Disable Admin Accounts

Reply
L1 Bithead

Disable Admin Accounts

Is there a way to disable FW admin accounts?  Let's say we have a situation where we have consultants who come on site and we only want to enable their access for certain periods of time and then disable them after the engagement is complete.  Is this possible?

I tried creating a custom role with no access, but it wouldn't let me commit.

PANOS 5.0.x

Thanks!

Highlighted
L4 Transporter

Re: Disable Admin Accounts

A couple of options as its not possible to disable an account on the PA itself

  1. Change the password on the account after the consultants leave
  2. Configure either Kerberos or LDAP authentication for the account and disable the account there

I typically recommend number two since it does not require a commit on the firewall to change the password.

L4 Transporter
L4 Transporter

Re: Disable Admin Accounts

There's also a third option if you don't want to create an account in AD for your contractor.

Create a local user on the FW (see screenshot) and add that local user to the Administrators list with the role you want them to have. When the contractor's engagement is complete, just uncheck the Enable box under the local user account (see screenshot).

Local-User-Admin.png

Local-User-Account.png

L4 Transporter

Re: Disable Admin Accounts

That still requires a commit on the Palo Alto to disable the account

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!