<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID two usernames being identified by User-ID servers in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/315201#M81219</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;BR /&gt;&lt;BR /&gt;Correct the user-id servers are the only source currently. I can confirm this when I review the User-ID monitor tab as you suggested. Further to this I can see both versions of the username coming through on both servers in the same moment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;As in &lt;A href="mailto:user.name@domain.local" target="_blank"&gt;user.name@domain.local&lt;/A&gt; &amp;amp; domain\user.name exist in a log entry at the same time. The second User-ID server also records both of these duplicate usernames and does so with a Palo User-ID Monitor tab entry 1 second apart from the first server, or sometimes the other way around.&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;It seems the User-ID servers are determined to give the Pan-OS bother UPN and SAM.&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;We have not rolled out GP yet, and it is something that I am thinking from an Internal Gateway perspective to overcome the User-ID issues. However that's a bigger project as we would need to deprecate our current client to site vpn solution.&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;I cannot see in the User-ID agent server a way to filter either, potentially it may be worthwhile for testing not using the User-ID agent servers?&lt;/P&gt;</description>
    <pubDate>Mon, 09 Mar 2020 02:47:38 GMT</pubDate>
    <dc:creator>DanielBostock</dc:creator>
    <dc:date>2020-03-09T02:47:38Z</dc:date>
    <item>
      <title>User-ID two usernames being identified by User-ID servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/312981#M80858</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I am having troubles with getting the Palo's in my network to only use the UPN of a user in our environment. I would like to start creating security policies to control staff members access to resources based on their AD user rather than IP address and then further to that leverage groups. Long term of course the idea is to leverage AD groups to control access to resources, however I need to prove that this will work on individual users first.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;It is not working currently because what I am seeing in the monitor logs is either domain\user.name or &lt;A href="mailto:user.name@domain.local" target="_blank"&gt;user.name@domain.local&lt;/A&gt;&amp;nbsp; and because of this whenever I make a security policy sometimes it works for the end user and then the next moment it doesn't work. It will work 100% of the time if I update the policy to domain\user.name and &lt;A href="mailto:user.name@domain.local" target="_blank"&gt;user.name@domain.local&lt;/A&gt; . This of course is not practical and scalable.&lt;BR /&gt;&lt;BR /&gt;Currently we are using 2 Palo Alto Windows Server Agents to get the access data from our AD servers. Palo Alto monitor logs are reporting back connected and the User-ID log shows the source as being either of these servers.&lt;BR /&gt;&lt;BR /&gt;Here is some screenshots of our current configuration for the user &amp;amp; group mapping.&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ldap_group_mapping1.png" style="width: 611px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24087i03016B4633E3B28E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ldap_group_mapping1.png" alt="ldap_group_mapping1.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ldap_group_mapping2.png" style="width: 591px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24088iF444AD2F11687AF4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ldap_group_mapping2.png" alt="ldap_group_mapping2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Are there additional settings, or things I need to be doing to resolve this and either only match on domain\user.name or &lt;A href="mailto:user.name@domain.local" target="_blank"&gt;user.name@domain.local&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 05:32:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/312981#M80858</guid>
      <dc:creator>DanielBostock</dc:creator>
      <dc:date>2020-02-26T05:32:00Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID two usernames being identified by User-ID servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/312988#M80859</link>
      <description>&lt;P&gt;if you want everything to be UPN, you'll need to set userPrincipalName in the User Object Search Filter, and in the primary Username, or set sAMAccountName in both&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 07:17:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/312988#M80859</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-02-26T07:17:12Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID two usernames being identified by User-ID servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/313238#M80901</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp; - Thanks for your assistance here. I have updated the settings to match this but I am still seeing the duplicate username in the monitor traffic log and user-id log. Is this still expected? If this is expected and normal, I will do some policy testing just using the UPN.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 23:46:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/313238#M80901</guid>
      <dc:creator>DanielBostock</dc:creator>
      <dc:date>2020-02-26T23:46:56Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID two usernames being identified by User-ID servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/313736#M80972</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/123487"&gt;@DanielBostock&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just wondering if this document would help.&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClpsCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClpsCAC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kavi&lt;/P&gt;</description>
      <pubDate>Sun, 01 Mar 2020 03:05:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/313736#M80972</guid>
      <dc:creator>kgopichand</dc:creator>
      <dc:date>2020-03-01T03:05:58Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID two usernames being identified by User-ID servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/313828#M80990</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/59290"&gt;@kgopichand&lt;/a&gt;- Thanks for sharing this post but I have already followed this guide and it sadly did not fix the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2020 03:58:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/313828#M80990</guid>
      <dc:creator>DanielBostock</dc:creator>
