<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problems with Windows User-ID Agent and the normalized Users in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/problems-with-windows-user-id-agent-and-the-normalized-users/m-p/379103#M89547</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/104430"&gt;@Chris_Johnston&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've tested it with only one group mapping profile but at the moment I have disabled the connectivity from the firewall to the useragent and the agent also normalizes the users.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Jan 2021 21:10:04 GMT</pubDate>
    <dc:creator>kan3de</dc:creator>
    <dc:date>2021-01-11T21:10:04Z</dc:date>
    <item>
      <title>Problems with Windows User-ID Agent and the normalized Users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problems-with-windows-user-id-agent-and-the-normalized-users/m-p/378972#M89529</link>
      <description>&lt;P&gt;Hi together,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have here a Windows User Agent (tested with Version 9.1.1-8 &amp;amp; 9.1.2-9), which has connected to one Active Directory (MS2012 R2) where they scan the events. The rights from the agent user looks good and they find many client users. But after a few seconds the usernames normalized&amp;nbsp; here.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Domain structure:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;company.domain.com&amp;nbsp; &amp;lt;- root domain with no users, such a few service accounts&lt;/P&gt;&lt;P&gt;departure.company.domain.com &amp;lt;- sub domain with the users&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So when I enable the debug to verbose on the user-id agent, I see the following:&amp;nbsp;&lt;/P&gt;&lt;P&gt;Event Log: &lt;A href="mailto:UserA@lab.company.domain.com" target="_blank"&gt;UserA@lab.company.domain.com&lt;/A&gt;&amp;nbsp;is connected&lt;/P&gt;&lt;P&gt;NormalizeUser_n returns &lt;A href="mailto:usera@lab.company.domain.com" target="_blank"&gt;usera@lab.company.domain.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;NormalizeUser returns &lt;STRONG&gt;lab\usera&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;UserIpMap: IP(1.1.1.1) Username &lt;A href="mailto:usera@lab.company.domain.com" target="_blank"&gt;usera@lab.company.domain.com&lt;/A&gt;) queued for xmission to firewall&lt;/P&gt;&lt;P&gt;NormalizeUser returns &lt;STRONG&gt;lab\usera&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And a few seconds later:&amp;nbsp;&lt;/P&gt;&lt;P&gt;NormalizeUser_n reutrns &lt;STRONG&gt;company\usera&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;UserIpMap: IP 1.1.1.1 login name gets changed from &lt;A href="mailto:usera@lab.company.domain.com" target="_blank"&gt;usera@lab.company.domain.com&lt;/A&gt;&amp;nbsp;to &lt;STRONG&gt;company\usera&lt;/STRONG&gt; with timeout 7200.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After a few seconds later:&amp;nbsp;&lt;/P&gt;&lt;P&gt;NormalizeUser_n returns &lt;STRONG&gt;lab\usera&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And this ping pong we have the full day. At the moment the UserAgent is disabled on the firewall. Because we want to exclude that the group mapping from the ldap server is here a problem. Only the user lab\usera is in the group mapping/policies and a user customer\usera is not existend.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone here a idea? What does the function&amp;nbsp;NormalizeUser_n do?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2021 14:26:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problems-with-windows-user-id-agent-and-the-normalized-users/m-p/378972#M89529</guid>
      <dc:creator>kan3de</dc:creator>
      <dc:date>2021-01-11T14:26:15Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with Windows User-ID Agent and the normalized Users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problems-with-windows-user-id-agent-and-the-normalized-users/m-p/379062#M89539</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/106736"&gt;@kan3de&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;But the user-id agent is installed and reading logs for both the root domain and the subdomain correct? When you actually go and read the logs, do you see the security events in both lab\user and company\user when the user authenticates? Somewhere along the way, somethings seeing the username in both domains.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you just quickly wanted to fix this you could use a wildcard entry in the ignore-user list. Forcing the firewall to ignore everything received with whatever format you don't want so that only the proper mapping is actually respected. So if you update the ignore-user list with a new entry for 'lab\*' for example, it'll ignore any user received from that domain.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2021 18:33:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problems-with-windows-user-id-agent-and-the-normalized-users/m-p/379062#M89539</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-01-11T18:33:05Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with Windows User-ID Agent and the normalized Users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problems-with-windows-user-id-agent-and-the-normalized-users/m-p/379078#M89544</link>
