We've been running into some UID mapping issues, running in agentless mode. It turns out that since we have multiple domains, we weren't uspposed to be using agentless. Instead, PAN advised us to stand up a vm/server in each domain and put an agent on it that can reach out and query the DCs. We were having the same issue, where we were only getting 50-60% of the UIDs. Sometimes we'd get UID, and then it would just drop. We also tried doing switch user, and the UID would still be for the first user.
Or you can enforce Captive Portal, but that's really more of a catch-all.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!