<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global Protect portal Config selection criteria combination of User group/device check/custom check? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-portal-config-selection-criteria-combination-of/m-p/383293#M89942</link>
    <description>&lt;P&gt;I'm guessing others are combining these together, but is it possible to specify these together mix/match?&amp;nbsp; &amp;nbsp; Specifically, We have configs without a custom check (custom checkmark box UNchecked-portal/agent/configs/config selection criteria custom checks), and that are only based on AD group. But when I turn on custom checks for a different agent config that includes both AD group and Custom Check (portal/agent/config/config selection criteria/custom checks) , the configs with only an AD group specified (and NO custom checks) don't match.&amp;nbsp; Almost like once you turn on Custom checks in one config, the portal uses that against all other agent configs regardless of if that "custom checks" box is marked or not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is all on the same portal.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 01 Feb 2021 20:26:25 GMT</pubDate>
    <dc:creator>Sec101</dc:creator>
    <dc:date>2021-02-01T20:26:25Z</dc:date>
    <item>
      <title>Global Protect portal Config selection criteria combination of User group/device check/custom check?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-portal-config-selection-criteria-combination-of/m-p/383293#M89942</link>
      <description>&lt;P&gt;I'm guessing others are combining these together, but is it possible to specify these together mix/match?&amp;nbsp; &amp;nbsp; Specifically, We have configs without a custom check (custom checkmark box UNchecked-portal/agent/configs/config selection criteria custom checks), and that are only based on AD group. But when I turn on custom checks for a different agent config that includes both AD group and Custom Check (portal/agent/config/config selection criteria/custom checks) , the configs with only an AD group specified (and NO custom checks) don't match.&amp;nbsp; Almost like once you turn on Custom checks in one config, the portal uses that against all other agent configs regardless of if that "custom checks" box is marked or not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is all on the same portal.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 20:26:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-portal-config-selection-criteria-combination-of/m-p/383293#M89942</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2021-02-01T20:26:25Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect portal Config selection criteria combination of User group/device check/custom ch</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-portal-config-selection-criteria-combination-of/m-p/383321#M89945</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/157358"&gt;@Sec101&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Are you attempting to utilize the same group in both agent configurations?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 21:43:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-portal-config-selection-criteria-combination-of/m-p/383321#M89945</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-02-01T21:43:13Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect portal Config selection criteria combination of User group/device check/custom ch</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-portal-config-selection-criteria-combination-of/m-p/383328#M89947</link>
      <description>&lt;P&gt;different groups even.&amp;nbsp; &amp;nbsp;It's kind of like it prioritizes the registry custom check for every agent config you have, and starts to check that first before checking your AD group.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This actually seems to be related to using different auth profiles.&amp;nbsp; &amp;nbsp;I can't replicate when using the same auth profile (simple ldap).&amp;nbsp; &amp;nbsp;When getting a username back from SAML (we are sending back domain\username) it's failing to match any config -&amp;nbsp; but it only fails when I select the "custom check" to match against reg key.&amp;nbsp; If I remove that check, everything works normally.&amp;nbsp; &amp;nbsp;Odd that I can cause a failure, simply by editing that box.&amp;nbsp; It's like it's changing the way that the portal looks at the username and domain?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Feb 2021 21:08:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-portal-config-selection-criteria-combination-of/m-p/383328#M89947</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2021-02-10T21:08:23Z</dc:date>
    </item>
  </channel>
</rss>

