04-21-2023 10:00 PM
My User-ID agent was successfully linked to PA and I also saw Source User in the log.
I then configured the LDAP and group mapping and applied its source user to the new policy and wanted to verify that it worked.
I found that the PAs were all using the old policy (LAN_to_WAN) and it seemed that the PAs were not catching the source users to use new policy (Test_User)...
Any help is appreciate.
04-22-2023 02:57 AM
Hi @young19918 ,
When a user does not match a group, it is almost always is because the username format does not match.
If the domain does not match or is missing, you can manually configure the User Domain (Domain Override) for the user-IP mappings in the authentication profile or for the user-group mappings under the Server Profile tab.
If the username format is different (e.g., domain\user = sAMAccountName vs. user@domain = userPrincipalName) you can modify the Primary Username under the User and Group Attributes tab in the Group Mapping settings. Or, you can change the Username Modifier in the authentication profile.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!