in the security policy. Again this is because Panorama does not properly populate the included groups in the Group Mapping config.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 16:19:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-stopped-working-failed-to-add-group-to-id-manager/m-p/426557#M94511</guid>
      <dc:creator>TBardIPsoft</dc:creator>
      <dc:date>2021-08-12T16:19:34Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID stopped working / Failed to add group to id manager</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-stopped-working-failed-to-add-group-to-id-manager/m-p/1235225#M124882</link>
      <description>&lt;P&gt;Another possibility is too many Groups from Group Mapping or Users in the Groups.&amp;nbsp; Most firewalls have a limit of 10,000 Groups.&amp;nbsp; Anymore than that and we've got to limit that with filters.&amp;nbsp; Confirm with&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;show user group-mapping statistics &lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Aug 2025 16:58:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-stopped-working-failed-to-add-group-to-id-manager/m-p/1235225#M124882</guid>
      <dc:creator>tcleghorn</dc:creator>
      <dc:date>2025-08-01T16:58:09Z</dc:date>
    </item>
  </channel>
</rss>

