I have ldap server setup with auth profile. User gets authenticate by ldap server and can login via global protect.
User is part og the group and a policy is created for this group to access resources.
If i change the group to any access is granted but not with specific group in policy.
also... remember that adding users to groups can take up to 45 mins to replicate to Palo.
this will force an update...
debug user-id refresh group-mapping all
to see your included groups
show user group list
to list known users in a group
show user group name "group-name-from-above-command"
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!