<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Administrators - AD users in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/administrators-ad-users/m-p/342043#M85770</link>
    <description>&lt;P&gt;Yesterday,&amp;nbsp;I have logged with a "SuperUser" account. It was the "admin" user (default). But, when I browse to Device &amp;gt; Administrators, the user's accounts didn't appear. Just the "admin" account. Also, I was not able to create a new user.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to change the LDAP's user privileges. Currently, LDAP users can log in to the web interface, but they do not have "SuperUser" permissions. Where can I change it? Where can I see the LDAP firewall's administrators?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 04 Aug 2020 17:58:44 GMT</pubDate>
    <dc:creator>iscott</dc:creator>
    <dc:date>2020-08-04T17:58:44Z</dc:date>
    <item>
      <title>Administrators - AD users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/administrators-ad-users/m-p/342009#M85767</link>
      <description>&lt;P&gt;Hello, Community.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you know if is there a way to change the "level admin" of an AD's user? In Device &amp;gt; Administrators I can't see the firewall's admins. Just the "admin" account. If I try to create a new account, I can't do it. The LDAP users can manage the firewall but they are not "Super Users". Currently, we have 2 firewalls in HA, connected to Panorama.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 15:21:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/administrators-ad-users/m-p/342009#M85767</guid>
      <dc:creator>iscott</dc:creator>
      <dc:date>2020-08-04T15:21:57Z</dc:date>
    </item>
    <item>
      <title>Re: Administrators - AD users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/administrators-ad-users/m-p/342039#M85769</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/126345"&gt;@iscott&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If i understood correctly what you need to accomplish&lt;/P&gt;
&lt;P&gt;First of all you need super user account to login and create new accounts under device administrators.&lt;/P&gt;
&lt;P&gt;So what level of access you need to grant to users?&lt;/P&gt;
&lt;P&gt;What additional access you need to allow to current users?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Under Admin Roles you can create new profile and allow them that access they need.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 17:51:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/administrators-ad-users/m-p/342039#M85769</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-08-04T17:51:06Z</dc:date>
    </item>
    <item>
      <title>Re: Administrators - AD users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/administrators-ad-users/m-p/342043#M85770</link>
      <description>&lt;P&gt;Yesterday,&amp;nbsp;I have logged with a "SuperUser" account. It was the "admin" user (default). But, when I browse to Device &amp;gt; Administrators, the user's accounts didn't appear. Just the "admin" account. Also, I was not able to create a new user.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to change the LDAP's user privileges. Currently, LDAP users can log in to the web interface, but they do not have "SuperUser" permissions. Where can I change it? Where can I see the LDAP firewall's administrators?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 17:58:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/administrators-ad-users/m-p/342043#M85770</guid>
      <dc:creator>iscott</dc:creator>
      <dc:date>2020-08-04T17:58:44Z</dc:date>
    </item>
    <item>
      <title>Re: Administrators - AD users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/administrators-ad-users/m-p/342046#M85771</link>
      <description>&lt;P&gt;Seems it is by design if you need to create additional super users you can create under Device Administrators .&lt;/P&gt;
&lt;P&gt;By design if you have LDAP users even with full access to PA under admin roles still they can not do the super user functions like rebooting&amp;nbsp;a firewall etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 18:08:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/administrators-ad-users/m-p/342046#M85771</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-08-04T18:08:21Z</dc:date>
    </item>
  </channel>
</rss>

