<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Advise on using AD user-id in local PA groups? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/advise-on-using-ad-user-id-in-local-pa-groups/m-p/257047#M72918</link>
    <description>&lt;P&gt;I am struggling with utilizing ActiveDirectory groups in firewall policy. My concern is then our AD administrators have control over transversing our firewall policy. Generally speaking say for example we have a FW policy setup where AD group ServerAdmins has &amp;lt;some type of&amp;gt; to a resource, they (the AD administrator) could very easily throw any user into that group thus giving sed person access to the resource. However I do love the user-ID capabilities and want to leverage that but it gets tideous having individiaul users defined in policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So my thought\question is if I could have a locally defined PA group (that I administrator) this would allow me to add the ActiveDirectory defined users into this group and then use this group in FW policy. Now I'm getting the benefits of user-ID and efficiency of using groups in firewall policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Curious if this is at all possible or if anyone else has any other options\ideas?&lt;/P&gt;</description>
    <pubDate>Wed, 10 Apr 2019 18:39:38 GMT</pubDate>
    <dc:creator>zthiel</dc:creator>
    <dc:date>2019-04-10T18:39:38Z</dc:date>
    <item>
      <title>Advise on using AD user-id in local PA groups?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/advise-on-using-ad-user-id-in-local-pa-groups/m-p/257047#M72918</link>
      <description>&lt;P&gt;I am struggling with utilizing ActiveDirectory groups in firewall policy. My concern is then our AD administrators have control over transversing our firewall policy. Generally speaking say for example we have a FW policy setup where AD group ServerAdmins has &amp;lt;some type of&amp;gt; to a resource, they (the AD administrator) could very easily throw any user into that group thus giving sed person access to the resource. However I do love the user-ID capabilities and want to leverage that but it gets tideous having individiaul users defined in policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So my thought\question is if I could have a locally defined PA group (that I administrator) this would allow me to add the ActiveDirectory defined users into this group and then use this group in FW policy. Now I'm getting the benefits of user-ID and efficiency of using groups in firewall policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Curious if this is at all possible or if anyone else has any other options\ideas?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 18:39:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/advise-on-using-ad-user-id-in-local-pa-groups/m-p/257047#M72918</guid>
      <dc:creator>zthiel</dc:creator>
      <dc:date>2019-04-10T18:39:38Z</dc:date>
    </item>
    <item>
      <title>Re: Advise on using AD user-id in local PA groups?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/advise-on-using-ad-user-id-in-local-pa-groups/m-p/257055#M72920</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Yes this could be an issue. What we did was implement compensating controls. We have our security analysts review the revious days SIEM reports for users added/removed from certain groups. If there is a change, then a support ticket needs to have been entered for the correct action, i.e. user B was added to group F for reason Y. I can also see how this could become a tedious process in a large environment but reports can be substituted for alerts/alarms that need to be reviewed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you go with a local user/group the end user now needs to have those credentials and this can be tedious as well for the firewall admins.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 19:03:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/advise-on-using-ad-user-id-in-local-pa-groups/m-p/257055#M72920</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-04-10T19:03:13Z</dc:date>
    </item>
    <item>
      <title>Re: Advise on using AD user-id in local PA groups?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/advise-on-using-ad-user-id-in-local-pa-groups/m-p/257147#M72946</link>
      <description>&lt;P&gt;Similar issue for us, we are very restrictive on file uploading and block all webmail.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;to get around the AD admin issues mentioned we have policies that overide some restrictions (where needed) and just add the users direct to that policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;its no different than having local groups but if you have many policies that are an issue then yes groups will just save you entering individual names.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2019 05:26:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/advise-on-using-ad-user-id-in-local-pa-groups/m-p/257147#M72946</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-04-11T05:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: Advise on using AD user-id in local PA groups?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/advise-on-using-ad-user-id-in-local-pa-groups/m-p/257148#M72947</link>
      <description>&lt;P&gt;Oops sorry&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/4746"&gt;@zthiel&lt;/a&gt;&amp;nbsp;, i just noticed your comments on individual users....&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2019 05:47:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/advise-on-using-ad-user-id-in-local-pa-groups/m-p/257148#M72947</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-04-11T05:47:55Z</dc:date>
    </item>
  </channel>
</rss>

