<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User-ID mapping for users logged in to a domain controller in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-for-users-logged-in-to-a-domain-controller/m-p/388739#M90534</link>
    <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know or have experience on configuring User-ID agent to perform user mappings for users who are currently logged in to a domain controller.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue I am facing is that anyone logs into a domain controller is not being pickup by User-ID agent, so there is no user mapping for any of our domain controllers. All other servers on the same subnet as the DC are fine, no issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Leo&lt;/P&gt;</description>
    <pubDate>Wed, 03 Mar 2021 02:07:36 GMT</pubDate>
    <dc:creator>Leo_Huang</dc:creator>
    <dc:date>2021-03-03T02:07:36Z</dc:date>
    <item>
      <title>User-ID mapping for users logged in to a domain controller</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-for-users-logged-in-to-a-domain-controller/m-p/388739#M90534</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know or have experience on configuring User-ID agent to perform user mappings for users who are currently logged in to a domain controller.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue I am facing is that anyone logs into a domain controller is not being pickup by User-ID agent, so there is no user mapping for any of our domain controllers. All other servers on the same subnet as the DC are fine, no issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Leo&lt;/P&gt;</description>
      <pubDate>Wed, 03 Mar 2021 02:07:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-for-users-logged-in-to-a-domain-controller/m-p/388739#M90534</guid>
      <dc:creator>Leo_Huang</dc:creator>
      <dc:date>2021-03-03T02:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID mapping for users logged in to a domain controller</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-for-users-logged-in-to-a-domain-controller/m-p/388791#M90541</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/95819"&gt;@Leo_Huang&lt;/a&gt;&amp;nbsp;, From what I can remember... &amp;nbsp;this is because DC local logins are not registered in the security logs. I can’t remember what we did so will have a dig.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Mar 2021 06:55:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-for-users-logged-in-to-a-domain-controller/m-p/388791#M90541</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-03-03T06:55:12Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID mapping for users logged in to a domain controller</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-for-users-logged-in-to-a-domain-controller/m-p/392787#M90955</link>
      <description>&lt;P&gt;The normal server Monitoring should do the trick. Do you see the&lt;STRONG&gt; user login events&amp;nbsp; &lt;/STRONG&gt;in the Domain server logs, if not then it is a Windows issue. If they are present you will need to check many things like if the Palo Alto has the right credentials if login attemps are seen on the DC from the Palo Alto, does the zone has User id mapping allowed, do the DC allow a non Windows device like palo alto to connect or an external UserId agent is needed, maybe do pcap captures and check the Palo Alto authd log and so on:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm5bCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm5bCAC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClR1CAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClR1CAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 18:30:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-for-users-logged-in-to-a-domain-controller/m-p/392787#M90955</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-03-22T18:30:01Z</dc:date>
    </item>
  </channel>
</rss>

