- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-16-2026 10:01 PM
I have VM-100 running panos-11.1.13. currently i have local admins for msp -superusers and 1 customer user with a customer -admin-role profile. customer wants to have mutiple admins controlled by their radius. so radius profile and auth profile is configured. how can i attach admin user group(listed under auth profile) to admin role profile.
I see long way of getting list of users ,configure them attaching radius auth profile and admin role profile. or ldap would be better as i can extract group mapping in user identification.
03-17-2026 05:13 AM
You can't add groups in your authentication profile
For radius auth you can either create local accounts and set an authentication profile, or you can change the device level authentication settings to accept radius credentials. that way the radius server decides which accounts to accept and which attributes to return to the firewall (superuser, device admin,...)
03-19-2026 08:47 PM
thanks for the info. Currently I havent setup auth profile under auth setting so radius users were failing -complaining cant find radius profile. i created a radius user under administrator account and this radius user can access firewall. I dont want to create users under administrator so I will go ahead with configuring admin profile under auth setting. But i have msp administrators on the firewall who r superusers. My only concern is setting auth profile will not cut off these superuser from logging to fw?
03-23-2026 02:37 AM
local accounts will remain active (and preferred) while a system authentication profile is active, so make sure there's no overlap
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