      <dc:date>2020-03-02T03:58:12Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID two usernames being identified by User-ID servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/313948#M81019</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/123487"&gt;@DanielBostock&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead lia-component-message-view-widget-author-username"&gt;Ok , lets look into this further. If you want , you could open a ticket and one of us will investigate.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead lia-component-message-view-widget-author-username"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead lia-component-message-view-widget-author-username"&gt;One thing I noticed is the user attribute that is specified .&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead lia-component-message-view-widget-author-username"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead lia-component-message-view-widget-author-username"&gt;You specified&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead lia-component-message-view-widget-author-username"&gt;&amp;nbsp;"sAMaccount" . It is supposed to be "sAMAccountName".&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead lia-component-message-view-widget-author-username"&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead lia-component-message-view-widget-author-username"&gt;Can you please change this entry to&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead lia-component-message-view-widget-author-username"&gt;"sAMAccountName" and repeat your tests .&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead lia-component-message-view-widget-author-username"&gt;&lt;BR /&gt;Second point : If you&amp;nbsp; repeat the command "show user user-attributes user all" a number of times, what attribute do you see for the "Primary user" . Do the primary user attribute always show&amp;nbsp;"sAMAccountName" or does it fluctuate between "sAMAccountName" and "userPrincipalName".&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Kavi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2020 17:32:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/313948#M81019</guid>
      <dc:creator>kgopichand</dc:creator>
      <dc:date>2020-03-02T17:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID two usernames being identified by User-ID servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/314037#M81034</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/59290"&gt;@kgopichand&lt;/a&gt;- Thanks for helping here Kavi appreciate it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would prefer to use UPN. Is this possible or for the sake of testing and working out the issue would you prefer I stick with SAM?&lt;BR /&gt;&lt;BR /&gt;I adjusted my configuration to the following.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ldap_group_mapping3.png" style="width: 596px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24202i761C1689776D16C5/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ldap_group_mapping3.png" alt="ldap_group_mapping3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ldap_group_mapping4.png" style="width: 621px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24200i61EA300C9D2FDBA6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ldap_group_mapping4.png" alt="ldap_group_mapping4.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I run the command you have suggested, I get a blank response. So maybe I am missing a configuration step somewhere?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2020 01:24:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/314037#M81034</guid>
      <dc:creator>DanielBostock</dc:creator>
      <dc:date>2020-03-03T01:24:50Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID two usernames being identified by User-ID servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/314107#M81047</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/123487"&gt;@DanielBostock&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;are your user-id servers the only source of user-id...&amp;nbsp; &amp;nbsp; &amp;nbsp;check the user-id server monitor tab to see what it is forwarding to the palo.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit---&amp;nbsp; &amp;nbsp;check the user-id log to see where the source is for the different user ID's.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you have more than 1 user-id source (perhaps CP or GP) then increase your user-id agent timeout to 8-12 hours because it may be that the user ID agent timeout is too soon and other auth sources are remaining.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can also exclude the domain part of usernames in the local user id agent setup but cannot see if this can be done with the server agents.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2020 12:35:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/314107#M81047</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-03-03T12:35:46Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID two usernames being identified by User-ID servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/314125#M81051</link>
      <description>&lt;P&gt;ust to be sure, your 'user domain' is set to the NetBIOS name, right? (domain, not domain.com)&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2020 13:30:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/314125#M81051</guid>
      <dc:creator>panwreaper</dc:creator>
      <dc:date>2020-03-03T13:30:03Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID two usernames being identified by User-ID servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/315201#M81219</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;BR /&gt;&lt;BR /&gt;Correct the user-id servers are the only source currently. I can confirm this when I review the User-ID monitor tab as you suggested. Further to this I can see both versions of the username coming through on both servers in the same moment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;As in &lt;A href="mailto:user.name@domain.local" target="_blank"&gt;user.name@domain.local&lt;/A&gt; &amp;amp; domain\user.name exist in a log entry at the same time. The second User-ID server also records both of these duplicate usernames and does so with a Palo User-ID Monitor tab entry 1 second apart from the first server, or sometimes the other way around.&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;It seems the User-ID servers are determined to give the Pan-OS bother UPN and SAM.&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;We have not rolled out GP yet, and it is something that I am thinking from an Internal Gateway perspective to overcome the User-ID issues. However that's a bigger project as we would need to deprecate our current client to site vpn solution.&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;I cannot see in the User-ID agent server a way to filter either, potentially it may be worthwhile for testing not using the User-ID agent servers?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 02:47:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/315201#M81219</guid>
      <dc:creator>DanielBostock</dc:creator>
      <dc:date>2020-03-09T02:47:38Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID two usernames being identified by User-ID servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/315202#M81220</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132518"&gt;@panwreaper&lt;/a&gt;&amp;nbsp; - Correct, it is set to NetBIOS. I have set the domain to 'domain' not 'domain.local'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 02:49:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/315202#M81220</guid>
      <dc:creator>DanielBostock</dc:creator>
      <dc:date>2020-03-09T02:49:35Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID two usernames being identified by User-ID servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/315209#M81222</link>