      <description>&lt;P&gt;How many group mapping profiles are present?&amp;nbsp; We saw something similar in our environment where we had multiple group mapping profiles configured with different primary username attributes.&amp;nbsp; Once the firewall refreshes the group mappings, the last 'primaryusername' will replace them and cause a mismatch&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;Group Mapping Profile 1&lt;BR /&gt;User/Group Attributes / Primary Username / 'UPN', secondary/email = samaccountname&lt;/P&gt;&lt;P&gt;Group include list 'admin users'&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:userfirst.last@domain.com" target="_blank"&gt;userfirst.last@domain.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;userfirst.last2@domain.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Group Mapping Profile 2&lt;BR /&gt;User/Group Attributes / Primary Username / 'samaccountname', secondary = UPN&lt;/P&gt;&lt;P&gt;Group include list 'domain users'&lt;/P&gt;&lt;P&gt;domain\flast&lt;/P&gt;&lt;P&gt;domain\flast2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once groupmapping profile '2' refreshed, the firewall would detect first.last as an attribute of domain\flast and replace the mapping.&amp;nbsp; However, group mapping is a direct match...not an attribute match.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2021 19:13:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problems-with-windows-user-id-agent-and-the-normalized-users/m-p/379078#M89544</guid>
      <dc:creator>Chris_Johnston</dc:creator>
      <dc:date>2021-01-11T19:13:36Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with Windows User-ID Agent and the normalized Users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problems-with-windows-user-id-agent-and-the-normalized-users/m-p/379102#M89546</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for your response. At the moment I have only connected a node from the&amp;nbsp;&lt;A href="mailto:usera@lab.company.domain.com" target="_blank" rel="nofollow noopener noreferrer"&gt;lab.company.domain.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;So I think in the Event log, should be nothing from the root&amp;nbsp;company.domain.com direct , but I'm not an AD guy.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Service I use for my requests is a user from the root domain, maybe this is a problem.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The method with the ignore file I've always tested and this works. But in the future we also want to see, the Service Users which are direct in the root.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2021 21:07:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problems-with-windows-user-id-agent-and-the-normalized-users/m-p/379102#M89546</guid>
      <dc:creator>kan3de</dc:creator>
      <dc:date>2021-01-11T21:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with Windows User-ID Agent and the normalized Users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problems-with-windows-user-id-agent-and-the-normalized-users/m-p/379103#M89547</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/104430"&gt;@Chris_Johnston&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've tested it with only one group mapping profile but at the moment I have disabled the connectivity from the firewall to the useragent and the agent also normalizes the users.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2021 21:10:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problems-with-windows-user-id-agent-and-the-normalized-users/m-p/379103#M89547</guid>
      <dc:creator>kan3de</dc:creator>
      <dc:date>2021-01-11T21:10:04Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with Windows User-ID Agent and the normalized Users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problems-with-windows-user-id-agent-and-the-normalized-users/m-p/472427#M103209</link>
      <description>&lt;P&gt;Did you ever happen to find a solution to this? I'm running into the same issue.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 17:55:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problems-with-windows-user-id-agent-and-the-normalized-users/m-p/472427#M103209</guid>
      <dc:creator>TravisChaney</dc:creator>
      <dc:date>2022-03-11T17:55:33Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with Windows User-ID Agent and the normalized Users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problems-with-windows-user-id-agent-and-the-normalized-users/m-p/472774#M103243</link>
      <description>&lt;P&gt;We disabled in the UserID Agent the "Enable Server Session Read" and that was all.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Mar 2022 06:22:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problems-with-windows-user-id-agent-and-the-normalized-users/m-p/472774#M103243</guid>
      <dc:creator>kan3de</dc:creator>
      <dc:date>2022-03-14T06:22:55Z</dc:date>
    </item>
  </channel>
</rss>

