Disable Admin Accounts

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Disable Admin Accounts

L1 Bithead

Is there a way to disable FW admin accounts?  Let's say we have a situation where we have consultants who come on site and we only want to enable their access for certain periods of time and then disable them after the engagement is complete.  Is this possible?

I tried creating a custom role with no access, but it wouldn't let me commit.

PANOS 5.0.x

Thanks!

1 accepted solution

Accepted Solutions

There's also a third option if you don't want to create an account in AD for your contractor.

Create a local user on the FW (see screenshot) and add that local user to the Administrators list with the role you want them to have. When the contractor's engagement is complete, just uncheck the Enable box under the local user account (see screenshot).

Local-User-Admin.png

Local-User-Account.png

View solution in original post

4 REPLIES 4

L4 Transporter

A couple of options as its not possible to disable an account on the PA itself

  1. Change the password on the account after the consultants leave
  2. Configure either Kerberos or LDAP authentication for the account and disable the account there

I typically recommend number two since it does not require a commit on the firewall to change the password.

There's also a third option if you don't want to create an account in AD for your contractor.

Create a local user on the FW (see screenshot) and add that local user to the Administrators list with the role you want them to have. When the contractor's engagement is complete, just uncheck the Enable box under the local user account (see screenshot).

Local-User-Admin.png

Local-User-Account.png

L4 Transporter

That still requires a commit on the Palo Alto to disable the account

  • 1 accepted solution
  • 6250 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!