<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Crednetial Phishing Agent Permissions in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/crednetial-phishing-agent-permissions/m-p/251268#M71446</link>
    <description>&lt;P&gt;Hi thanks for replying - I've made sure we're using the system account, not a service account.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've logged it with TAC and will update here if I get a resolution.&lt;/P&gt;</description>
    <pubDate>Tue, 26 Feb 2019 03:13:17 GMT</pubDate>
    <dc:creator>SARowe_NZ</dc:creator>
    <dc:date>2019-02-26T03:13:17Z</dc:date>
    <item>
      <title>Crednetial Phishing Agent Permissions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/crednetial-phishing-agent-permissions/m-p/229276#M65915</link>
      <description>&lt;P&gt;Does anyone know if the credential phishing agent requires different\additional permissions to the base User agent?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have installed with our 'standard' account and I get this in the logs:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;09/03/18 18:05:33:996 [ Info 2036]: ------------Service is being started------------&lt;BR /&gt;&amp;nbsp;09/03/18 18:05:33:996 [ Info 2043]: Os version is 6.2.0.&lt;BR /&gt;&amp;nbsp;09/03/18 18:05:33:996 [ Info&amp;nbsp; 389]: Load debug log level Info.&lt;BR /&gt;&amp;nbsp;09/03/18 18:05:33:996 [ Info&amp;nbsp; 247]: Service version is 8.1.3.10.&lt;BR /&gt;&amp;nbsp;09/03/18 18:05:33:996 [ Info&amp;nbsp; 392]: Product version is 8.&lt;BR /&gt;&amp;nbsp;09/03/18 18:05:33:996 [ Info&amp;nbsp; 313]: Named pipe for UaService created.&lt;BR /&gt;&amp;nbsp;09/03/18 18:05:34:028 [Error&amp;nbsp; 716]: Unable to extract credentials.&lt;BR /&gt;&amp;nbsp;09/03/18 18:05:39:028 [Error&amp;nbsp; 716]: Unable to extract credentials.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is also possible this is due to a security setting on the server itself I assume.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 03 Sep 2018 17:15:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/crednetial-phishing-agent-permissions/m-p/229276#M65915</guid>
      <dc:creator>apackard</dc:creator>
      <dc:date>2018-09-03T17:15:07Z</dc:date>
    </item>
    <item>
      <title>Re: Crednetial Phishing Agent Permissions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/crednetial-phishing-agent-permissions/m-p/251246#M71441</link>
      <description>&lt;P&gt;Hey did you get this fixed? I'm having the same issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;BR /&gt;Shannon&lt;/P&gt;</description>
      <pubDate>Mon, 25 Feb 2019 23:41:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/crednetial-phishing-agent-permissions/m-p/251246#M71441</guid>
      <dc:creator>SARowe_NZ</dc:creator>
      <dc:date>2019-02-25T23:41:59Z</dc:date>
    </item>
    <item>
      <title>Re: Crednetial Phishing Agent Permissions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/crednetial-phishing-agent-permissions/m-p/251266#M71445</link>
      <description>&lt;P&gt;We did - I'm fairly sure we just had to run the Cred service as SYSTEM, not the Palo agent service account we assumed we needed to run both the PA agent and Cred agent with..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That said it is currently broken for us - I've not had time to check as we were only testing but I'm due to look this week as it turns out.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2019 02:08:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/crednetial-phishing-agent-permissions/m-p/251266#M71445</guid>
      <dc:creator>apackard</dc:creator>
      <dc:date>2019-02-26T02:08:53Z</dc:date>
    </item>
    <item>
      <title>Re: Crednetial Phishing Agent Permissions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/crednetial-phishing-agent-permissions/m-p/251268#M71446</link>
      <description>&lt;P&gt;Hi thanks for replying - I've made sure we're using the system account, not a service account.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've logged it with TAC and will update here if I get a resolution.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2019 03:13:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/crednetial-phishing-agent-permissions/m-p/251268#M71446</guid>
      <dc:creator>SARowe_NZ</dc:creator>
      <dc:date>2019-02-26T03:13:17Z</dc:date>
    </item>
    <item>
      <title>Re: Crednetial Phishing Agent Permissions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/crednetial-phishing-agent-permissions/m-p/251533#M71518</link>
      <description>&lt;P&gt;I could have sworn early on the install instructions said you needed a domain admin or at least something along the way domain admin was required, but that doesn't appear to be the case now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/threat-prevention/prevent-credential-phishing/configure-credential-detection-with-the-windows-based-user-id-agent.html#&amp;nbsp;" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/threat-prevention/prevent-credential-phishing/configure-credential-detection-with-the-windows-based-user-id-agent.html#&amp;nbsp;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For using "Domain Credential Filter" --&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"Install the User-ID agent and the User Agent Credential service on an RODC using an account that has privileges to read Active Directory via LDAP (the User-ID agent also requires this privilege)."&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2019 13:47:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/crednetial-phishing-agent-permissions/m-p/251533#M71518</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2019-02-27T13:47:43Z</dc:date>
    </item>
  </channel>
</rss>

