<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Add LDAP  *GROUP* as Administrator in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/add-ldap-group-as-administrator/m-p/260754#M73913</link>
    <description>&lt;P&gt;All -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, I know how to add individual LDAP users as local appliance / Panorama administrators.&amp;nbsp; What I'm wondering is, is it possible to add an LDAP group as an administrator, instead of enumerating each user individually?&amp;nbsp; So, instead of manually enumerating "mark", "bob", "jim" and the 10 other people I want to administer a given box, can I add those users to an LDAP group and tell the firewall to allow anyone within that group to be a device administrator?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should this be a feature request, if it is not possible today?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;</description>
    <pubDate>Mon, 13 May 2019 15:04:15 GMT</pubDate>
    <dc:creator>MarkRosenecker</dc:creator>
    <dc:date>2019-05-13T15:04:15Z</dc:date>
    <item>
      <title>Add LDAP  *GROUP* as Administrator</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/add-ldap-group-as-administrator/m-p/260754#M73913</link>
      <description>&lt;P&gt;All -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, I know how to add individual LDAP users as local appliance / Panorama administrators.&amp;nbsp; What I'm wondering is, is it possible to add an LDAP group as an administrator, instead of enumerating each user individually?&amp;nbsp; So, instead of manually enumerating "mark", "bob", "jim" and the 10 other people I want to administer a given box, can I add those users to an LDAP group and tell the firewall to allow anyone within that group to be a device administrator?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should this be a feature request, if it is not possible today?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 15:04:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/add-ldap-group-as-administrator/m-p/260754#M73913</guid>
      <dc:creator>MarkRosenecker</dc:creator>
      <dc:date>2019-05-13T15:04:15Z</dc:date>
    </item>
    <item>
      <title>Re: Add LDAP  *GROUP* as Administrator</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/add-ldap-group-as-administrator/m-p/260818#M73932</link>
      <description>&lt;P&gt;Not directly as an LDAP group, but it can be done with RADIUS:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/authentication/configure-radius-authentication.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/authentication/configure-radius-authentication.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Essentially, you're creating a Vendor Specific Attribute for the users that you want to assign as a device admin, superuser, super reader, etc. It's definitely more work than being able to specify a group, so a filing a feature request with your account team would still be a good idea.&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 20:15:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/add-ldap-group-as-administrator/m-p/260818#M73932</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2019-05-13T20:15:33Z</dc:date>
    </item>
  </channel>
</rss>