      <description>&lt;P&gt;The userid agent is supposed to simply pick up logs&lt;/P&gt;&lt;P&gt;Is it possible that it is either reading 2 different sources, or the eventlog is getting populated by 2 processes that write the username differently?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One workaround would be to set up thebignire_user_list.txt and exclude either domain\* or *@domain, but it would be better if you figure out why the userid agent is seeing both and suppress one source&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 06:11:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/315209#M81222</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-03-09T06:11:27Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID two usernames being identified by User-ID servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/315216#M81225</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I think there is something to what you are saying, however I will look into it tomorrow with a colleague. I have deployed User-ID in other environments before and not had this issue, there is something peculiar with this AD setup I am thinking.&lt;BR /&gt;&lt;BR /&gt;The ignore text file which you meantion here, I have not seen a guide mention it, apologies if I have missed this though. Is this a file that should exist on the User-ID agent servers?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 06:17:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/315216#M81225</guid>
      <dc:creator>DanielBostock</dc:creator>
      <dc:date>2020-03-09T06:17:35Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID two usernames being identified by User-ID servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/315217#M81226</link>
      <description>&lt;P&gt;The file doesn't exist, you need to create it&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is a bit of tribal knowledge &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; but it's described here&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClklCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClklCAC&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 06:22:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/315217#M81226</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-03-09T06:22:15Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID two usernames being identified by User-ID servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/315220#M81228</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hey mate, looks like this has really started to filter out the @domain SAM log entries. I will let this run over night and for some of the day tomorrow then begin testing some rules to see how it goes now with this filter and then let you know if this has solved it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Really appreciate the help!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 07:20:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/315220#M81228</guid>
      <dc:creator>DanielBostock</dc:creator>
      <dc:date>2020-03-09T07:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID two usernames being identified by User-ID servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/523041#M108339</link>
      <description>&lt;P&gt;I bumped into this discussion and I believe I have an additional challange&amp;nbsp;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In our case the UPN and samAccountName are not the same. The samAccountName is the employee number. In the example below this is user1234&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The user recognition works flawless on for example VPN connections and when I look at the group mappings it only shows UPN names.&lt;/P&gt;
&lt;P&gt;Also when creating policies I can choose the user principal name.&lt;/P&gt;
&lt;P&gt;The user data is fetched via Active Directory-WinRM&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Looking at the "User-ID" logs it shows that the client (computer) provides the username.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In this case it is domain\sAMAccountName&lt;/P&gt;
&lt;P&gt;I would guess that a user has logged onto with his employee number.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is also shown in the Traffic Logs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But there does not appear to be a match between short-domain\sAMAcountName and the UPN.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is a match on FQDN-DomainName\sAMAccountName&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Most likely I need to find the solution to this problem in the alternate UserName fields.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any idea what needs to be set to find the correct match.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Remko_0-1669906902992.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/45854iAD30F8D3AB6ED39E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Remko_0-1669906902992.png" alt="Remko_0-1669906902992.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Example username&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="mailto:john.doe@acme.com" target="_blank"&gt;UPN : john.doe@acme.com&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;acme.com\user1234&lt;/P&gt;
&lt;P&gt;acme.com\john.doe&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;needed:&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;ac\user1234&lt;/P&gt;
&lt;P&gt;where ac is the short domain name instead of the FQDN&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any thoughts are most welcome.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 15:12:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/523041#M108339</guid>
      <dc:creator>Remko</dc:creator>
      <dc:date>2022-12-01T15:12:04Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID two usernames being identified by User-ID servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/523615#M108407</link>
      <description>&lt;P&gt;Above problem has been resolved by changing the Domain Settings in the Group Mapping to the "Short" domain name instead of the FQDN&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Remko_0-1670500565941.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/46005i7CF4AB164C65E39E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Remko_0-1670500565941.png" alt="Remko_0-1670500565941.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Users are now correctly identified.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2022 11:56:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/523615#M108407</guid>
      <dc:creator>Remko</dc:creator>
      <dc:date>2022-12-08T11:56:43Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID two usernames being identified by User-ID servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/1240593#M125409</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm also facing the same problem, how did you solve it in the end?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Carol&lt;/P&gt;</description>
      <pubDate>Thu, 23 Oct 2025 08:59:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-two-usernames-being-identified-by-user-id-servers/m-p/1240593#M125409</guid>
      <dc:creator>carolwu</dc:creator>
      <dc:date>2025-10-23T08:59:29Z</dc:date>
    </item>
  </channel>
</rss>

