<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User-ID Policies in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-policies/m-p/321819#M82339</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a few questions regarding policies using user-id for access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I select add, to add a source user into a policy I can start typing a name and it will give me a list of users with thoses names to add in, like a prepopulation.&lt;/P&gt;&lt;P&gt;Is there a limit as to how many it will display?&lt;/P&gt;&lt;P&gt;for example, if i type the domain first it will give me a long list of users, but its clearly not the full domain users list? is this by design? can it be changed?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm also trying to add groups to make it alittle easier to read the rules and amalgamate single users, but it never prepopulates groups.&lt;/P&gt;&lt;P&gt;Even if I add ad groups manually this doesnt work, the rule denies access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The authentication profile for the LDAP query is setup as default. I have viewed a video regarding using groups for policies, my configuration looks correct, so drawing a blank with this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Ian&lt;/P&gt;</description>
    <pubDate>Thu, 09 Apr 2020 09:27:39 GMT</pubDate>
    <dc:creator>IanBroadway</dc:creator>
    <dc:date>2020-04-09T09:27:39Z</dc:date>
    <item>
      <title>User-ID Policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-policies/m-p/321819#M82339</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a few questions regarding policies using user-id for access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I select add, to add a source user into a policy I can start typing a name and it will give me a list of users with thoses names to add in, like a prepopulation.&lt;/P&gt;&lt;P&gt;Is there a limit as to how many it will display?&lt;/P&gt;&lt;P&gt;for example, if i type the domain first it will give me a long list of users, but its clearly not the full domain users list? is this by design? can it be changed?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm also trying to add groups to make it alittle easier to read the rules and amalgamate single users, but it never prepopulates groups.&lt;/P&gt;&lt;P&gt;Even if I add ad groups manually this doesnt work, the rule denies access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The authentication profile for the LDAP query is setup as default. I have viewed a video regarding using groups for policies, my configuration looks correct, so drawing a blank with this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Ian&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2020 09:27:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-policies/m-p/321819#M82339</guid>
      <dc:creator>IanBroadway</dc:creator>
      <dc:date>2020-04-09T09:27:39Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-policies/m-p/321860#M82351</link>
      <description>&lt;P&gt;hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/95468"&gt;@IanBroadway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes there's a limit to the number of items listed, this cannot be changed&lt;/P&gt;&lt;P&gt;&amp;nbsp;(because if you have a million objects the firewall needs to query it's database every time you add or delete a letter to repopulate the list)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for the groups: did you set up group mapping? this is a separate tab in the user identification configuration (device &amp;gt; user identification &amp;gt; group mapping), the authentication profile only provides authentication and a connector to the ldap for the group mapping profile&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2020 12:12:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-policies/m-p/321860#M82351</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-04-09T12:12:41Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-policies/m-p/322000#M82382</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Save your sanity and use groups. This will make it easier to add/remove users in the future and help the policies look cleaner.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2020 21:27:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-policies/m-p/322000#M82382</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-04-09T21:27:43Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-policies/m-p/322856#M82536</link>
      <description>&lt;P&gt;Thanks all&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2020 11:27:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-policies/m-p/322856#M82536</guid>
      <dc:creator>IanBroadway</dc:creator>
      <dc:date>2020-04-15T11:27:58Z</dc:date>
    </item>
  </channel>
</rss>

